Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #193897 > unrolled thread

More then 2800 spams from the list...

Started by"Michelle Konzack" <linux4michelle@tamay-dogan.net>
First post2018-03-19 14:00 +0100
Last post2018-03-21 08:10 +0100
Articles 20 on this page of 29 — 17 participants

Back to article view | Back to linux.debian.user


Contents

  More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 14:00 +0100
    Re: More then 2800 spams from the list... Jonathan Dowland <jmtd@debian.org> - 2018-03-19 14:20 +0100
      Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 15:50 +0100
        Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 15:50 +0100
          Re: More then 2800 spams from the list... Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-19 16:10 +0100
            Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:30 +0100
              Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 16:40 +0100
                Re: More then 2800 spams from the list... Jim Popovitch <jim@k4vqc.com> - 2018-03-19 17:00 +0100
                Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 17:30 +0100
                  Re: More then 2800 spams from the list... Miles Fidelman <mfidelman@meetinghouse.net> - 2018-03-19 18:50 +0100
                    Re: More then 2800 spams from the list... Tony van der Hoff <lists@vanderhoff.org> - 2018-03-19 19:20 +0100
                      Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 19:30 +0100
                  Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 19:40 +0100
            Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 16:40 +0100
            Re: More then 2800 spams from the list... Curt <curty@free.fr> - 2018-03-19 18:20 +0100
        Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:00 +0100
    Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 19:40 +0100
      Re: More then 2800 spams from the list... Nick Boyce <nick@steelyglint.org> - 2018-03-19 22:20 +0100
        Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 22:40 +0100
      Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-19 23:30 +0100
        Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 09:00 +0100
          Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-20 10:30 +0100
            Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 10:50 +0100
            Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 13:30 +0100
              Re: More then 2800 spams from the list... David Wright <deblis@lionunicorn.co.uk> - 2018-03-20 14:40 +0100
                Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 14:50 +0100
            Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-20 20:00 +0100
              Re: More then 2800 spams from the list... Brian <ad44@cityscape.co.uk> - 2018-03-21 01:20 +0100
                Re: More then 2800 spams from the list... Brad Rogers <brad@fineby.me.uk> - 2018-03-21 08:10 +0100

Page 1 of 2  [1] 2  Next page →


#193897 — More then 2800 spams from the list...

From"Michelle Konzack" <linux4michelle@tamay-dogan.net>
Date2018-03-19 14:00 +0100
SubjectMore then 2800 spams from the list...
Message-ID<vv2ym-6C8-13@gated-at.bofh.it>
Hello and Listmaster/owner,

I have send on "Date: Mon, 19 Mar 2018 07:17:40 -0400" a message
to the list and now I got already 2800 Spams on one go!

The EMail responsabble for this shit is <helm7722@gmail.com>.

Please can you remove this EMail from the list?

The message is:

----8<------------------------------------------------------------------
Hello, this is the mail server on frash.longvieace.com.

I am sending you this message to inform you on the delivery status of a
message you previously sent.  Immediately below you will find a list of
the affected recipients;  also attached is a Delivery Status
Notification
(DSN) report in standard format, as well as the headers of the original
message.

  <helm7722@gmail.com>  delivery failed; will not continue trying
----8<------------------------------------------------------------------

All servers have exactly the same message...

The header are:

----8<------------------------------------------------------------------
Received: from localhost (127.0.0.1) by propt.simptor.net id
hlue5c16lt0i for <helm7722@gmail.com>; Mon, 19 Mar 2018 07:17:40
-0400 (envelope-from <linux4michelle@tamay-dogan.net>)
Received: from mail.tamay-dogan.net (mail.tamay-dogan.net
[78.47.247.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA
(256/256 bits)) (Client did not present a certificate) by
bendel.debian.org (Postfix) with ESMTPS id D474D57 for
<debian-user@lists.debian.org>; Mon, 19 Mar 2018 07:17:40 -0400
Received: from localhost (localhost [127.0.0.1])
  (uid 33)
  by mail.tamay-dogan.net with local; Mon, 19 Mar 2018 09:10:30 +0100
  id 0000000000001F47.5AAF7076.00000EF8
Received: from 37.157.105.227
        (SquirrelMail authenticated user michelle.konzack)
        by webmail.tamay-dogan.net with HTTP;
        Mon, 19 Mar 2018 07:17:40 -0400
Message-ID:
<8fab183a7c01f62340f38f1a9bbe6911.squirrel@webmail.tamay-dogan.net>
In-Reply-To:
<CANnei0H3xGxyMuaOjE7E+hQJTb19QQXGDVGg51Z8_3ZUWadE4w@mail.gmail.com>
References:
<CANnei0H3xGxyMuaOjE7E+hQJTb19QQXGDVGg51Z8_3ZUWadE4w@mail.gmail.com>
Date: Mon, 19 Mar 2018 07:17:40 -0400
Subject: diFAy ier871 188.164.196.32
From: Michelle Konzack <linux4michelle@tamay-dogan.net>
To: debian-user@lists.debian.org
User-Agent: SquirrelMail/1.4.23 [SVN]
Mime-Version: 1.0
OpenPGP: id=A5957FD8834573E2;
url=http://michelle.konzack.tdhome.net/public.gpg
X-Mime-Autoconverted: from 8bit to 7bit by courier 0.68
X-Rc-Virus: 2007-09-13_01
X-Rc-Spam: 2008-11-04_01
Resent-Message-ID: <6M7pfiS7BiG.A.GlG.HC3raB@bendel>
Resent-From: debian-user@lists.debian.org
X-Mailing-List: <debian-user@lists.debian.org> archive/latest/733721
X-Loop: debian-user@lists.debian.org
List-Id: <debian-user.lists.debian.org>
List-URL: <https://lists.debian.org/debian-user/>
List-Post: <mailto:debian-user@lists.debian.org>
List-Help: <mailto:debian-user-request@lists.debian.org?subject=help>
List-Subscribe:
<mailto:debian-user-request@lists.debian.org?subject=subscribe>
List-Unsubscribe:
<mailto:debian-user-request@lists.debian.org?subject=unsubscribe>
Precedence: list
Resent-Sender: debian-user-request@lists.debian.org
List-Archive:
https://lists.debian.org/msgid-search/8fab183a7c01f62340f38f1a9bbe6911.squirrel@webmail.tamay-dogan.net
Resent-Date: Mon, 19 Mar 2018 08:10:47 +0000 (UTC)
Content-Type: text/html
----8<------------------------------------------------------------------

This how it looks like in squirrelmail:

----8<------------------------------------------------------------------
>From sort                               Received sort	Subject sort
postmaster@midr.longvieace.com		Mar 19, 2018  	Delivery report
postmaster@frash.longvieace.com		Mar 19, 2018  	Delivery report
postmaster@picao.staoration.com		Mar 19, 2018  	Delivery report
postmaster@zem.templrch.com		Mar 19, 2018  	Delivery report
postmaster@smpx.rockweional.net		Mar 19, 2018  	Delivery report
postmaster@frasca.accemix.com		Mar 19, 2018  	Delivery report
postmaster@wbbuzz.accemix.com		Mar 19, 2018  	Delivery report
postmaster@prope.diversiags.net		Mar 19, 2018  	Delivery report
postmaster@bleza.diversiags.net		Mar 19, 2018  	Delivery report
postmaster@khabhi.diversiags.net	Mar 19, 2018  	Delivery report
postmaster@atl161.firenus.net		Mar 19, 2018  	Delivery report
postmaster@frasca.regarun.net		Mar 19, 2018  	Delivery report
postmaster@frasca.pueting.net		Mar 19, 2018  	Delivery report
postmaster@ninbun.northtion.net		Mar 19, 2018  	Delivery report
postmaster@laera.bridgesunstone.com	Mar 19, 2018  	Delivery report
postmaster@iclp.bridgesunstone.com	Mar 19, 2018  	Delivery report
postmaster@vedl.fishetants.net		Mar 19, 2018  	Delivery report
postmaster@exchange.moestates.net	Mar 19, 2018  	Delivery report
postmaster@picmy.renrs.net		Mar 19, 2018  	Delivery report
postmaster@renrs.net			Mar 19, 2018  	Delivery report
postmaster@zem.renrs.net		Mar 19, 2018  	Delivery report
postmaster@raik.buzrity.com		Mar 19, 2018  	Delivery report
postmaster@msgin.buzrity.com		Mar 19, 2018  	Delivery report
postmaster@iclp.renrs.net		Mar 19, 2018  	Delivery report
postmaster@buzrity.com			Mar 19, 2018  	Delivery report
postmaster@rivara.buzrity.com		Mar 19, 2018  	Delivery report
postmaster@wbbuzz.bikader.net		Mar 19, 2018  	Delivery report
postmaster@frasl.renrs.net		Mar 19, 2018  	Delivery report
postmaster@netsy.casaeetop.net		Mar 19, 2018  	Delivery report
postmaster@midpit.casaeetop.net		Mar 19, 2018  	Delivery report
postmaster@picao.reacacy.com		Mar 19, 2018  	Delivery report
postmaster@febric.staoration.com	Mar 19, 2018  	Delivery report
postmaster@laerka.staoration.com	Mar 19, 2018  	Delivery report
postmaster@ohrs.longvieace.com		Mar 19, 2018  	Delivery report
postmaster@simptor.net			Mar 19, 2018  	Delivery report
postmaster@vedla.simptor.net		Mar 19, 2018  	Delivery report
postmaster@pop3.simptor.net		Mar 19, 2018  	Delivery report
postmaster@propt.simptor.net		Mar 19, 2018  	Delivery report
----8<------------------------------------------------------------------

While writing this EMail, the spam increased to 3118.

Thanks in advance

-- 
Michelle Konzack        Miila ITSystems @ TDnet
GNU/Linux Developer     00372-54541400

[toc] | [next] | [standalone]


#193898

FromJonathan Dowland <jmtd@debian.org>
Date2018-03-19 14:20 +0100
Message-ID<vv2RH-6Yt-1@gated-at.bofh.it>
In reply to#193897
This does not belong on debian-user (and indeed posting it will only
make matters worse for you and us)


-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#193901

FromGene Heskett <gheskett@shentel.net>
Date2018-03-19 15:50 +0100
Message-ID<vv4gO-7NP-7@gated-at.bofh.it>
In reply to#193898
On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:

> This does not belong on debian-user (and indeed posting it will only
> make matters worse for you and us)

Jonathon, why berate the poor user for what may your servers 
malperformance, which since I am subscribed and didn't get them, I'd put 
the blame on downstream, perhaps even in Michelles own ISP's server, and 
do it without telling her where the complaint should have been sent. 

-- 
Cheers, Gene Heskett
--
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#193902

From<tomas@tuxteam.de>
Date2018-03-19 15:50 +0100
Message-ID<vv4gO-7NP-11@gated-at.bofh.it>
In reply to#193901
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 19, 2018 at 10:40:10AM -0400, Gene Heskett wrote:
> On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:
> 
> > This does not belong on debian-user (and indeed posting it will only
> > make matters worse for you and us)
> 
> Jonathon, why berate the poor user for what may your servers 
> malperformance, which since I am subscribed and didn't get them, I'd put 
> the blame on downstream, perhaps even in Michelles own ISP's server, and 
> do it without telling her where the complaint should have been sent. 

No, Jonathan is right. Resending the spam to -user is not productive
(and perhaps exactly what the spammers want you to do: multiply by 3000
at no cost to them). Michelle put <debian-user-owner@lists.debian.org>
already on the cc which *might* be more relevant.

You can try to do the best of it and have a go at the header analysis:
are they legit or spoof?

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqvzZ0ACgkQBcgs9XrR2kamHgCfYJ6OGEf7qCMBBOhl9Me1KA8x
azQAniTjCx4IOYA+yAOdJ9zH6l+81ea4
=MV44
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#193907

FromCindy-Sue Causey <butterflybytes@gmail.com>
Date2018-03-19 16:10 +0100
Message-ID<vv4A9-8aE-5@gated-at.bofh.it>
In reply to#193902
On 3/19/18, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Mon, Mar 19, 2018 at 10:40:10AM -0400, Gene Heskett wrote:
>> On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:
>>
>> > This does not belong on debian-user (and indeed posting it will only
>> > make matters worse for you and us)
>>
>> Jonathon, why berate the poor user for what may your servers
>> malperformance, which since I am subscribed and didn't get them, I'd put
>> the blame on downstream, perhaps even in Michelles own ISP's server, and
>> do it without telling her where the complaint should have been sent.
>
> No, Jonathan is right. Resending the spam to -user is not productive
> (and perhaps exactly what the spammers want you to do: multiply by 3000
> at no cost to them). Michelle put <debian-user-owner@lists.debian.org>
> already on the cc which *might* be more relevant.
>
> You can try to do the best of it and have a go at the header analysis:
> are they legit or spoof?


Did anyone else receive more than the one very obviously spoofed
Debian-User email over the weekend?

Cindy :)
-- 
Cindy-Sue Causey
Talking Rock, Pickens County, Georgia, USA

* runs with duct tape *

[toc] | [prev] | [next] | [standalone]


#193909

FromRichard Owlett <rowlett@cloud85.net>
Date2018-03-19 16:30 +0100
Message-ID<vv4Tw-8gF-5@gated-at.bofh.it>
In reply to#193907
On 03/19/2018 10:07 AM, Cindy-Sue Causey wrote:
> On 3/19/18, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> On Mon, Mar 19, 2018 at 10:40:10AM -0400, Gene Heskett wrote:
>>> On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:
>>>
>>>> This does not belong on debian-user (and indeed posting it will only
>>>> make matters worse for you and us)
>>>
>>> Jonathon, why berate the poor user for what may your servers
>>> malperformance, which since I am subscribed and didn't get them, I'd put
>>> the blame on downstream, perhaps even in Michelles own ISP's server, and
>>> do it without telling her where the complaint should have been sent.
>>
>> No, Jonathan is right. Resending the spam to -user is not productive
>> (and perhaps exactly what the spammers want you to do: multiply by 3000
>> at no cost to them). Michelle put <debian-user-owner@lists.debian.org>
>> already on the cc which *might* be more relevant.
>>
>> You can try to do the best of it and have a go at the header analysis:
>> are they legit or spoof?
> 
> 
> Did anyone else receive more than the one very obviously spoofed
> Debian-User email over the weekend?
> 
> Cindy :)
> 

I didn't. But as my ISP has an excellent spam filter I don't see what 
many others see. I suspect the key is interpreting the header 
information the OP gave. Is there a guide for an average user to 
interpreting that information?

[toc] | [prev] | [next] | [standalone]


#193911

From"Michelle Konzack" <linux4michelle@tamay-dogan.net>
Date2018-03-19 16:40 +0100
Message-ID<vv53h-8jE-3@gated-at.bofh.it>
In reply to#193909
Hello Richard and *,

Am 2018-03-19 hackte Richard Owlett in die Tasten:
> I didn't. But as my ISP has an excellent spam filter I don't see what
> many others see. I suspect the key is interpreting the header
> information the OP gave. Is there a guide for an average user to
> interpreting that information?

It seems, the spamer is on the List and manipulated the Mailinglist
messages b using the original headers removed anything newer then
the <bendel> Receied Headers and sent the message to more then 17000
servers.

<mail.tamay-dogan.net> is subject of a DOS attack.

It seems, the Attacker know probably several 10.000 wrong configured
mailservers and now use it, to pull down my server...

I am sure, this attacker is here on the list, because it started with
my anser to "[LEARNING OUTCOME] Wi-Fi WPA Hacking Tool is Totally
Useless on New Wireless Routers".

Greetings

-- 
Michelle Konzack        Miila ITSystems @ TDnet
GNU/Linux Developer     00372-54541400

[toc] | [prev] | [next] | [standalone]


#193914

FromJim Popovitch <jim@k4vqc.com>
Date2018-03-19 17:00 +0100
Message-ID<vv5mx-8qk-1@gated-at.bofh.it>
In reply to#193911

[Multipart message — attachments visible in raw view] — view raw

On Mon, 2018-03-19 at 17:35 +0200, Michelle Konzack wrote:
> I am sure, this attacker is here on the list, because it started with
> my anser to "[LEARNING OUTCOME] Wi-Fi WPA Hacking Tool is Totally
> Useless on New Wireless Routers".
> 

Replying solely because I live/lust for parties like these
(seriously!).

Let's see what kind of "presents" i get.

-Jim P. 

[toc] | [prev] | [next] | [standalone]


#193917

From<tomas@tuxteam.de>
Date2018-03-19 17:30 +0100
Message-ID<vv5PA-po-7@gated-at.bofh.it>
In reply to#193911
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 19, 2018 at 05:35:04PM +0200, Michelle Konzack wrote:
> Hello Richard and *,
> 
> Am 2018-03-19 hackte Richard Owlett in die Tasten:
> > I didn't. But as my ISP has an excellent spam filter I don't see what
> > many others see. I suspect the key is interpreting the header
> > information the OP gave. Is there a guide for an average user to
> > interpreting that information?
> 
> It seems, the spamer is on the List and manipulated the Mailinglist
> messages b using the original headers removed anything newer then
> the <bendel> Receied Headers and sent the message to more then 17000
> servers.

What do you mean by "the spammer is on the list"? The spam messages
don't go via list. I would get them (my own mail server and no spam
filter beyond the standard Exim header checking, which would never
drop/reject a mail coming from the list).

> <mail.tamay-dogan.net> is subject of a DOS attack.

Yes, I rather think they are targetting you. The Debian mailing
list headers seem to me (well placed) spoof.

> It seems, the Attacker know probably several 10.000 wrong configured
> mailservers and now use it, to pull down my server...

Yes, that's how it looks to me. Perhaps they're real bounces,
perhaps they're fake. But I'm pretty sure by now that the
Debian-list related headers are plain fake, to nudge people
into "responding to list" and thus spreading the spam even
more. So folks, don't do that. And if you do, at least strongly
snip the original (as Michelle has done, thankfully) and don't
include the whole kaboodle, top-posting style (you don't top-post,
do you ;-)

FWIW, I've sent a test mesage to (some randomly chosen user name)
at one of the servers in list and am awaiting a bounce message.

Let's see...

@Michelle: could you please send me a *complete* bounce message,
headers and all, as it arrives at your place? I still can't figure
out what kind of headers you sent to this list.

Thanks
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqv498ACgkQBcgs9XrR2kYoxwCfaN5x3Zwsa6/PKUsJTKz+cSfY
DukAn2FiLNAOLzMzGGoHAH4CJdN/zQCL
=79xT
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#193921

FromMiles Fidelman <mfidelman@meetinghouse.net>
Date2018-03-19 18:50 +0100
Message-ID<vv74Z-18I-1@gated-at.bofh.it>
In reply to#193917

[Multipart message — attachments visible in raw view] — view raw

Comments at end.


On 3/19/18 12:22 PM, tomas@tuxteam.de wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Mon, Mar 19, 2018 at 05:35:04PM +0200, Michelle Konzack wrote:
>> Hello Richard and *,
>>
>> Am 2018-03-19 hackte Richard Owlett in die Tasten:
>>> I didn't. But as my ISP has an excellent spam filter I don't see what
>>> many others see. I suspect the key is interpreting the header
>>> information the OP gave. Is there a guide for an average user to
>>> interpreting that information?
>> It seems, the spamer is on the List and manipulated the Mailinglist
>> messages b using the original headers removed anything newer then
>> the <bendel> Receied Headers and sent the message to more then 17000
>> servers.
> What do you mean by "the spammer is on the list"? The spam messages
> don't go via list. I would get them (my own mail server and no spam
> filter beyond the standard Exim header checking, which would never
> drop/reject a mail coming from the list).
>
>> <mail.tamay-dogan.net> is subject of a DOS attack.
> Yes, I rather think they are targetting you. The Debian mailing
> list headers seem to me (well placed) spoof.
>
>> It seems, the Attacker know probably several 10.000 wrong configured
>> mailservers and now use it, to pull down my server...
> Yes, that's how it looks to me. Perhaps they're real bounces,
> perhaps they're fake. But I'm pretty sure by now that the
> Debian-list related headers are plain fake, to nudge people
> into "responding to list" and thus spreading the spam even
> more. So folks, don't do that. And if you do, at least strongly
> snip the original (as Michelle has done, thankfully) and don't
> include the whole kaboodle, top-posting style (you don't top-post,
> do you ;-)
>
> FWIW, I've sent a test mesage to (some randomly chosen user name)
> at one of the servers in list and am awaiting a bounce message.
>
> Let's see...
>
> @Michelle: could you please send me a *complete* bounce message,
> headers and all, as it arrives at your place? I still can't figure
> out what kind of headers you sent to this list.
>
>

Actually, what's more important are a collection of spam & bounce 
messages - both from Michelle, and anybody else who's seen the spam.

That way we can tell if they're all coming from one place (the list, or 
otherwise) or if they're coming from lots of sites across a botnet.

All we know right now is

1. the mailer (purportedly) at freash.longvieace.com is reporting a ton 
of bounces on a mail that purportedly came from Michelle via 
Debian-user, and

2. the spam (purportedly) got to that mailer from mail.tamay-dogan.net

None of the other headers can be trusted.  Actually, not even that 
message can be trusted - except that spambots don't generally report 
bounces.

One needs more copies of the spam, and more bounce messages, to figure 
out what's going on.

The general assumption here is that some spambot has manufactured 
headers that make it look like a message from Michelle to Debian-User.  
Beyond that, we really don't know anything useful or actionable.

Miles Fidelman (who deals with this sh*t on too many lists that he 
manages, sigh...)







-- 
In theory, there is no difference between theory and practice.
In practice, there is.  .... Yogi Berra

[toc] | [prev] | [next] | [standalone]


#193922

FromTony van der Hoff <lists@vanderhoff.org>
Date2018-03-19 19:20 +0100
Message-ID<vv7y1-1xQ-9@gated-at.bofh.it>
In reply to#193921
On 19/03/18 17:38, Miles Fidelman wrote:
>
> Comments at end.
>
Where they should be. If you can avoid the HTML, and change your sig.sep to
<dash><dash><space>, you're on your way to becoming a hero on this list.

[toc] | [prev] | [next] | [standalone]


#193923

From<tomas@tuxteam.de>
Date2018-03-19 19:30 +0100
Message-ID<vv7HI-1AZ-11@gated-at.bofh.it>
In reply to#193922
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 19, 2018 at 05:54:10PM +0000, Tony van der Hoff wrote:
> On 19/03/18 17:38, Miles Fidelman wrote:
> >
> > Comments at end.
> >
> Where they should be. If you can avoid the HTML, and change your sig.sep to
> <dash><dash><space>, you're on your way to becoming a hero on this list.

Actually he does and it is (hint: his mail is a mime/multipart
alternative, with one plain text and one HTML alternative, which
is fine. If your MUA does The Right Thing, it'll show you the
text alternative, with dash-dash-space signature separator and
all :-)

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqwAREACgkQBcgs9XrR2kYVQQCfZsiqvQ71mC5ETvumLPA+byLq
ETwAn3KiVjWuoCeRMIWbCcuZ7wwFXIvY
=Enel
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#193925

From"Michelle Konzack" <linux4michelle@tamay-dogan.net>
Date2018-03-19 19:40 +0100
Message-ID<vv7Ro-1Et-13@gated-at.bofh.it>
In reply to#193917
Now I have made a script to analyse where the traffic is comming from:

A singel network in Spain!

Am 2018-03-19 hackte tomas@tuxteam.de in die Tasten:
> What do you mean by "the spammer is on the list"? The spam messages
> don't go via list. I would get them (my own mail server and no spam
> filter beyond the standard Exim header checking, which would never
> drop/reject a mail coming from the list).
>
>> <mail.tamay-dogan.net> is subject of a DOS attack.
>
> Yes, I rather think they are targetting you. The Debian mailing
> list headers seem to me (well placed) spoof.
>
>> It seems, the Attacker know probably several 10.000 wrong configured
>> mailservers and now use it, to pull down my server...
>
> Yes, that's how it looks to me. Perhaps they're real bounces,
> perhaps they're fake. But I'm pretty sure by now that the
> Debian-list related headers are plain fake, to nudge people
> into "responding to list" and thus spreading the spam even
> more.

I am attacked by this network:

----[ c 'whois -B 188.164.196.32' ]-------------------------------------
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Information related to '188.164.192.0 - 188.164.199.255'

% Abuse contact for '188.164.192.0 - 188.164.199.255' is
'abuse@infortelecom.es'

inetnum:        188.164.192.0 - 188.164.199.255
netname:        ES-INFORTELECOM-20120912
country:        ES
org:            ORG-ISS3-RIPE
admin-c:        JDDG1-RIPE
tech-c:         JDDG1-RIPE
status:         ALLOCATED PA
mnt-by:         RIPE-NCC-HM-MNT
mnt-by:         AS50926-MNT
created:        2012-09-12T11:52:24Z
last-modified:  2017-11-30T11:26:09Z
source:         RIPE

organisation:   ORG-ISS3-RIPE
org-name:       Infortelecom Hosting S.L.
org-type:       LIR
address:        Ronda Narciso Monturiol, num.17
                Puerta 1 1 Parque Tecnologico
address:        46980
address:        Paterna - VALENCIA
address:        SPAIN
phone:          +34910820073
phone:          +34963788771
e-mail:         jdomenech@infortelecom.es
admin-c:        JDDG1-RIPE
admin-c:        VGP13-RIPE
abuse-c:        ABIT11-RIPE
mnt-ref:        RIPE-NCC-HM-MNT
mnt-ref:        AS50926-MNT
mnt-by:         RIPE-NCC-HM-MNT
mnt-by:         AS50926-MNT
created:        2004-10-07T15:33:06Z
last-modified:  2017-10-30T14:49:58Z
source:         RIPE

person:         Jose Daniel Domenech Gasco
address:        C/ Ciudad de Sevilla, 76 - Pol. Ind. Fuente del Jarro
address:        46980 Paterna
address:        Valencia, SPAIN
e-mail:         jdomenech@infortelecom.es
phone:          +34963788771
fax-no:         +34960451442
nic-hdl:        JDDG1-RIPE
mnt-by:         AS50926-MNT
created:        2002-10-08T14:20:22Z
last-modified:  2013-04-03T16:12:35Z
source:         RIPE

% Information related to '188.164.196.0/24AS50926'

route:          188.164.196.0/24
origin:         AS50926
descr:          AXARnet-Network
mnt-by:         AXARNET-MNT
mnt-by:         AS50926-MNT
created:        2017-05-16T10:01:19Z
last-modified:  2017-05-16T10:01:19Z
source:         RIPE

% This query was served by the RIPE Database Query Service version
1.91.1 (BLAARKOP)
-----------------------------------------------------------------------

They have several 1000 mailservers which send me this crap...

...and if I read on theire website "VPS & CLOUD" my alarm bells are
ringing.  I blocked there WHOLE network!


> FWIW, I've sent a test mesage to (some randomly chosen user name)
> at one of the servers in list and am awaiting a bounce message.
>
> Let's see...
>
> @Michelle: could you please send me a *complete* bounce message,
> headers and all, as it arrives at your place? I still can't figure
> out what kind of headers you sent to this list.

yes in some seconds.

> Thanks
> - -- tomás

Thanks in advance

-- 
Michelle Konzack        Miila ITSystems @ TDnet
GNU/Linux Developer     00372-54541400

[toc] | [prev] | [next] | [standalone]


#193912

FromGene Heskett <gheskett@shentel.net>
Date2018-03-19 16:40 +0100
Message-ID<vv53h-8jE-7@gated-at.bofh.it>
In reply to#193907
On Monday 19 March 2018 11:07:39 Cindy-Sue Causey wrote:

> On 3/19/18, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > On Mon, Mar 19, 2018 at 10:40:10AM -0400, Gene Heskett wrote:
> >> On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:
> >> > This does not belong on debian-user (and indeed posting it will
> >> > only make matters worse for you and us)
> >>
> >> Jonathon, why berate the poor user for what may your servers
> >> malperformance, which since I am subscribed and didn't get them,
> >> I'd put the blame on downstream, perhaps even in Michelles own
> >> ISP's server, and do it without telling her where the complaint
> >> should have been sent.
> >
> > No, Jonathan is right. Resending the spam to -user is not productive
> > (and perhaps exactly what the spammers want you to do: multiply by
> > 3000 at no cost to them). Michelle put
> > <debian-user-owner@lists.debian.org> already on the cc which *might*
> > be more relevant.
> >
> > You can try to do the best of it and have a go at the header
> > analysis: are they legit or spoof?
>
> Did anyone else receive more than the one very obviously spoofed
> Debian-User email over the weekend?
>
> Cindy :)

I got 2 copies of a msg posted by Tomas, but that was it.


-- 
Cheers, Gene Heskett
--
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#193920

FromCurt <curty@free.fr>
Date2018-03-19 18:20 +0100
Message-ID<vv6BX-YW-1@gated-at.bofh.it>
In reply to#193907
On 2018-03-19, Cindy-Sue Causey <butterflybytes@gmail.com> wrote:
>
> Did anyone else receive more than the one very obviously spoofed
> Debian-User email over the weekend?

I received just now, after a followup to Brian in this group via the gmane
service, a bounce:

 Delivery has failed to these recipients or groups:

 kisscoolatgb@lacabanedeladmin.trickip.net
 Your message couldn't be delivered. The Domain Name System (DNS)
 reported that the recipient's domain
 does not exist.

with my followup message to the list (which arrived here safely) attached.

I admit I don't get it (I mean I got it, but I don't get it).

> Cindy :)


-- 
Bah, the latest news, the latest news is not the last.
Samuel Beckett

[toc] | [prev] | [next] | [standalone]


#193905

FromRichard Owlett <rowlett@cloud85.net>
Date2018-03-19 16:00 +0100
Message-ID<vv4qu-7S1-9@gated-at.bofh.it>
In reply to#193901
On 03/19/2018 09:40 AM, Gene Heskett wrote:
> On Monday 19 March 2018 09:14:19 Jonathan Dowland wrote:
> 
>> This does not belong on debian-user (and indeed posting it will only
>> make matters worse for you and us)
> 
> Jonathon, why berate the poor user for what may your servers
> malperformance, which since I am subscribed and didn't get them, I'd put
> the blame on downstream, perhaps even in Michelles own ISP's server, and
> do it without telling her where the complaint should have been sent.
> 

*+1*

[toc] | [prev] | [next] | [standalone]


#193924

FromKarol Augustin <karol@augustin.pl>
Date2018-03-19 19:40 +0100
Message-ID<vv7Rn-1Et-9@gated-at.bofh.it>
In reply to#193897
On 2018-03-19 12:58, Michelle Konzack wrote:
> Hello and Listmaster/owner,
> 
> I have send on "Date: Mon, 19 Mar 2018 07:17:40 -0400" a message
> to the list and now I got already 2800 Spams on one go!
> 
> The EMail responsabble for this shit is <helm7722@gmail.com>.
> 
> Please can you remove this EMail from the list?
> 
> The message is:
> 
> ----8<------------------------------------------------------------------
> Hello, this is the mail server on frash.longvieace.com.
> 
> I am sending you this message to inform you on the delivery status of a
> message you previously sent.  Immediately below you will find a list of
> the affected recipients;  also attached is a Delivery Status
> Notification
> (DSN) report in standard format, as well as the headers of the original
> message.
> 
>   <helm7722@gmail.com>  delivery failed; will not continue trying
> ----8<------------------------------------------------------------------
> 
> All servers have exactly the same message...
> 

> 
> While writing this EMail, the spam increased to 3118.
> 
> Thanks in advance



It looks like you are hit by backscatter bounces. Someone uses your
e-mail (in prepared message) as sender and spams the misconfigured
servers which send you bounces as they can't deliver spammers message to
the recipient.

This is precisely why e-mail server should never send bounces to
non-local senders. When sender is spoofed as in this case then is hit
with thousands of DSNs.

As most of the time people want to get DSNs for emails they sent it is
hard to mitigate using spam filtering software. You just have bad
luck/you are targeted.

k.


-- 
Karol Augustin
karol@augustin.pl
http://karolaugustin.pl/
+353 85 775 5312

[toc] | [prev] | [next] | [standalone]


#193930

FromNick Boyce <nick@steelyglint.org>
Date2018-03-19 22:20 +0100
Message-ID<vvame-3v7-13@gated-at.bofh.it>
In reply to#193924
On Mon, 19 Mar 2018 18:31:48 +0000
Karol Augustin <karol@augustin.pl> wrote:

> On 2018-03-19 12:58, Michelle Konzack wrote:
> > Hello and Listmaster/owner,
> > 
> > I have send on "Date: Mon, 19 Mar 2018 07:17:40 -0400" a message
> > to the list and now I got already 2800 Spams on one go!
> > 
> > The EMail responsabble for this shit is <helm7722@gmail.com>.
[...]
----8<------------------------------------------------------------------
> > Hello, this is the mail server on frash.longvieace.com.
> > 
> > I am sending you this message to inform you on the delivery status of a
> > message you previously sent.  Immediately below you will find a list of
> > the affected recipients;  also attached is a Delivery Status
> > Notification
[...]
> It looks like you are hit by backscatter bounces. Someone uses your
> e-mail (in prepared message) as sender and spams the misconfigured
> servers which send you bounces as they can't deliver spammers message to
> the recipient.

+1
Exactly what Karol said - someone has used your email address as the sender for a spamming run, and you're being hit by all the bounces from all the receiving mailservers that quite properly reject the spam, but quite wrongly send a bounce to the supposed sender instead of to the mailserver that established the SMTP connection.

It's just your bad luck that it was your address that the spammer chose.  It's happened to me before now, and it was the most miserable period of weeks before the flood of backscatter DSNs slowed and then stopped.  There is almost no way of filtering the damn things out, because they're coming from all over the Internet and you usually *do* want to see such things.  Console yourself with planning what you would do to the spammer if you ever got hold of them.
 
> This is precisely why e-mail server should never send bounces to
> non-local senders. When sender is spoofed as in this case then is hit
> with thousands of DSNs.

Yes ... sigh.

Pleasingly, some spammers are being tracked down and are going to jail for long periods of time.

http://www.theregister.co.uk/2005/11/17/spammer_jailed/print.html
https://usatoday30.usatoday.com/tech/news/computersecurity/2008-04-29-spam-sentencing_N.htm
https://www.telegraph.co.uk/news/worldnews/northamerica/usa/6653892/Godfather-of-spam-jailed-for-four-years.html
https://www.independent.co.uk/life-style/gadgets-and-tech/news/spam-emails-millions-us-man-michael-persaud-arizona-jail-time-prison-send-out-spamming-a7577216.html

Nick
-- 
Never FDISK after midnight.

[toc] | [prev] | [next] | [standalone]


#193932

FromKarol Augustin <karol@augustin.pl>
Date2018-03-19 22:40 +0100
Message-ID<vvaFA-3CJ-15@gated-at.bofh.it>
In reply to#193930
On 2018-03-19 20:50, Nick Boyce wrote:
> On Mon, 19 Mar 2018 18:31:48 +0000
> Karol Augustin <karol@augustin.pl> wrote:
> 
>> On 2018-03-19 12:58, Michelle Konzack wrote:
>> > Hello and Listmaster/owner,
>> >
>> > I have send on "Date: Mon, 19 Mar 2018 07:17:40 -0400" a message
>> > to the list and now I got already 2800 Spams on one go!
>> >
>> > The EMail responsabble for this shit is <helm7722@gmail.com>.
> [...]
> ----8<------------------------------------------------------------------
>> > Hello, this is the mail server on frash.longvieace.com.
>> >
>> > I am sending you this message to inform you on the delivery status of a
>> > message you previously sent.  Immediately below you will find a list of
>> > the affected recipients;  also attached is a Delivery Status
>> > Notification
> [...]
>> It looks like you are hit by backscatter bounces. Someone uses your
>> e-mail (in prepared message) as sender and spams the misconfigured
>> servers which send you bounces as they can't deliver spammers message to
>> the recipient.
> 
> +1
> Exactly what Karol said - someone has used your email address as the
> sender for a spamming run, and you're being hit by all the bounces
> from all the receiving mailservers that quite properly reject the
> spam, but quite wrongly send a bounce to the supposed sender instead
> of to the mailserver that established the SMTP connection.
> 
> It's just your bad luck that it was your address that the spammer
> chose.  It's happened to me before now, and it was the most miserable
> period of weeks before the flood of backscatter DSNs slowed and then
> stopped.  There is almost no way of filtering the damn things out,
> because they're coming from all over the Internet and you usually *do*
> want to see such things.  Console yourself with planning what you
> would do to the spammer if you ever got hold of them.
>  
>> This is precisely why e-mail server should never send bounces to
>> non-local senders. When sender is spoofed as in this case then is hit
>> with thousands of DSNs.
> 
> Yes ... sigh.
> 
> Pleasingly, some spammers are being tracked down and are going to jail
> for long periods of time.
> 
> http://www.theregister.co.uk/2005/11/17/spammer_jailed/print.html
> https://usatoday30.usatoday.com/tech/news/computersecurity/2008-04-29-spam-sentencing_N.htm
> https://www.telegraph.co.uk/news/worldnews/northamerica/usa/6653892/Godfather-of-spam-jailed-for-four-years.html
> https://www.independent.co.uk/life-style/gadgets-and-tech/news/spam-emails-millions-us-man-michael-persaud-arizona-jail-time-prison-send-out-spamming-a7577216.html
> 
> Nick

You can use http://www.backscatterer.org/?target=usage
I don't know what is the quality of this list, but if used as described
in what they call "safe mode" it will be only check against if sender is
null or postmaster@, which should stop all DSNs from servers they have
listed.

Have to look into implementing this on my server just in case...
k.

-- 
Karol Augustin
karol@augustin.pl
http://karolaugustin.pl/
+353 85 775 5312

[toc] | [prev] | [next] | [standalone]


#193934

FromJoe <joe@jretrading.com>
Date2018-03-19 23:30 +0100
Message-ID<vvbrY-49V-5@gated-at.bofh.it>
In reply to#193924
On Mon, 19 Mar 2018 18:31:48 +0000
Karol Augustin <karol@augustin.pl> wrote:

> On 2018-03-19 12:58, Michelle Konzack wrote:
> > Hello and Listmaster/owner,
> > 
> > I have send on "Date: Mon, 19 Mar 2018 07:17:40 -0400" a message
> > to the list and now I got already 2800 Spams on one go!
> > 
> > The EMail responsabble for this shit is <helm7722@gmail.com>.
> > 
> > Please can you remove this EMail from the list?
> > 
> > The message is:
> > 
> > ----8<------------------------------------------------------------------
> > Hello, this is the mail server on frash.longvieace.com.
> > 
> > I am sending you this message to inform you on the delivery status
> > of a message you previously sent.  Immediately below you will find
> > a list of the affected recipients;  also attached is a Delivery
> > Status Notification
> > (DSN) report in standard format, as well as the headers of the
> > original message.
> > 
> >   <helm7722@gmail.com>  delivery failed; will not continue trying
> > ----8<------------------------------------------------------------------
> > 
> > All servers have exactly the same message...
> >   
> 
> > 
> > While writing this EMail, the spam increased to 3118.
> > 
> > Thanks in advance  
> 
> 
> 
> It looks like you are hit by backscatter bounces. Someone uses your
> e-mail (in prepared message) as sender and spams the misconfigured
> servers which send you bounces as they can't deliver spammers message
> to the recipient.
> 
> This is precisely why e-mail server should never send bounces to
> non-local senders. When sender is spoofed as in this case then is hit
> with thousands of DSNs.
> 
> As most of the time people want to get DSNs for emails they sent it is
> hard to mitigate using spam filtering software. You just have bad
> luck/you are targeted.

You do it by never accepting email for non-existent users. The problem
is the use of a mail server which accepts absolutely anything for the
domain, then finds that the end user rejects the rubbish. Having
accepted it in the first place, the receiving mail server is then
required to admit that it can't deliver it, by means of an NDR. It does
this using the reply-to address, which is easily forged.

The fix is that *all* incoming SMTP servers for the domain, primary and
backup, have a list of valid users (spammers often target
lower-priority MX records, as a backup server often doesn't have a user
account list). They must reject all other recipients at SMTP handshake
time, completely ignoring whatever has been forged in the headers. Spam
filtering doesn't do the job at all, the mail has already been accepted
by the time that sees it.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web