You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Aaron Boyles <Bo...@ITC.GOV> on 2005/12/21 21:33:27 UTC

Does "tuxorama.com" sound familiar to anyone?

This could just be sheer coincidence, but like I said, we don't get a whole
lot of E-Mail here, so it'd be an odd coincidence.  

Almost immediately after my first posting on this board, someone has started
"testing" our SMTP server, with an IP registered in Amsterdam, NL.

Here's our current log to give you an idea of what I mean by "testing."

[1] Accepting connection from: 81.169.185.26
[1] 220 - SMTP Server ready.  Only basic commands permitted.
[1] HELO userland.tuxorama.com
[1] 250 - Hello, userland.tuxorama.com
[1] MAIL FROM:<>
[1] 250 - OK, Mail from: <>
[1] RCPT TO:<Bo...@ITC.GOV>
[1] 250 - OK, Recipient: <Bo...@ITC.GOV>
[1] QUIT
[1] 250 - OK, Ending session.
[1] Connection closed locally...

[1] Accepting connection from: 81.169.185.26
[1] 220 - SMTP Server ready.  Only basic commands permitted.
[1] HELO userland.tuxorama.com
[1] 250 - Hello, userland.tuxorama.com
[1] MAIL FROM:<>
[1] 250 - OK, Mail from: <>
[1] RCPT TO:<Bo...@ITC.GOV>
[1] 250 - OK, Recipient: <Bo...@ITC.GOV>
[1] QUIT
[1] 250 - OK, Ending session.
[1] Connection closed locally...

This has been done repeatedly, and mirrors what happened before when the
exploit was used to relay mail through us.  Whoever this is, you might as
well switch to a different IP, as that one has been banned and reported.
Keep this up long enough, and you're gonna run out of IPs.  

Anywho, if someone on this forum has any way of tracking down who the
jokester is, you might want to remove him from the forum all together.

-Aaron Boyles
ITC Applications Programmer