Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Backscatterer: How to get sample emails?

13 views
Skip to first unread message

David E. Smith

unread,
Aug 12, 2008, 8:00:44 PM8/12/08
to
Apparently, my office (I work for a small ISP) has ended up on the
backscatterer list. I've dug through all the relevant logs and configurations
(we do have several email servers in-house), and I'm not sure where the
back-scatter would be coming from (i.e. which server specifically, how
it's routed, et cetera).

Is it possible to request "samples" of the emails that got me listed, so
I can review their headers and find out where the backscatter is coming
from in the first place? If so, to whom should I speak? I don't see anything
that looks terribly relevant on the backscatterer.org Web site (that site,
in fact, directs people here, which seems a bit odd, but whatever).

dave

--
Comments posted to news.admin.net-abuse.blocklisting
are solely the responsibility of their author. Please
read the news.admin.net-abuse.blocklisting FAQ at
http://www.blocklisting.com/faq.html before posting.

Seth

unread,
Aug 13, 2008, 12:02:18 PM8/13/08
to
In article <6gegljF...@mid.individual.net>,

David E. Smith <da...@technopagan.org> wrote:
>Apparently, my office (I work for a small ISP) has ended up on the
>backscatterer list.

>Is it possible to request "samples" of the emails that got me listed, so

>I can review their headers and find out where the backscatter is coming
>from in the first place?

You could start by posting the IP address. No guarantees, but that
might help somebody find something.

Seth

da...@technopagan.org

unread,
Aug 13, 2008, 4:46:33 PM8/13/08
to
Seth <se...@panix.com> wrote:
>>Is it possible to request "samples" of the emails that got me listed, so
>>I can review their headers and find out where the backscatter is coming
>>from in the first place?
>
> You could start by posting the IP address. No guarantees, but that
> might help somebody find something.

That's a "duh" moment for me.

66.232.160.81.

dave

E-Mail Sent to this address will be added to the BlackLists

unread,
Aug 14, 2008, 9:25:23 AM8/14/08
to
da...@technopagan.org wrote:
> 66.232.160.81.

I see an 2008 Aug
Received: from outboundmail.mvn.net (outboundmail.mvn.net [66.232.160.81])
From: "Postmaster" <postm...@wdml.com>
Subject: Undeliverable Mail
User mailbox exceeds allowed message count: mun...@wdml.com
...
<that apparently includes the complete original Pharma Spam.>


I see some old stuff from 2008 Jan like:
client-ip=66.232.160.81; envelope-from=wireless-bounces at wispa.org; helo=outboundmail.mvn.net;


X-Barracuda-Virus-Scanned:by MVN Junkmail Filtering System at mvn.net
(if that doesn't have all three sections turned off for
notifications, it will cause backscatter.)


FYI: <http://www.projecthoneypot.org/i_732bef444088034b0db3f15b100a0c50>

--
E-Mail Sent to this address <Blac...@Anitech-Systems.com>
will be added to the BlackLists.

David E. Smith

unread,
Aug 14, 2008, 11:10:14 AM8/14/08
to
<Nu...@blacklist.anitech-systems.invalid> wrote:

[ snip: something that looks like one of my customers ]

sigh.

One of those sure does look like it came from my ancient mail system.
I'm not sure I can persuade it to stop sending "mailbox full" notices,
because if I could I probably would've done that a few years ago. (I
know, the "right" answer is not to use mail software that hasn't been
updated since 2003, and that doesn't accept messages that lead to
backscatter in the first place, but welp.)


> X-Barracuda-Virus-Scanned:by MVN Junkmail Filtering System at mvn.net
> (if that doesn't have all three sections turned off for
> notifications, it will cause backscatter.)

I did that when we first got the Barracuda mail filters. They're not the
problem, at least. I have exciting new problems instead! :D

Wish me luck!

dave

Atro Tossavainen

unread,
Aug 14, 2008, 6:55:34 PM8/14/08
to
<da...@technopagan.org> writes:

> >>Is it possible to request "samples" of the emails that got me listed, so
> >>I can review their headers and find out where the backscatter is coming
> >>from in the first place?
> >
> > You could start by posting the IP address. No guarantees, but that
> > might help somebody find something.
>
> That's a "duh" moment for me.
>
> 66.232.160.81.

It is a mail system that accepts messages addressed to accounts that
can't be delivered into (for any reason, such as over quota). The
bounces it generates are not RFC 3464 Delivery Status Notifications,
but whatever the authors of "SMTPD32-8.15" (CastleCops IMail Server)
decided to invent.

