P.Z. Low Cost CPanel Web Hosting  

Go Back   P.Z. Low Cost CPanel Web Hosting > Page-Zone Web Hosting Main Forum > General FAQ > General Questions and Comments

General Questions and Comments Post your question or grace us with your knowledge. Posting limited to registered members.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Help - my site email has been taken over by spammers
Old
  (#1 (permalink))
Gregg
Registered User
Gregg is on a distinguished road
 
Status: Offline
Posts: 8
Join Date: Jun 2005
Rep Power: 0
Help - my site email has been taken over by spammers - 03-01-2007, 01:18 PM

I tried the help desk, but for some reason I can not sign on to the help desk, and the phone message recording is full.

I disabled my site's email (at at the site)

Oddly the non-delivered spam is being bounced back to my personal email, not to the site. I thought it ran its course, but it has started up again.

Can someone please give me some advice so that I can stop this?

Thanks,


Gregg

classicaldomin.org
   
Reply With Quote
Old
  (#2 (permalink))
Jim
of Page-Zone
Jim will become famous soon enoughJim will become famous soon enough
 
Status: Offline
Posts: 1,134
Join Date: Jun 2002
Location: Wauseon, Ohio
Rep Power: 98
My location
03-01-2007, 08:58 PM

I remember answering a ticket about this yesterday, but not sure if it was you that put it in. The default email address should be set to :fail: And the instructions are on the cpanel page.


--
Thank You,
Jim Snape
Page-Zone
--
   
Reply With Quote
Old
  (#3 (permalink))
Gregg
Registered User
Gregg is on a distinguished road
 
Status: Offline
Posts: 8
Join Date: Jun 2005
Rep Power: 0
03-01-2007, 09:23 PM

Hi Jim,

It wasn't me, I could not log in. I know the help desk has been reconfigured, I thought that might have been a reason.

But that's my second order of business, thanks for the advice on #1.


Gregg
   
Reply With Quote
Old
  (#4 (permalink))
Gregg
Registered User
Gregg is on a distinguished road
 
Status: Offline
Posts: 8
Join Date: Jun 2005
Rep Power: 0
03-01-2007, 09:47 PM

Jim,

Ok, great it was so easy even I gotthe point.

That fixes the emails being bounced back to me, but some one is using my site to send (perhaps) millions of spam emails as xxxx@classicaldomain...

Is there a way to stop that?


Gregg
   
Reply With Quote
Old
  (#5 (permalink))
Jim
of Page-Zone
Jim will become famous soon enoughJim will become famous soon enough
 
Status: Offline
Posts: 1,134
Join Date: Jun 2002
Location: Wauseon, Ohio
Rep Power: 98
My location
03-02-2007, 12:40 AM

That is common to for spammers to find an address that answers to callbacks on anyword@thedomain.tld, and start using it like there's no tomorrow. And for them, there is no tomorrow because we seriously considering disableing catch all email addresses completely.

There is a total outbreak this month of spammers forging return addresses because they have to. Receiving servers have been switching over to callbacks for the past 6 months - that is, not accepting an email from the sender until they take the sending address and try calling it back to see if they are an actual email server. We did it (callbacks) for a while, months ago.

When a domain sets their email up to say yes to ANY word@domain.tld the spammers, once they find a domain doing that, now have a fake return address they can use. One that will answer to call backs instead of ":no such user"

Long story short, there's no way to stop someone from forging your address, aside from doing what you just did. Eventually it will be worthless to them.

You cannot be blamed as the spammer by anyone because the spam didn't originate from our network. What could happen though - if there is an autoresponder set up to respond to spam, eventually one of those spams will be returned to someone whose email address was forged, they will turn you in, and most ISP's would regard you as a spammer, including our ISP (level3). We would get a nast letter from them and have to get all posturish and threatening at you.

Not meaning you personally. I have no idea if you have an autoresponder set up. This is just for the sake of the achive of this post. We have had a couple complaints from level3, and they aren't fun. They go a little something like this "We've found out you are breaking your terms of service, and you have 6 hours to tell us why before the fiber is cut".


--
Thank You,
Jim Snape
Page-Zone
--
   
Reply With Quote
Wilco, but can you explain it?
Old
  (#6 (permalink))
Sailmariner
Registered User
Sailmariner is on a distinguished road
 
Status: Offline
Posts: 20
Join Date: Nov 2002
Rep Power: 39
Wilco, but can you explain it? - 03-09-2007, 10:19 AM

Hi, Jim--

I have gone through a number of my domains and set the default address to :fail: no such address here. I will march through all of them now and do that to each one.

I would just like to understand what the specific effect is.

If I get the picture correctly, the spam message hits our domain and encounters the ":fail" response, which sends the message back into the cloud somewhere. I infer that it never stays on our mail server, so it cannot clog the server or our individual domains. But please correct me if I am wrong.

But when a spam message hits the server, isn't that already traffic that is logged against us? In other words, haven't we already gotten a bad rep?
   
Reply With Quote
Old
  (#7 (permalink))
jerbell
Registered User
jerbell is on a distinguished road
 
Status: Offline
Posts: 3
Join Date: Sep 2003
Rep Power: 0
03-21-2007, 10:39 PM

I would LOVE to be able to set default address to :fail: but when I do all mail to the the main address gets bounced too...since about the time this thread started I have lost all my mail, and didn't notice it until tonite when I was trying to catch up on it. This is the second time the default address has been changed to :fail: for me and has screwed me over in the last year. Please stop changing my default mail setting or fix the problem where it also bounces mail to the domains main email account.
   
Reply With Quote
Old
  (#8 (permalink))
Jim
of Page-Zone
Jim will become famous soon enoughJim will become famous soon enough
 
Status: Offline
Posts: 1,134
Join Date: Jun 2002
Location: Wauseon, Ohio
Rep Power: 98
My location
03-22-2007, 01:36 PM

If you let me know the domain I can make the config file unchangeable. The fix is easy though - for example:
current username = hal
default email = hal

create an email address
anything@yourdomain.tld
log into it to get mail w/ username anything@yourdomain.tld
change default email to anything@yourdomain.tld instead of 'hal'

Then mail for any word at your domain would go to the one box.

Then if we need to go through and eliminate dictionary attacks server wide the your domain will be invisible to the search/replace operation. Thats probably the most reliable way because setting the immutable bit on the config file requires us to remember it was set for a reason at some point instead of "fixing" it when the search/replace script dies there.


--
Thank You,
Jim Snape
Page-Zone
--
   
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
My site is down (i'm on server 4)? Anyone else's site down? Gartner General Questions and Comments 1 10-21-2006 05:29 PM


Live Help



Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC6
vBulletin Skin developed by: vBStyles.com
Copyright © 2002 Page-Zone Web Hosting. All rights reserved.
Smilies provided by Crack's Smilies http://www.mysmilies.com