[Cialug] Hijack This! (Equivalent on Linux?)

cialug@cialug.org cialug@cialug.org
Fri, 28 Jan 2005 17:59:52 +0000


This looks like a lot of e-mails I get.  The joys of having your own domain
name.  Let me guess, you have a "catch-all" mailbox too, so anything sent to
your domain goes to this box (if it doesn't match a known address)?  I get a lot
of these in my "catch-all" mailbox.  If I have the time, I research and send
e-mails to abuse@ the servers I find in the headers.  This lets them know that
either they have an open server, someone is sending spam from them, or they have
the danger of being blacklisted.  I don't know if there is a law against this
(besides the CAN-SPAM act).  For me, since my domain is a personal one, I think
I could have grounds for identity theft.  Trying to catch the suckers is a
different issue.

--
Tim W.
> Dave Weis wrote:
> 
> >> I've both done a lot on this problem, and not near enough.   Some 
> >> idiots in the world have decided to hijack my server as a Relay host 
> >> for Spam.   I have only three entries in my /etc/mail/relay-domains 
> >> listing, and these entries are NOT the domain from which they 
> >> accomplish this spoof.
> >
> > It's possible that it's a joe job, when someone puts your from address 
> > on spam and you get the bounces. 
> 
> Thanks Dave and list,
> Interesting.  A "Joe Job"?
>  
> Here is a header:
[snip]
> > Looking at network traffic either you aren't sending much or it isn't 
> > actually going through your server.
> > Check in /var/log/maillog and see if they are going in and out, or 
> > forward a bounce message with full headers to the list. 
> 
> I have been checking the mail log, trying to identify a STATIC IP 
> address, or consistent email address, but all that is coming in are the 
> bounces.  But boy are there a lot of those (hundreds every day). 
> 
> Isn't there a law against this? :-D
> 
> Andrew L.
> 
> 
> _______________________________________________
> Cialug mailing list
> Cialug@cialug.org
> http://cialug.org/mailman/listinfo/cialug