It also seems that the system accepts mail from IPs listed on the
Spamhaus PBL, which might increase the likelihood of events such
as the above.

--
Atro Tossavainen (Mr.) / The Institute of Biotechnology at
Systems Analyst, Techno-Amish & / the University of Helsinki, Finland,
+358-9-19158939 UNIX Dinosaur / employs me, but my opinions are my own.
< URL : http : / / www . helsinki . fi / %7E atossava / > NO FILE ATTACHMENTS

phil-new...@ipal.net

unread,
Aug 19, 2008, 7:44:50 PM8/19/08
to
On Wed, 13 Aug 2008 20:46:33 GMT da...@technopagan.org wrote:
| Seth <se...@panix.com> wrote:
|>>Is it possible to request "samples" of the emails that got me listed, so
|>>I can review their headers and find out where the backscatter is coming
|>>from in the first place?
|>
|> You could start by posting the IP address. No guarantees, but that
|> might help somebody find something.
|
| That's a "duh" moment for me.
|
| 66.232.160.81.

================================================================
phil@hadar:/home/phil 1690> ptr 66.232.160.81
81.160.232.66.in-addr.arpa. 86400 IN PTR outboundmail.mvn.net.
phil@hadar:/home/phil 1691> a outboundmail.mvn.net
outboundmail.mvn.net. 7200 IN A 66.232.160.104
phil@hadar:/home/phil 1692> ptr 66.232.160.104
104.160.232.66.in-addr.arpa. 86400 IN PTR outboundmail.mvn.net.
phil@hadar:/home/phil 1693>
================================================================

So which is your outbound server? If both are, maybe you should list both
IP addresses in DNS A records for that name. You can have many IP addresses
for one name, depending on the length of the name.

Sending email from 66.232.160.81 to my servers would be rejected due to the
lack of 66.232.160.81 in the A records for the name returned via a PTR lookup
for 66.232.160.81 (e.g. for "outboundmail.mvn.net"). OTOH, sending email from
66.232.160.104 would have worked (unless the list you are on is one I use,
and 66.232.160.104 is on the list).

Maybe you should check and see what the actual error message is on rejected
mail. I know a lot of mail servers will reject 66.232.160.81 in this case.

I see you are running Postfix on 66.232.160.104. I get no connection on port
25 with 66.232.160.81 (as an outbound only server, it need not answer port 25).
Your inbound (MX) servers do not indicate what software. So I hope it's not
Qmail or Exchange.

================================================================
phil@hadar:/home/phil 1693> telnet 66.232.160.81 25
Trying 66.232.160.81...

phil@hadar:/home/phil 1694> telnet 66.232.160.104 25
Trying 66.232.160.104...
Connected to 66.232.160.104.
Escape character is '^]'.
220 outboundmail.mvn.net ESMTP Postfix
^]
telnet> quit
Connection closed.
phil@hadar:/home/phil 1695> telnet 66.232.160.15 25
Trying 66.232.160.15...
Connected to 66.232.160.15.
Escape character is '^]'.
220 junkmail.mvn.net ESMTP (65593871720659961c279604cbf3c666)
^]
telnet> quit
Connection closed.
phil@hadar:/home/phil 1696> telnet 66.232.160.16 25
Trying 66.232.160.16...
Connected to 66.232.160.16.
Escape character is '^]'.
220 junkmail.mvn.net ESMTP (d8ca629411325e1c0de11e9f4f63cafb)
^]
telnet> quit
Connection closed.
phil@hadar:/home/phil 1697>
================================================================

Some funny aliasing here, but it shouldn't be a cause of a problem:

================================================================
phil@hadar:/home/phil 1697> a junkmail.mvn.net
junkmail.mvn.net. 7200 IN A 66.232.160.15
junkmail.mvn.net. 7200 IN A 66.232.160.16
phil@hadar:/home/phil 1698> ptr 66.232.160.1{5,6}
15.160.232.66.in-addr.arpa. 86400 IN PTR mx1.mvn.net.
16.160.232.66.in-addr.arpa. 86400 IN PTR mx2.mvn.net.
phil@hadar:/home/phil 1699> a mx{1,2}.mvn.net
mx1.mvn.net. 7200 IN A 66.232.160.15
mx2.mvn.net. 7200 IN A 66.232.160.16
phil@hadar:/home/phil 1700>
================================================================

--
|WARNING: Due to extreme spam, googlegroups.com is blocked. Due to ignorance |
| by the abuse department, bellsouth.net is blocked. If you post to |
| Usenet from these places, find another Usenet provider ASAP. |
| Phil Howard KA9WGN (email for humans: first name in lower case at ipal.net) |

0 new messages