funsec mailing list archives

Re: Blacklisted by a mouse?


From: Steven Champeon <schampeo () hesketh com>
Date: Tue, 10 Jan 2006 11:57:00 -0500

on Tue, Jan 10, 2006 at 09:18:58AM -0500, jonathan.curtis () bell ca wrote:
 
 Diagnostic code: smtp;550 Not interested in mail from 
shawcable.net pool
 hosts. 

Unfortunately for a number of reasons, dynamic IP space has a poor
reputation. In Shaw's case, they don't block port 25 which allows you to
directly connect to Mouse's mail server. 

Yeah, and to mine. Over and over and over. Just in the past 24 hours, just
from one botnet, just sent to one dormant address from a piece of ratware
that HELO's as a random string of digits, and so it wouldn't get delivered
/anyway/:

S01060050ba4024b6.vf.shawcable.net [70.68.167.197]
S01060007e9754e87.cg.shawcable.net [68.144.204.2]
S01060050bf782700.gv.shawcable.net [24.68.149.182]
S01060007e9754e87.cg.shawcable.net [68.144.204.2]
S01060004ac6e8089.du.shawcable.net [70.67.215.115]
S01060007e9754e87.cg.shawcable.net [68.144.204.2]
S010600c0a88c3727.vf.shawcable.net [70.69.64.117]
S0106000d611c0eaf.rd.shawcable.net [70.65.101.90]
S0106000d611c0eaf.rd.shawcable.net [70.65.101.90]

That's out of 691 delivery attempts, making shawcable.net responsible
for 1.3% of all botnet traffic received here yesterday by that mailbox.

But if you can distinguish yourself from the sewer-like neighborhood
you're in, with static IP and non-generic rDNS, I'd be happy to receive
mail from you. 

-- 
hesketh.com/inc. v: +1(919)834-2552 f: +1(919)834-2554 w: http://hesketh.com
antispam news, solutions for sendmail, exim, postfix: http://enemieslist.com/
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: