PDA

View Full Version : Hostpc's Mail Server Blacklisted...


dchakrab
01-18-2005, 12:46 AM
Hi all,

Not major enough (yet) to warrant a support ticket, so I thought I'd post it here for comments. I tried responding to an email recently and had the email bounce, and received a notice saying the mail server i was using was directly blacklisted for spamming. I visited the site for the spam blocker, and clicked on the "evidence" link, and this is what was listed:


Return-Path: <apache@www19.hostpc.com>
Received: from www19.hostpc.com (www19.hostpc.com [198.87.87.19])
by spf1.us4.outblaze.com (Postfix) with ESMTP id 98A8C53A8A
for <detroitfan57@email.com>; Mon, 6 Dec 2004 21:01:23 +0000 (GMT)
Received: from apache
by www19.hostpc.com with local (Exim 4.43) id 1CbPyy-0007pz-IL
for detroitfan57@email.com; Mon, 06 Dec 2004 16:01:20 -0500
To: detroitfan57@email.com
Subject: Customer notification: data confirmation [ Mon, 06 Dec 2004 07:16:25 +0200]
From: security@suntrust.com <security@suntrust.com>
Content-Type: text/html
Message-Id: <E1CbPyy-0007pz-IL@www19.hostpc.com>
Date: Mon, 06 Dec 2004 16:01:20 -0500

<img border="0" src="http://www.jobsinthemoney.com/images/homepage/suntrust.gif" width="110" height="40">
<p>
<p><b>Official information to SunTrust Bank clients:</b><br>
</p>
<p>We recently reviewed your account, and suspect that your<br>






The email I received:


This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

larco34@lycos.com
SMTP error from remote mailer after RCPT TO:<larco34@lycos.com>:
host lycos-com.mr.outblaze.com [208.36.123.75]:
554 EMail from mailserver at 198.87.87.19 is refused. See http://spamblock.outblaze.com/198.87.87.19



Comments, or suggestions? Is there any way to know if this was actually spam sent through a hostpc account, or if this was just spam with the outbound ip / addresses forged / spoofed? Has anyone else seen this kind of thing yet, and if so, is it a problem I should be concerned about?

-Dave.

ozee
01-18-2005, 01:03 AM
If 198.87.87.19 is a legit hostpc IP (and it looks like it could be) then it did indeed originate from here.

Have you done an antivirus scan and hijacker check lately? If you need help, I can help you with any of that... lmk



(kinda humerous -- I don't have any idea how many spams I've gotten that originated at an outblaze ip...)

dbmasters
01-18-2005, 07:30 AM
rut row, yet another formmail script appears to have been hijacked.

Joe
01-18-2005, 08:41 AM
www19's IP is indeed 198.87.87.19[

http://spamblock.outblaze.com/198.87.87.19
Not Found.

Explanatory Note :

Your IP is not currently blocked by us.

Outblaze Postmaster

Mon, 6 Dec 2004

Thats an OLD spam report, which we cleared nearly immediately. The IP hasn't been blocked in well over a month. The offending customer was, if I remember correctly, removed from the server. It's part of what prompted the phpBB upgrade issue (http://http://www.hostpc.com/forums/index.php?showtopic=1704)

dchakrab
01-18-2005, 09:15 AM
Hi

Your webhost's IP was blocked some weeks back because of phishing spam sent
directly out it (no it is not spoofed - and yes, I do know the difference).
The most likely cause is a compromised cgi or php script on the server that
you're using - sample below.

I've lifted the block. If this recurs please ask your webhost to contact us

-srs
postmaster@outblaze.com

Return-Path: <apache@www19.hostpc.com>
Received: from www19.hostpc.com (www19.hostpc.com [198.87.87.19])
by spf1.us4.outblaze.com (Postfix) with ESMTP id 98A8C53A8A
for <detroitfan57@email.com>; Mon, 6 Dec 2004 21:01:23 +0000 (GMT)
Received: from apache
by www19.hostpc.com with local (Exim 4.43) id 1CbPyy-0007pz-IL
for detroitfan57@email.com; Mon, 06 Dec 2004 16:01:20 -0500
To: detroitfan57@email.com
Subject: Customer notification: data confirmation [ Mon, 06 Dec 2004 07:16:25
+0200]
From: security@suntrust.com <security@suntrust.com>
Content-Type: text/html
Message-Id: <E1CbPyy-0007pz-IL@www19.hostpc.com>
Date: Mon, 06 Dec 2004 16:01:20 -0500

<img border="0"
src="http://www.jobsinthemoney.com/images/homepage/suntrust.gif" width="110"
height="40">
<p>
<p><b>Official information to SunTrust Bank clients:</b><br>
</p>
<p>We recently reviewed your account, and suspect that your<br>