Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


AartJansen

26 posts

Geek


#105225 29-Jun-2012 14:55
Send private message

So last week a clients server had a user account hacked, then abused to send bulk spam.
Telecom handled the problem really well.

1st they rang the business owner the next day "your email has been blocked, you are sending so much spam you will shut down the internet" apparently the guy said that 4 or 5 times.

At this point the problem hadn't been identified. I assumed some kind of open relay was created by the techs who installed a scan to email machine a few weeks earlier, and it had been exploited. I ensured there was no relay, turned on maximum event logging.

Next day there was more spam, but I had enabled logging so saw that an IP from germany was loggin in as a local user, and delivering bulk email.

I changed the password/ hardened the password policy, cleared the queues, and thought all done.

Email still wasn't going, senders were bouncing immediately  from the backup mx server hosted by xtra (wierd I thought).

Got xtra to delete the backup record, screw it I thought we'll add it back later.

Still no email, xtra perpetually denied it was them, just wait! can take 24 hours to remove the block (obviously xtra don't manage such things themselves its outsourced to yahoo i bet)

Then several calls later they admitted the server got blacklisted, not by any reputable blacklist (I had been checking) but by xtra, apparently they have their own blacklist, that you can't know about or check yourself, real helpful.

Now a full week later, and after emails had worked again, mail outbound to xtra are borked once more.

Create new topic
CYaBro
4583 posts

Uber Geek

ID Verified
Trusted

  #648300 29-Jun-2012 16:08
Send private message

Sign them up for something like SMX and use that for the SMTP server.
That's what we're moving our bigger clients over to.
Never have to worry about being blacklisted again and also works as a backup MX if the client's server goes down.




Opinions are my own and not the views of my employer.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.