Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 22, 2012, 05:33:57 AM

Pages: [1]   Go Down
  Print  
Author Topic: Accused of spamming - not doing it - all to AOL HELP  (Read 883 times)
brrnese
Trekkie
**
Offline Offline

Posts: 15


« on: December 27, 2003, 04:32:24 PM »

We had a problem with one of our domains at the beginning of the month -apparently our mailing script was compromised and used to send thousands of spam - and it was the form lunar recommends and configures - but it happened.  We removed the form from the site.  We are not using the outgoing mail server for the domain as we connect with broadband and use that server and this morning I got an email from tech -
"We are still getting complaints of spam against your account.

The most recent complaint was sent was sent out on Sat, 27 Dec 2003.

Someone that has access to your account has a virus or your password for this account has been comprimised.

It's important that this situation is corrected. We would be unable to continue to host an account that is allowing spam to be processed through it
Do not hesitate to contact us if you have any questions.

Lee Coleman
support@lunarpages.com"

I emailed back within 30 minutes of receiving that message and still have had no reply - very frustrating.  

We are not sending any outoing email - and I'm wondering if this has something to do with problems with AOL mentioned in numerous other posts.  I have never had a problem with any of our sites witih prior hosts and am trying my darndest to understand what is going on here.  I asked before - could this be an inside job?  Once someone knows the format of the outgoing mail server it doesn't take much to use it - and Lunar proudly posts the names of all its servers on their website...

I'm still waiting for a reply from Lee Coleman with particulars of what "spam" was sent on our account that generated a complaint.  This time there is nor returned mail to even inspect.

Any advice would be greatly appreciated.  I'm spending way too much time on trying to resolve a problem that we have no part in.

Kathie Meier
Logged
Danielle
Guest
« Reply #1 on: December 27, 2003, 04:58:31 PM »

Hi,

I apologize that you did not receive a response from support on the ticket.  After we received your ticket, one of our representatives did ICQ Lee on the matter, however, Lee is not currently working.  She is the General Manager and the one who would handle the issue.  Due to the fact that you had not received a reply, I just sent one to you myself to let you know that Lee has been contacted about the ticket.

Next, I understand your frustration in this matter, however, please be aware that the script did originate on your account that was used to relay the spam and cause this to occur.  It is unfortunate that this script was compromised and caused this to happen and that the script was originally recommended by Lunarpages as well.  You have taken steps to alleviate the matter by removing the script.  Please bear in mind that neither Lunarpages nor yourself want this spam to continue.  Hopefully, Lee will be able to assist you further in determining precisely what to do to correct the matter.

I sincerely apologize for any inconvenience you have had in this matter.

I hope this information was helpful.
Logged
brrnese
Trekkie
**
Offline Offline

Posts: 15


« Reply #2 on: December 27, 2003, 05:43:55 PM »

Thank you Miranda.  I understand the responsibility for the script - tho while I have heard of these types of problems - I have scripts on most of our sites and never had even a hint of a problem.  However, we immediately removed the script, changed passwords etc.  I do computer consulting by profession and am fanatical about antivirus software, anti-trojan software, anti-spyware etc. so I am virtually certain that no compromise has occurred from my end.  This is what I find so frustrating...  I have no idea where the smtp access is coming from as we don't use the lunar outgoing mail servers.  I anxiously await further response from Lee.

Kathie
Logged
arfunk
Spacescooter Operator
*****
Offline Offline

Posts: 42



WWW
« Reply #3 on: December 30, 2003, 08:55:54 AM »

Often what looks like spam from a particular domain is actually spoofed -- the spam has a false "From:" field.

That's what's been happening with my domain -- a lot of spam is going out with forged "from:" fields indicating various false addresses @arfunk.com.

(How do I know? I get the bounce messages when the spam was sent to invalid email addresses.)

I ended up putting a disclaimer at the top of my main web page,
http://www.arfunk.com,  because of this.

Aaargh!

/Andy
Logged

lee
Administrator
Jabba the Hutt
*****
Offline Offline

Posts: 521



« Reply #4 on: December 30, 2003, 11:25:45 AM »

Kathie,

If you recall I did call you on Sunday, the day after your message was sent to our office.   When your message was received on Saturday I was not working and unable to call you immediately.

The situation with spammers exploiteing formmail scripts is not limited to Lunarpages.  

Many hosting companies are not allowing any type of formmail script on their servers, because of the situation.
Logged

leighsww
* The Tough Love Cuddly One *
Berserker Poster
*****
Offline Offline

Posts: 13870


WWW
« Reply #5 on: December 30, 2003, 11:29:21 AM »

Welcome to the club, Andy!

It seems many of us are victims of this atrocity! (*sigh*)  I have a similar disclaimer on my website, however, I doubt that people who receive these spoofed spams are actually going to our websites to read it then say to themselves, "Oh, okay, these people are vicitims of identity theft, so I shouldn't get pissed off at them".  No, I doubt this is what is happening.  Instead, they are putting in complaints so that we are blocked.  Crying or Very sad

Are you getting a lot of undeliverables from AOL?  This is who I'm getting back from everyday like a swarm of bees in the last month (I've had hotmail, empal, yahoo, and a few others, but AOL is really frequent and what I'm getting most of right now).  I even went to the http://postmaster.info.aol.com link and did the test for open relay.  I'm waiting for the response that they say they will send (I have a dedicated IP from LP, but when I tried to send a test email with the IP addy instead of domain name, I didn't get it back, so I'm not sure if I'll get their test message).

Does anybody know about this?  Has anyone did this AOL open relay test, etc. and can share any info/results on it?

Would be real helpful.
Logged
leighsww
* The Tough Love Cuddly One *
Berserker Poster
*****
Offline Offline

Posts: 13870


WWW
« Reply #6 on: December 30, 2003, 11:45:00 AM »

Quote from: lee
The situation with spammers exploiteing formmail scripts is not limited to Lunarpages.  

Many hosting companies are not allowing any type of formmail script on their servers, because of the situation.


Lee - I don't think that Formmail is how these spoofers are compromising us, because I have never used Formmail. I guess we should find out by asking others if this is the case for them.

Are those of you who are having this spoofing (identity theft where someone is using your domain to send out SPAM) problem using the Formmail script?  Yes or No?

Although, this is definitely not the only way to be compromised (via scripts) this info could be very useful and helpful.
Logged
Admin
Über Jedi
*****
Offline Offline

Posts: 2544


WWW
« Reply #7 on: December 30, 2003, 12:16:54 PM »

I believe in the first case it was an issue of a formmail script that was compromised.  No, it is not the only way for an account to be compromised.
Logged

arfunk
Spacescooter Operator
*****
Offline Offline

Posts: 42



WWW
« Reply #8 on: December 30, 2003, 02:11:06 PM »

From what I've seen on the bounce messages I've received for spam spoofing my domain, none was actually sent from my domain - they were all pure forgeries. (Leighsww, you nailed it --we're victims of identity theft.) While I viewed them all at first, now I just don't have the time to look at 'em all.


Back when I was looking at all the bounce messages I checked the actual headers from the spam message (if enclosed) and wrote to "abuse" and/or"postmaster" at the appropriate domain. Out of the approximately 75 messages I sent out I received one reply, from a university. That postmaster tracked down the spammer and banned him from their systems.

Yes, a lot have been from AOL. I haven't visited http://postmaster.info.aol.com yet, but will when I get home from work.

I just wish the scripts generating the bounce messages looked at the actual mail forwarding headers instead of the "From:" header which is so easily forged.

/a
Logged

Yaxley
Galactic Royalty
*****
Offline Offline

Posts: 362


WWW
« Reply #9 on: December 30, 2003, 05:55:26 PM »

I've noticed that I am getting identical spam directed to 'all" my lunar email accounts..to specific email addresses I have. I have other email accounts from ISP, hotmail, etc. and do not get these same spam messages.

Very suspicious?
FYI
Logged

Yaxley

Tired of the same old stuff? Unique gifts at:
http://southwestwoodcrafts.com
http://westernwoodartist.com
Jwink3101
Über Jedi
*****
Offline Offline

Posts: 1838


The one and only.


« Reply #10 on: December 30, 2003, 06:50:08 PM »

It is amazing how easy it is to spoof with an open relay. I have one from comcast but i do not use it.

I was telling my dad about it and he didn't belive me so i studied an email he sent me and, with his permission, spoofed his work account. I actually authenticated with LP's server becuase i figured it was once, with his permission, for his own security reasons.

I told my dad to look at the message headers to see the server it was relayed from.
Logged

-Justin Winokur


"The Music is reversible but time is not. Turn Back! Turn Back! Turn Back! Turn Back!" - Intentional backmasking in ELO's Fire On High.
Ed
Berserker Poster
*****
Offline Offline

Posts: 5208



WWW
« Reply #11 on: December 30, 2003, 10:03:00 PM »

It does use a passive auth system, so if you have logged in the check email in the last x mins you can send without reauthenticating...

- Ed
Logged

Pages: [1]   Go Up
  Print  
 
Jump to: