Open Relay Bjarne
    Open Relay Bjarne

From: Bjarne
Date: 2/1/16 9:35 AM
Topic: Open Relay
Type: General Discussions
Post a follow up

Greetings!

I have a problem with Xeams relaying inbound mail to outbound recipients, its acting as an Open Relay at the moment.

 I've got thousands of mails in my OutboundSendQueue folder.

Close Relay is enabled with only our internal ip subnet listed. I added my own subnet as test but didn't make any difference, the list was empty at first....

The xeams diagnostics states that everything is ok with the relay.

What's common with all relayed mails is that all of them have our domain as sender, which seems to override the Closed Relay setting.

For the moment I've enabled Grey Listing in order to temporarily halt the spammers somewhat.

Any suggestions folks?

/B

Top

From: Bjarne
Date: 2/2/16 1:15 AM
Topic: Open Relay
Type: General Discussions
Post a follow up

Main problem solved.

One of our Xeams user accounts was compromised and a spammer authenticated and started spamming using this account.

The closed relay sett was overridden by this fact and the user was allowed to use Xeams as outbound server, which was quite unfortunate as it eventually got blocked/blacklisted by Barracuda and others for spamming.

I which there was a way to disable smtp authentication, that could perhaps prevent this type of attacks. The user accounts are only used for http login as our Xeams box runs in hybrid mode, relaying all (good) emails to our backend exchange server.

/Bjarne

 

Top