Mail Server Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationMail Server Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old November 30th, 2004, 01:39 PM
garbonzo boy garbonzo boy is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 3 garbonzo boy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Strange looking bounce messages - Qmail

I had a spammer exploiting a webmail module in the php-nuke installation on my server. I've since deactivated the module and everything seems to be back to normal, except for the occasional strange bounce message. The bounce lists multiple addresses as the intended recipients and the reason each message failed. The attached message however, is one that is sent hourly as a test for a mail gateway, not a spammer generated message. My fear is that there is a much larger recipient list and the ones not listed in the bounce message have been delivered.

Even stranger is that when I've scoured the logs, I can't find any attempts made to deliver the message to anyone but the original intended recipient. Where is this bounce message and/or recipient list coming from? The headers don't reveal anything either. Here's the bounce message:

Code:
Return-Path: <#@[]>
Delivered-To: xxxx@evinrude.eurydium.org
Received: (qmail 22015 invoked by alias); 30 Nov 2004 00:01:03 -0000
Delivered-To: xxxx@evinrude.eurydium.org
Received: (qmail 22010 invoked for bounce); 30 Nov 2004 00:01:03 -0000
Date: 30 Nov 2004 00:01:03 -0000
From: MAILER-DAEMON@evinrude.eurydium.org
To: xxxx@evinrude.eurydium.org
Subject: failure notice

Hi. This is the qmail-send program at evinrude.eurydium.org.
I tried to deliver a bounce message to this address, but the bounce bounced!

<tania.payne@max2.maxwell.af.mil>:
Sorry, I couldn't find any host named max2.maxwell.af.mil. (#5.1.2)

<melville55@juno.com>:
64.136.20.83 does not like recipient.
Remote host said: 550 melville55@juno.com Account Inactive
Giving up on 64.136.20.83.

<crockerj@usa.net>:
165.212.8.32 does not like recipient.
Remote host said: 550 <crockerj@usa.net>... User not known
Giving up on 165.212.8.32.


And many, many, many more failed recipients until it wraps up like this:

Code:
<sois@juno.com>:
64.136.28.83 does not like recipient.
Remote host said: 550 sois@juno.com Account Inactive
Giving up on 64.136.28.83.

<typierce@insightbb.com>:
63.240.76.150 does not like recipient.
Remote host said: 551 not our customer
Giving up on 63.240.76.150.

<tmbc@bellsouth.net>:
205.152.59.33 does not like recipient.
Remote host said: 550 Invalid recipient: <tmbc@bellsouth.net>
Giving up on 205.152.59.33.

<ccampbell@pky.com>:
63.124.238.114 does not like recipient.
Remote host said: 550 5.1.1 User unknown
Giving up on 63.124.238.114.

--- Below this line is the original bounce.

Return-Path: <>
Received: (qmail 22007 invoked for bounce); 30 Nov 2004 00:01:02 -0000
Date: 30 Nov 2004 00:01:02 -0000
From: MAILER-DAEMON@evinrude.eurydium.org
To: xxxx@evinrude.eurydium.org
Subject: failure notice

Hi. This is the qmail-send program at evinrude.eurydium.org.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<xxxx@omaropo.hyatt.com>:
Connected to 140.95.205.120 but sender was rejected.
Remote host said: 553 5.3.0 <xxxx@evinrude.eurydium.org>... OKR

--- Below this line is a copy of the message.

Return-Path: <xxxx@evinrude.eurydium.org>
Received: (qmail 22002 invoked by uid 0); 30 Nov 2004 00:01:01 -0000
Date: 30 Nov 2004 00:01:01 -0000
Message-ID: <20041130000101.22001.qmail@evinrude.eurydium.org>
Subject: Test Mon Nov 29 18:01:01 CST 2004
To: "Helpdesk" <xxxx@omaropo.hyatt.com>
From: "Gateway Cop" <xxxx@eurydium.org>
CC:


Test Message.


I'll get one like that once a week or so. Any ideas?
Thanks!

Reply With Quote
  #2  
Old December 3rd, 2004, 08:26 AM
dba_frog's Avatar
dba_frog dba_frog is offline
cave painting, the 1st Opn Src
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2003
Posts: 407 dba_frog User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 21 h 9 m 2 sec
Reputation Power: 6
That is someone sending email to accts that are non-existant on your qmail. It also means that you didn't set any of your email accts to be a catchall.
I use the qmailadmin in my qmail install to have a catchall acct for this spam...
__________________
Curious by Nature,
Linux by Choice

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationMail Server Help > Strange looking bounce messages - Qmail


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT