You are viewing a plain text version of this content. The canonical link for it is here.
Posted to general@jakarta.apache.org by Steve Cohen <st...@comcast.net> on 2005/05/16 13:18:51 UTC

mail server hacked?

My mailbox has suddenly filled up with large volumes of German-language 
email that appear to be of a racist anti-Turk nature.  (I don't speak 
German).  All of this email has a "To:" addresses that are from 
phony-sounding lists at apache.org.  I can see minotaur.apache.org in 
the headers of all of them.  Was there some sort of exploit that allowed 
this email to be sent through the Apache servers?  Or is this some new 
form of hackery that allows the email to appear as if it has come 
through the Apache servers?

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


Re: mail server hacked?

Posted by Henri Yandell <ba...@generationjava.com>.
It's a new (return of an old) virus (Sober) that was flying past the spam 
rules. The Infra list has a thread about it and the admins seem to be 
sorting things out.

Hen

On Mon, 16 May 2005, Steve Cohen wrote:

> My mailbox has suddenly filled up with large volumes of German-language email 
> that appear to be of a racist anti-Turk nature.  (I don't speak German).  All 
> of this email has a "To:" addresses that are from phony-sounding lists at 
> apache.org.  I can see minotaur.apache.org in the headers of all of them. 
> Was there some sort of exploit that allowed this email to be sent through the 
> Apache servers?  Or is this some new form of hackery that allows the email to 
> appear as if it has come through the Apache servers?
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
> For additional commands, e-mail: general-help@jakarta.apache.org
>

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


Re: mail server hacked?

Posted by Henri Gomez <he...@gmail.com>.
>Noel J. Bergman wrote:
> Same here.  I received many of them as well.  Tons of "German" spam.  Is
> that the same as you are seeing?

>seeing them too. they seem to be a re-emergence of those distgusting
>xenophobe zombie spams from a while back:

>http://www.wired.com/news/technology/0,1282,63806,00.html


2005/5/16, Steve Cohen <st...@comcast.net>:
> My mailbox has suddenly filled up with large volumes of German-language
> email that appear to be of a racist anti-Turk nature.  (I don't speak
> German).  All of this email has a "To:" addresses that are from
> phony-sounding lists at apache.org.  I can see minotaur.apache.org in
> the headers of all of them.  Was there some sort of exploit that allowed
> this email to be sent through the Apache servers?  Or is this some new
> form of hackery that allows the email to appear as if it has come
> through the Apache servers?
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
> For additional commands, e-mail: general-help@jakarta.apache.org
> 
>

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


Re: mail server hacked?

Posted by Felipe Leme <ja...@felipeal.net>.
On Tue, 2005-05-17 at 03:53 -0500, Steve Cohen wrote:
 
> Might that rule have possibly been overly strict?  I notice at least two 
> posts that should have gone out in the past day - one a post I made half 
> an hour ago to the ant-dev list that still has not appeared on the list. 

Hmm, I think it's also happening with me: I've sent a message to the
harmony-dev twice (using jakartalists2 at felipeal) and they haven't
arrived yet.

-- Felipe



---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


RE: mail server hacked?

Posted by "Noel J. Bergman" <no...@devtech.com>.
Steve Cohen wrote:

> Noel J. Bergman wrote:
> > Just spam that made it past spamassassin.  We installed a new
> > rule set last night to address it.
>  Might that rule have possibly been overly strict?

Not unless your e-mail has subjects written in German.  :-)

More likely, e-mail just can't get through.  There is 0% idle CPU and I'm
sure that connections are being refused and need to be retried over and
over.

	--- Noel


---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


Re: mail server hacked?

Posted by Steve Cohen <sc...@javactivity.org>.
Noel J. Bergman wrote:
> Just spam that made it past spamassassin.  We installed a new rule set last
> night to address it.
> 
> 	--- Noel
> 
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
> For additional commands, e-mail: general-help@jakarta.apache.org
> 
> 
> 
Might that rule have possibly been overly strict?  I notice at least two 
posts that should have gone out in the past day - one a post I made half 
an hour ago to the ant-dev list that still has not appeared on the list. 
  Another was a bugzilla change to Ant that was not reported out.  Or 
have you guys tightened down the screws for the duration of an attack?

---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org


RE: mail server hacked?

Posted by "Noel J. Bergman" <no...@devtech.com>.
Just spam that made it past spamassassin.  We installed a new rule set last
night to address it.

	--- Noel


---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscribe@jakarta.apache.org
For additional commands, e-mail: general-help@jakarta.apache.org