Security Incidents mailing list archives

Email Relay Searches


From: "Pat Moffitt" <pmoffitt () wrv com>
Date: Fri, 29 Mar 2002 08:15:03 -0800

I have been seeing a few of these and find them, well, interesting.

2002-03-29 00:14:18 refused relay (host) to <mattkell () 00264587623 com> from
<mattkel () 00264587623 com> H=(12.144.138.34) [12.254.177.131]

If you check you will find that 002645587623.com does exist.  They are
sending out email trying to relay through other servers and the hello has
the server's address in it.  So all they have to do is log all the
H=(xx.xx.xx.xx)'s and they have a list of open mail relay servers.

Anything we can do about these?

Pat Moffitt
MIS Administrator
Western Recreational Vehicles, Inc.



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: