using smtp-auth, but spammers getting through?

This is a discussion on using smtp-auth, but spammers getting through? within the alt.comp.mail.qmail forums, part of the Mail Servers and Related category; I have been running been running smtp-auth (http://members.elysium.pl/brush/qmail-smtpd-auth/) for years, but in ...


Go Back   Usenet Forums > Mail Servers and Related > alt.comp.mail.qmail

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-09-2003
James Thornton
 
Posts: n/a
Default using smtp-auth, but spammers getting through?

I have been running been running smtp-auth
(http://members.elysium.pl/brush/qmail-smtpd-auth/) for years, but in
the last week spammers have been using roam.unifiedmind.com -- I have
no idea how.

I'm logging with recordio, and I patched qmail with
qmail-smtpd-auth-log (http://tomclegg.net/qmail/#qmail-smtpd-auth-log)
so that I can view the user in the log file, but it doesn't appear
that they are authenticating (no relevant 235 lines).

Sample header...

Return-Path: <laott@msn.com>
Received: (qmail 1565 invoked from network); 9 Jul 2003 01:10:56 -0000
Received: from unknown (HELO smtp0321.mail.yahoo.com)
(webmaster@218.70.150.60)
by 0 with SMTP; 9 Jul 2003 01:10:56 -0000
Date: Wed, 9 Jul 2003 06:14:32 GMT
From: "darryll "<laott@msn.com>
X-Priority: 3
To: vasi@vic.com
Subject: vasi,FREE Sample of weight loss product!


Any ideas?
Reply With Quote
  #2 (permalink)  
Old 07-09-2003
Jonathan de Boyne Pollard
 
Posts: n/a
Default Re: using smtp-auth, but spammers getting through?

JT> I have been running been running smtp-auth for years, [...]

.... but haven't configured its password checking correctly, and the
unsolicited bulk mailers have finally spotted this.

220 roam.unifiedmind.com ESMTP
EHLO 0
250-roam.unifiedmind.com
250-AUTH LOGIN CRAM-MD5 PLAIN
250-AUTH=LOGIN CRAM-MD5 PLAIN
250-PIPELINING
250 8BITMIME
AUTH LOGIN
334 VXNlcm5hbWU6
piddle
334 UGFzc3dvcmQ6
piddle
235 ok, ¦']à, go ahead (#2.0.0)
MAIL FROM:<Spurious@example.invalid>
250 ok
RCPT TO:<Spurious@example.invalid>
250 ok
DATA
354 go ahead

The most common configuration mistake that produces this behaviour is to
forget one of the new arguments to "qmail-smtpd" and to thus end up running
"/bin/true" as one's password checking utility.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:14 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0