[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

spammers are killing me



it's either too late in the night or here's something going on.
IP=3D195.226.187.154, postfix 1.1.3-1 on debian woody, port 25,
mailhost for 27 domains, otherwise closed relay.

now i find this in the logs:

postfix/smtpd[6023]: connect from host074125.arnet.net.ar [200.45.74.125]
postfix/smtpd[6023]: 6937F1673D: client=host074125.arnet.net.ar[200.45.74.125]  
postfix/cleanup[6024]: 6937F1673D: message-id=<0000569d4d9a$000021ce$00002d35@64.197.156.227>
postfix/qmgr[31979]: 6937F1673D: from=<opt-in@randbad.com>, size=5880, nrcpt=25 (queue active)
postfix/smtp[6038]: 6937F1673D: to=<kkelsplace@cs.com>, relay=mailin-02.mx.aol.com[64.12.136.121], delay=7, status=sent (250 OK)

try it, it's a closed relay. there *exists* tls client authentication
but that would be logged. how the heck can this happen???

i'm going slightly mad, it finally happened.

-- 
martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:"; net@madduck
  
"god is a comedian playing to an audience too afraid to laugh."
                                                           -- voltaire

Attachment: pgpbfygj1Gtvu.pgp
Description: PGP signature


Reply to: