5 messages in net.sourceforge.lists.courier-usersRE: [courier-users] Re: how to close ...
FromSent OnAttachments
Alexander LangSep 22, 2003 3:40 am 
Sam VarshavchikSep 22, 2003 5:07 am 
Stephen ReeseSep 22, 2003 3:54 pm 
Phillip HutchingsSep 22, 2003 4:53 pm 
Stephen ReeseSep 22, 2003 6:17 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:RE: [courier-users] Re: how to close courier-mta open relay - I need help on this issue alsoActions...
From:Stephen Reese (sre@prcdigital.com)
Date:Sep 22, 2003 6:17:48 pm
List:net.sourceforge.lists.courier-users

Well then I thank both you and Phillip Hutchings for the information.

-----Original Message----- From: Malcolm Weir [mailto:ma@gelt.org] Sent: Monday, September 22, 2003 8:06 PM To: Stephen Reese Subject: RE: [courier-users] Re: how to close courier-mta open relay - I need help on this issue also

-----Original Message----- From: Stephen Reese Sent: Monday, September 22, 2003 3:53 PM

Well i'm having similar issues, all types of problems getting mail from *.microsoft *.newletters.com address's myself

You don't have an open relay...

here's one header:

Delivered-To: sre@prcdigital.com Return-Path: <rew@twcny.rr.com> Received: from ms-smtp-02.nyroc.rr.com (ms-smtp-02.nyroc.rr.com [::ffff:24.92.226.49]) by prcdigital.com with esmtp; Mon, 22 Sep 2003 18:35:40 -0400 Received: from jkcuchh (syr-24-58-136-138.twcny.rr.com [24.58.136.138]) by ms-smtp-02.nyroc.rr.com (8.12.5/8.12.2) with SMTP id h8MMMjuC027321; Mon, 22 Sep 2003 18:22:46 -0400 (EDT) Date: Mon, 22 Sep 2003 18:22:45 -0400 (EDT) Message-Id: <2003@ms-smtp-02.nyroc.rr.com> FROM: "Program Security Division" <vhcc@newsletters.net> TO: " " <cust@newsletters.net> SUBJECT: Net Critical Pack Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="=_prcserver.prcdigital.com-17567-1064270148-0001-2"

And your point is?

SWEN is hitting you. That is a BCC to you using totally fake FROM and TO headers, with an envelope wrapper specifying your name.

here's another one:

Delivered-To: sre@prcdigital.com Return-Path: <rew@twcny.rr.com> Received: from ms-smtp-02.nyroc.rr.com (ms-smtp-02.nyroc.rr.com [::ffff:24.92.226.49]) by prcdigital.com with esmtp; Mon, 22 Sep 2003 18:44:48 -0400 Received: from szwz (syr-24-58-136-138.twcny.rr.com [24.58.136.138]) by ms-smtp-02.nyroc.rr.com (8.12.5/8.12.2) with SMTP id h8MMY5uC018988; Mon, 22 Sep 2003 18:34:05 -0400 (EDT) Date: Mon, 22 Sep 2003 18:34:05 -0400 (EDT) Message-Id: <2003@ms-smtp-02.nyroc.rr.com> FROM: "Microsoft Net Email Service" <vmai@netmail.com> TO: "Inet Recipient" <rece@homeserver.com> SUBJECT: Letter Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="=_prcserver.prcdigital.com-17645-1064270694-0001-2"

I know there being sent from my machine sometimes since there not even

passing through spamassassin when coming in or they would look like the following:

Errrr... what do you THINK those "Received: from" lines are telling you?

They both originated from IP address 24.58.136.138 (which looks like a RoadRunner customer in Syracuse, NY).

Delivered-To: sre@prcdigital.com Return-Path: <cli@prcdigital.com> Received: from prcdigital.com ([::ffff:66.35.133.92]) (AUTH: LOGIN clinke) by prcdigital.com with esmtp; Mon, 22 Sep 2003 16:58:37 -0400 Message-ID: <3F6F@prcdigital.com> Date: Mon, 22 Sep 2003 16:56:47 -0400 From: Chris Linke <cli@prcdigital.com> User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Stephen Reese <sre@prcdigital.com> Subject: Re: new phone number References: <001401c37d5d$4efdc3f0$6401a8c0@inspiron> In-Reply-To: <001401c37d5d$4efdc3f0$6401a8c0@inspiron> Content-Type: multipart/alternative; boundary="------------000504080604010108090208" X-Spam-Status: No, hits=-0.8 required=5.0 tests=EMAIL_ATTRIBUTION,HTML_20_30,HTML_FONT_COLOR_BLUE, HTML_MESSAGE,IN_REP_TO,MAILTO_TO_SPAM_ADDR, QUOTED_EMAIL_TEXT,REFERENCES,REPLY_WITH_QUOTES, USER_AGENT_MOZILLA_UA,X_ACCEPT_LANG version=2.55 X-Spam-Level: X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp)

All that means is that your SpamAssassin setup isn't examining all your mail. By the way, you should be aware that SA 2.55 still believes in Osirus RBL, which is a Bad Thing in that that list has been closed down in a very petulant fashion...

Malc.