• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Mulit - Bounce Problem !!!

M

Matt.D

Guest
Hi all.

Since Friday I have been receiving about 600 emails into be server default address.

The emails seem to be multiple bounce.

I get a SPAM to a non-existant email address at one of the hosted domains.

QMail then sends it back to the email address of the SPAM email (as we all know, 99% of the time this one doesn't exist either). However this bounce is tagged with the default details of my server [email protected]

This these details does correspond to the info inbox at this domain.

I am running PLESK 7.5.4
on Fedora Core 1

I also got PSA Spam Guardian. Which is tagging the final bounce email as "SPAM". This would suggest that the second bounce comes from outside. But how can this be if QMail cannot deliver it???
Is this therefore a SPAM email that is made to look like a double bounce failure??????
But how would they know my server details?

Below is one of the hundreads of email I have been recently getting

Code:
Hi. This is the qmail-send program at sm12135.eaglenetworks.co.uk.
I tried to deliver a bounce message to this address, but the bounce bounced!

<[email protected]>:
71.121.128.146 does not like recipient.
Remote host said: 550 5.1.1 User unknown
Giving up on 71.121.128.146.

--- Below this line is the original bounce.

Return-Path: <>
Received: (qmail 682 invoked for bounce); 23 Aug 2006 21:36:46 +0000
Date: 23 Aug 2006 21:36:46 +0000
From: [email][email protected][/email]
To: [email][email protected][/email]
Subject: failure notice

Hi. This is the qmail-send program at sm12135.eaglenetworks.co.uk.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<[email protected]>:
This address no longer accepts mail.

--- Below this line is a copy of the message.

Return-Path: <[email protected]>
Received: (qmail 679 invoked from network); 23 Aug 2006 21:36:45 +0000
Received: from q9b39.q.pppool.de (HELO cdcmanagement.com) (89.53.155.57)
  by host204.maxim.net with SMTP; 23 Aug 2006 21:36:45 +0000
Received: by 192.168.49.195 with SMTP id yGApUjj;
        for <[email protected]>; Wed, 23 Aug 2006 14:36:44 -0700
Message-ID: <000001c6c6fc$3acab820$c331a8c0@xwpww>
Reply-To: "Ghislaine Bahr" <[email protected]>
From: "Ghislaine Bahr" <[email protected]>
To: [email][email protected][/email]
Subject: Re: new ri
Date: Wed, 23 Aug 2006 14:36:44 -0700
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0001_01C6C6C1.8E72E500"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106

This is a multi-part message in MIME format.

------=_NextPart_000_0001_01C6C6C1.8E72E500
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi,
=20
Not very good erecxction? You are welcome - [url]http://sonfolo.com/s/[/url]

=20

=20

=20

Theres more to it than that. But first a few introductions. The
bruised guy with red fur is Iron John. Leader of a cult which you are
now going to abolish. You can ship him off for treatment at an



------=_NextPart_000_0001_01C6C6C1.8E72E500
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2800.1106" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>Hi,</DIV>
<DIV>&nbsp;</DIV>
<DIV>Not very good erecxction? You are welcome - <A =
href=3D"http://sonfolo.com/s/">[url]http://sonfolo.com/s/[/url]</A></DIV><P>&nbsp;</=
P><P>&nbsp;</P><P>&nbsp;</P><P> Theres  more  to  it than that. But =
first a few introductions.  The<BR>
bruised guy with red fur is Iron John. Leader of a cult which you  =
are<BR>
now  going  to  abolish.  You can ship him off  for  treatment  at  =
an<BR></P></BODY></HTML>
------=_NextPart_000_0001_01C6C6C1.8E72E500--

Said it before, will say it again.
You guys are brilliant, and all your help and advise is much appreciated ;)
 
to stop double bounces, create the file: /var/qmail/control/doublebounceto containing #
 
I think bounce message are very usefull when the email is genuine.

So, I don't want to get rid of bounce option, if anything, I want to get access to the template to expand on the message.


What concerns me why I am being flooded all of a sudden. I have not had this problem before. Just the last week.

Have I been hacked?
Do I have a flaw in my security setting?
 
Hacked or Corrup?

Hey all,

I don't know if anyone has had a chance to look at this thread, but my emails are going through the roof.

I have been trying to look through the emails that bounce back, but there are sooo many I can't view them all.

However, the thing that surprised me is that INTERNAL emails are among the emails bounce back to MAILER-DAEMON and POSTMASTER.
Why would this be?

Has a security loop-hole been exploited on my server?
Is qmail, or something, corrupt?
Have I been hacked?

(Also, I have tried to use http://www.abuse.net/relay.html, but the instructions are not very clear. where can I read up on how to use this tool?)
 
Back
Top