Security Basics mailing list archives

Re: Receiving spam from my own server


From: "Dave Moore" <dave.j.moore () gmail com>
Date: Wed, 6 Dec 2006 16:31:22 -0600

On 12/6/06, Adam Rosen <ajrosen () buffdata com> wrote:
Dave,

When you say "I am receiving spam e-mails", what inbox is getting those
emails? Is it your dave.j.moore () gmail com account?

Yes.

Do you have any
forwarding set up for any email to someone () foobar net to go to that
address? If info () foobar net for example is set to forward to your gmail
account, than this is common - and the sender address is the easiest
thing to forge.

root () avitas net forwards to me. I have not set up any other
forwarders, and I have sent messages of my own to the address in
question (info () avitas net) to make sure that they are not forwarding.

Making it look as if someone inside your domain is the
sender is an old trick. I'd say that someone sent an email to
info () foobar net where it got picked up by an internal mail server which
then forwarded the mail to gmail.

Adam

Thanks for your help!
Dave

---------------------------------------------------------------------------
This list is sponsored by: ByteCrusher

Detect Malicious Web Content and Exploits in Real-Time.
Anti-Virus engines can't detect unknown or new threats.
LinkScanner can. Web surfing just became a whole lot safer.

http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildetect
---------------------------------------------------------------------------


Current thread: