Welcome to Geeklog, Anonymous Wednesday, November 27 2024 @ 05:42 am EST
Geeklog Forums
Outgoing SPAM
ronack
( I tried to include the log file but it detected it as spam)
Here is a link to a txt file
ironmax
I'm not sure how this is going on but I'm receiving delivery failure notices from the account i use in GL. The message is in Spanish, a few weeks ago I received a good 20 or 30 failure notices which indicate to me that SPAM is outgoing from my server. I did find this in my GL log which looks rather dubious. But since none of this is in Spanish I don't think this is it. Any ideas?
( I tried to include the log file but it detected it as spam)
Here is a link to a txt file
Your link does not resolve from my end. Nor do I get any DNS lookup info on it. Well atleast at the time of this posting.
Michael
Dirk
I'm not sure how this is going on but I'm receiving delivery failure notices from the account i use in GL.
With "account" you mean the email address? You realize that this can easily (trivially, even) be faked? Happens to everyone eventually ...
If you mean something else, we would need to be able to see that text file you linked to, but it's giving me a 404 ...
bye, Dirk
Dirk
( I tried to include the log file but it detected it as spam)
Found it in our logs (slightly censored):
<methodCall>
<methodName>slv</methodName>
<params>
<param>
<value><string>http://groups.google.ru/group/buy_ambien_online/...
http://groups.google.ru/group/.../best-ambien-prices-free-overnight-shipping</string></value>
</param>
</params>
</methodCall>
But that's just a notification that Spam-X was unable to contact SLV to see if those URLs should be considered spam (obviously, they are).
Looks fine to me: Someone tried to post spam on your site. Spam-X tried to get SLV's opinion on those URLs but SLV was unreachable or at least did not respond in time, so that problem was logged and the processing of the post continued without SLV's input. If it didn't show up on your site, then some other Spam-X module caught it. Check your spamx.log, you should have an entry there with the same timestamp.
bye, Dirk
ronack
This is the header of the message.
laudinha@telefonica.net
Return-Path: <Masked My Email Address>
Message-ID: <BAY0-MC2-F5mzfYuYyF002029c3@bay0-mc2-f5.bay0.hotmail.com>
X-OriginalArrivalTime: 29 Apr 2008 04:15:45.0789 (UTC) FILETIME=[B26C92D0:01C8A9AF]
Dirk
Having said that: We had an embarrassing case recently where a Nigerian scam artist used geeklog.net to send their stuff via the "Send email" link from the profile. Those should show up in your logfiles, though.
Oh, and if those bounces contain the original spam text, feed some of the keywords to Spam-X and see if it catches anything (enable notifications or keep an eye on your spamx.log).
bye, Dirk
- Normal Topic
- Sticky Topic
- Locked Topic
- New Post
- Sticky Topic W/ New Post
- Locked Topic W/ New Post
- View Anonymous Posts
- Able to post
- Filtered HTML Allowed
- Censored Content