?????Pls remove me I have been hacked!!!

Valeri Galtsev galtsev at kicp.uchicago.edu
Fri Jan 9 03:33:19 UTC 2015


On Thu, January 8, 2015 7:21 pm, Erich Dollansky wrote:
> Hi,
>
> On Thu, 08 Jan 2015 17:34:14 -0600
> Valeri Galtsev <galtsev at kicp.uchicago.edu> wrote:
>
>> Is that only me or others noticed too that every first message of new
>> thread on this list if followed by junk like this. This apparently
>> was delivered from domain
>>
> this is an old thing. It comes and goes.
>
>> sina.com.cn
>>
>> Would that be reasonable to reject all mail of that origin on the MX
>> level?
>>
> It is not that easy. The sender addresses change very often.
>

That is what I assumed from the very beginning. With these things on my
servers I usually do this: I find out which domain sender's MX serves.
Then I send complaint to

abuse at that.domain.com

No one usually gets back to me (at least from that geoip location no one
ever did). Then I send similar complaint appended with note that abise@
never came back to me to postmaster at that.domain.com. After that I set my
MX to reject mail with message that that domain didn't respond abuse
complaint. [Did I miss something decent sysadmin should do in the case?]

But, of course, freebsd.org has quite different audience from a couple of
Departments of some university...

Valeri

>> Sorry about sending spam in name of fighting spam.
>
> Isn't this real life?
>
> Erich



++++++++++++++++++++++++++++++++++++++++
Valeri Galtsev
Sr System Administrator
Department of Astronomy and Astrophysics
Kavli Institute for Cosmological Physics
University of Chicago
Phone: 773-702-4247
++++++++++++++++++++++++++++++++++++++++


More information about the freebsd-questions mailing list