Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations sizbut on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

problem with mail for users

Status
Not open for further replies.

pichi

Programmer
Nov 12, 2000
156
EC
hi everybody, i want to know how could some guy send e-mails to all my users, although he is using a osh shell,, i have installed all the patches to my server, so how he can do it??, (it send a political e-mail from a non existing address outside my network).
thanks in advance

Pichi
 
You can send mail to anybody if you know his/her address - if you aren't blocked. Establish some mail filter on your mail server, use spamassassin or something like this, or block remote site entirely (iptables, access rule in your mail server etc)
 
hi, thanks for the advice, but that's something i know, but i don't know how he got all my users e-mail (we are talking aout 2000 users) i didn't give him the users list, so how he could send e-mails to all my users.

Pichi
 
Try to post headers from one of such files. It is possible that he is using some mass mail account, but maybe he got account list from some source... I'm not able to say more now.
 
It's easy to send mail like this.
Use an open relay and send from user123@bignameisphere.com.
The relay will send the mail and the mail server
verification only makes sure of the fact that the dns
domain of the sender exists in most mail scenarios.

Utilizing anything more strict breaks a lot of the
really bad systems in use today.

All you can do is snarf the headers and look back into
the transit history and complain to anyone with an open
relay carrying the junk. Or report the relay to a RBL,
and use your access_db and a mail filter to look/block
spam.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top