PDA

View Full Version : Somebody on 70.96.188.111 is seriously spamming.



A.Gabston-Howell
03-10-2006, 10:10 PM
Twice in the past few weeks, we've discovered that U.C. Davis has blacklisted IP addy: 70.96.188.111 (outbound-mail-11.bluehost.com) for the below indicated reasons. (See the below email scrap.)

It would be very much appreciated if the logs for that box are inspected and the offender given notice, stern warning, the boot...whatever is necessary to clean things up.

Not the highest priority that Matt, et al, could have; but keeping the BlueHost neighborhood clean would be quite the responsible thing to do.

Is anyone else finding their out-bound mail traffic being RBL'ed because of things like this?

> ----- Original Message -----
> From: <ithelp_[AT]_ucdavis.edu>
> To: <_[MASKED EMAIL ADDY]_>
> Sent: Friday, March 10, 2006 8:52 AM
> Subject: Address Removed from RBL
>
>
> Your request for the removal of system 70.96.188.111 was accepted.
> Please wait approximately two to three hours before attempting to send
> your email message again.
>
> Administrator comments: Your email address has not been blocked by UC
> Davis. However the email server your messages were going through,
> outbound-mail-11.bluehost.com, with an ip address of 70.96.188.111, was
> identified sending a large number of messages in a short period of time,
> of which a vast of majority were either scanned as spam or viruses by the
> campus filters. We have released the block on the server at 70.96.188.111,
> however, if a similar mailing pattern comes from 70.96.188.111 in the
> future it will end up on the block list again.
>
>
>

A.Gabston-Howell
03-10-2006, 11:22 PM
Subject: failure notice
Message-Id: <E1FHxpS-0006Sr-Ig@box34.bluehost.com>
Status: R
X-Status: NC
X-KMail-EncryptionState:
X-KMail-SignatureState:
X-KMail-MDN-Sent:

Hi. This is the qmail-send program at outbound-mail-25.bluehost.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<_RECIPIENT ADDY MASKED_>:
Connected to 169.237.104.82 but sender was rejected.
Remote host said: 550 5.7.1 Your mail server has been marked as sending spam. Visit http://email.ucdavis.edu/rbl/index.php?ip=70.103.189.17 for more information

--- Below this line is a copy of the message.

Yadda-yadda-yadda.


http://email.ucdavis.edu/rbl/index.php?ip=70.103.189.17 shows:
IP Address: 70.103.189.17
Hostname: outbound-mail-22.bluehost.com
Type: abused
Date Added: 2006-02-19 08:36:54
Status: active

crazypenguin
03-11-2006, 03:21 AM
It seems Bluehost has enough problems wih just trying to keep the servers running. The last thing they need is some dirt bag jerk clogging the servers with spam.....................

rando
03-11-2006, 11:08 PM
It seems Bluehost has enough problems wih just trying to keep the servers running. The last thing they need is some dirt bag jerk clogging the servers with spam.....................

A very very very large part of my job is to stop people from spamming while trying to keep legitimate email working as nicely as possible. In a shared hosting solution like bluehost is, one person spamming can get a whole lot of other people banned.

Unfortunately, most people out there, instead of reporting the email to bluehost, just instantly ban it.

On wednesday/thursday, we had someone who had found an exploit in our system which made it so we couldn't detect who was sending the email, and sent out a lot of email. When I finally found out who he was and found a way to track him, I deleted 35,000 messages from our queue sent by him. A lot more than that got out. Since then I've been working on fixing that exploit and working on better logging systems so i can monitor trends in email sending, which has pre-empted my work on other projects.

I guess the point is, my job sucks sometimes. I hate spammers. :(

dvessel
03-13-2006, 02:45 PM
I thought this was interesting. It's from my old host.. Maybe it could give you some ideas.

http://blog.dreamhost.com/2005/12/09/we-want-our-spam-back/

It's basically about how larger companies can return spam in a specific way so the host where the spam originated can track and thus reduce outgoing spam. Just thought it was interesting.

John
03-14-2006, 10:37 PM
I thought this was interesting. It's from my old host.. Maybe it could give you some ideas.

http://blog.dreamhost.com/2005/12/09/we-want-our-spam-back/

It's basically about how larger companies can return spam in a specific way so the host where the spam originated can track and thus reduce outgoing spam. Just thought it was interesting.Now that's cool! Fight fire with fire...lol... love it.

:D