Submitted by whirlpool on Mon, 24/10/2005 - 15:15.
( categories: Miscellaneous )

I just received the following email.

From: admin@eglug.org
To: mostafa@eglug.org
Subject: Your Account is Suspended
Date: Mon, 24 Oct 2005 06:52:52 +0200


Dear user mostafa,

It has come to our attention that your Eglug User Profile ( x ) records are out of date. For further details see the attached document.

Thank you for using Eglug!
The Eglug Support Team






+++ Attachment: No Virus (Clean)
+++ Eglug Antivirus - www.eglug.org
[important-details.zip  application/octet-stream (68174 bytes)]

Here is the header:

Return-Path: <admin@eglug.org>
X-Original-To: mostafa@eglug.org
Delivered-To: mostafa@eglug.org
Received: from eglug.org (unknown [62.114.51.226])
	by manalaa.net (Postfix) with ESMTP id EBC7236CE6
	for <mostafa@eglug.org>; Mon, 24 Oct 2005 06:52:26 +0200 (EET)
From: admin@eglug.org
To: mostafa@eglug.org
Subject: Your Account is Suspended
Date: Mon, 24 Oct 2005 06:52:52 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed;
	boundary="----=_NextPart_000_0006_2A0D9778.1AC5B50E"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <20051024045226.EBC7236CE6@manalaa.net>

Please fix your mail servers.

__null's picture
Submitted by __null on Mon, 24/10/2005 - 15:48.

A simple DNS lookup for eglug.org would have revealed that the source IP [62.114.51.226] is not eglug.org's, which is [69.61.55.58]. was this a valid IP even?

Spoofed mail attacks are as easy as a few commands typed against a relay-enabled SMTP server.

As far as I know.


Alaa's picture
Submitted by Alaa on Mon, 24/10/2005 - 16:38.

admin ايه ده يا أخواتي اللي مش عارف ياخد بالله أن الheaders مزيفة

cheers,
Alaa


http://www.manalaa.net "i`m feeling for the 2nd time like alice in wonderland reading el wafd"


whirlpool's picture
Submitted by whirlpool on Mon, 24/10/2005 - 17:04.

At least eglug.org mail server can notice that this mail is not comming from admin@eglug.org. I mean if it was yahoo mail that didn't recognize the spoofed address then khalas mesh 2adya. But when eglug.org can't then there is something wrong.


Mostafa Hussein


__null's picture
Submitted by __null on Mon, 24/10/2005 - 17:38.

the DomainKeys technology lol? http://domainkeys.sourceforge.net


Alaa's picture
Submitted by Alaa on Mon, 24/10/2005 - 17:52.

there are way too many b0rked smtp servers out there that don't have proper DNS records, and many GNU/Linux users run their own SMTPs with no DNS records at all.

anyways will reread the docs again to make sure, I think I created several profiles on the postfix server so that each user can choose how strict the server will be when dealing with spam, by default everyone is on welcome spammers mode (since you could just run spam assasin at home), but if you want I can move you to a strict profile.

cheers,
Alaa


http://www.manalaa.net "i`m feeling for the 2nd time like alice in wonderland reading el wafd"


YoussefAssad's picture
Submitted by YoussefAssad on Mon, 24/10/2005 - 16:58.

whirlpool, you are a disgrace to the medical profession... err, wait. What I meant was, you are a disgrace to, no, that doesn't work either.

Give me a second, I'm sure he's disgracing something...

No, but remind me, why do we have a gynecologist in training admining a linux user group website? I mean, that's like giving a linux administrator a chain saw and asking him to remove your appendix.

Mostafa, you're disgracing SOMETHING, alright?

-- Panem et *burp* circenses


MohammedSameer's picture
Submitted by MohammedSameer on Mon, 24/10/2005 - 19:18.
Received: from eglug.org (_unknown_ [62.114.51.226])

$ nslookup  62.114.51.226  
Server:		62.140.73.1
Address:	62.140.73.1#53

** server can't find 226.51.114.62.in-addr.arpa: NXDOMAIN

$ dig eglug.org
................
eglug.org.		1860	IN	A	69.61.55.58

$ dig eglug.org
...................
eglug.org.		1860	IN	A	69.61.55.58

يابنى انا ساعات بيجيلى من admin@foolab.org, support@foolab.org ;-)


WWW: The place for organized randoms!
EGLUG Admin..
Arabeyes Core Member.
Free Software Foundation Associate Member.


Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.