[Mimedefang] New spammer trick?

mfaurot at atww.org mfaurot at atww.org
Wed Nov 26 15:43:43 EST 2003


In article <Pine.GSO.4.44.0311261301440.17003-100000 at www.uah.edu> you wrote:


> On Wed, 26 Nov 2003, Ben Kamen wrote:

>> rr.com has been a singular pain the in butt in terms of spam for me.

>   Same here.  Their security site claims that they scan customers for
> relay vulnerabilities, but we get spammed by them all the time.

I suspect what's happening lately is not so much open relays from these
consumer dialup and broadband customers, but the results of spamware
viruses (e.g., Mimail).  I don't know the specifics on how these viruses
work, but I suspect they don't answer connections on port 25/tcp like
a real SMTP MTA would, and thus probably wouldn't be seen by open relay
scanners.



More information about the MIMEDefang mailing list