Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 09-30-2008, 03:02 PM
Danl Danl is offline
Administrator
Admin
 
Mail2

Now that Mail0 and Mail1 are back up to speed, mail2 is getting hit hard, I'd just assume block every ip from hitting the server till I find out which IP it is but for some reason David doesn't want that to happen. I'm slowly going through the mail queue and killing spam and blacklisting people

Last edited by Danl : 09-30-2008 at 03:08 PM. Reason: Spelled some words wrong
Reply With Quote
  #2  
Old 09-30-2008, 03:54 PM
dcsweb dcsweb is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Update on this

Any idea of when we can expect mail to begin flowing again?
I'm getting complaints on this server.

Thanks!
Reply With Quote
  #3  
Old 09-30-2008, 04:27 PM
treeves's Avatar
treeves treeves is offline
President
Vortech Inc. Customer
 
Location: Indiana, USA
Send a message via MSN to treeves
I am getting complaints on Mail2 as well.
__________________
Toby Reeves
Rescott Marketing & Technology
http://www.rescott.com
Marketing Site: http://www.rescottmarketing.com
Rescott- Rescott is home to the innovative Connopia Software products (http://www.connopia.com).
Reply With Quote
  #4  
Old 09-30-2008, 04:35 PM
thanna thanna is offline
Registered User
Junior Member
 
update PLEASE!

Please provide update on the status of this problem. I have customers who are not receiving email containing contracts and other business transactions. How soon do you expect to resolve this problem?
btw, what issues were there with mail0 and mail1 ?
Reply With Quote
  #5  
Old 09-30-2008, 05:04 PM
WalkerL55 WalkerL55 is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
I am also getting 1 client that is having issues with mail2. any news on this yet. i am going submit a trouble ticket in a minute, to follow protocol.

Walker
Reply With Quote
  #6  
Old 09-30-2008, 05:06 PM
WillieCee WillieCee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Dallas, TX
Telling me about an hour more on mail 2
but I see a trickle of mail coming in ....
Reply With Quote
  #7  
Old 09-30-2008, 05:50 PM
dcsweb dcsweb is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
any update here?

An update?
Reply With Quote
  #8  
Old 09-30-2008, 06:12 PM
Danl Danl is offline
Administrator
Admin
 
I'm hoping to find the idiots who are doing this, when I do they will be turned off, I'm tempted to just block entire countries until we figure out what country this spam issue is coming from.
Reply With Quote
  #9  
Old 09-30-2008, 06:16 PM
WillieCee WillieCee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Dallas, TX
Dan,
with all the trojans out there it might very well be me or anyone else on the box I have gone machine by machine scaning with latist Dr. web on top of symantic endpoint. Do you have any recommendations for a scanner to check customer boxes with? I might add before I get some kerosen of my own ....
Reply With Quote
  #10  
Old 09-30-2008, 06:18 PM
WillieCee WillieCee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Dallas, TX
Quote:
Originally Posted by Danl
I'm hoping to find the idiots who are doing this, when I do they will be turned off, I'm tempted to just block entire countries until we figure out what country this spam issue is coming from.

As I said on the phone I am getting a ton of bounce back messages for email I did not send 90% of it states I sent a message to some .ru address if thats a clue or not????
Reply With Quote
  #11  
Old 09-30-2008, 06:23 PM
dcsweb dcsweb is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Then Block em

You can pretty much bet that you're not getting any legit email from pl or ru right now since it's midnight there

Can you shut down everything and work on processing the queue? At least showing some mail trickling through would ease everyone's mind.

---
I'm moving sites right now to another host due to this outage..for what it's worth.
Reply With Quote
  #12  
Old 09-30-2008, 06:26 PM
dcsweb dcsweb is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
@WillieCee

You would have most likely already been blocked at the SMTP layer by vortech because you would have been reported via the CBL.

Trojans can spew tons of email and it does not take long to get picked up as a spam source.

If your curious, just check here, put in your networks IP
http://cbl.abuseat.org/lookup.cgi
Reply With Quote
  #13  
Old 09-30-2008, 06:37 PM
WillieCee WillieCee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Dallas, TX
DCSweb

I checked my external IP on the link you sent says not blocked

Here is a header from Mailer Deamon Failure

Hi. This is the qmail-send program at fs.spdop.ru.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<knwcxcur@spdop.ru>:
Sorry, no mailbox here by that name. (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: <pro@eedata.com>
Received: (qmail 98654 invoked from network); 30 Sep 2008 19:43:59 -0000
Received: from unknown (HELO smtp.spdop.ru) (195.34.31.35)
by 0 with SMTP; 30 Sep 2008 19:43:59 -0000
Received: from localhost (localhost [127.0.0.1])
by smtp.spdop.ru (Postfix) with ESMTP id ACC04A5D161
for <knwcxcur@spdop.ru>; Wed, 1 Oct 2008 00:17:57 +0400 (MSD)
X-Virus-Scanned: SomeProgram on host: AZAZELLO
X-Spam-Score: -1.496
X-Spam-Level:
X-Spam-Status: No, score=-1.496 required=6.2 tests=[BAYES_00=-2.599,
HTML_MESSAGE=0.001, MIME_HTML_MOSTLY=1.102]
Received: from smtp.spdop.ru ([127.0.0.1])
by localhost (azazello.spdop.ru [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 0b0mHb+ke1BX for <knwcxcur@spdop.ru>;
Wed, 1 Oct 2008 00:17:54 +0400 (MSD)
Received: from mail1.hsphere.cc (mail1.hsphere.cc [216.157.145.21])
by smtp.spdop.ru (Postfix) with SMTP id 9E0C9A5D0EB
for <knwcxcur@spdop.ru>; Wed, 1 Oct 2008 00:17:52 +0400 (MSD)
Received: (qmail 33808 invoked by uid 399); 30 Sep 2008 20:16:47 -0000
Received: from unknown (HELO IBM2102TTI) (pro@eedata.com@216.201.213.97)
by mail1.hsphere.cc with SMTP; 30 Sep 2008 20:16:47 -0000
From: "Will" <pro@eedata.com>
To: '=?koi8-r?Q?p.r.i.n.t.i.n.g._-i.n.d.u.s.t.r.=D5.?=' <knwcxcur@spdop.ru>
Reply With Quote
  #14  
Old 09-30-2008, 06:46 PM
dcsweb dcsweb is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Looks like standard backscatter

Looks like standard backscatter,

it works like this:
someone forges an email and lie about who it's too and from.
SENT TO: knwcxcur@spdop.ru

Then they forge your email address into the email as the reply-to:
Return-Path: <pro@eedata.com>

When the mail cannot be delivered:
<knwcxcur@spdop.ru>:
Sorry, no mailbox here by that name. (#5.1.1)

it bounces back into your inbox as designed by the MTA and outlined in the RFCs for e-mail.

It's tough to stop this type of attack. It's typical to see groups of 5 or so emails structured the same way from a bunch of different addresses ending up in your inbox.

This is nothing you've done, just more tricks the spammers use to circumvent the anti-spam solutions out there.
Reply With Quote
  #15  
Old 09-30-2008, 07:01 PM
WillieCee WillieCee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Dallas, TX
Ok whats the point in sending to a dead address other then to just piss me off with all the bounce messages which I might add have manages to junk mail themselves now... (I made some type of MX recorded at the advise of V-tech support that tells the reciever that I did not send the message but this has not had any effect as of yet in curving the problem.
SPAM Following Wall Street now right down the chitter
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mail2 Problems...? Allen Chit Chat Public 7 08-29-2003 08:09 PM
mail2 and me MEELAN Chit Chat Public 3 06-25-2003 12:09 AM


All times are GMT -5. The time now is 03:44 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.48528 seconds with 18 queries
[Output: 107.17 Kb. compressed to 98.14 Kb. by saving 9.03 Kb. (8.42%)]