Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: exim: users

Joe job attack to my mail server.

 

 

exim users RSS feed   Index | Next | Previous | View Threaded


dinoosh.niki at gmail

Jun 21, 2012, 12:09 AM

Post #1 of 3 (268 views)
Permalink
Joe job attack to my mail server.

Hi all,

My mail server is in joe job attack. I cannot send mails coz that ip is
black listed. I tried to stop sending spam by adding acls and configuring
SPF but couldn't.

I'm really messed up right now. I attached my Exim config file also.

Need guide lines to get this fixed.

Another thing when i took over the old mail server of this domain was
already blacklisted.

Thanks,
Dinoosh.
--
## List details at https://lists.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/


dinoosh.niki at gmail

Jun 21, 2012, 12:10 AM

Post #2 of 3 (259 views)
Permalink
Joe job attack to my mail server. [In reply to]

Hi all,

My mail server is in joe job attack. I cannot send mails coz that ip is
black listed. I tried to stop sending spam by adding acls and configuring
SPF but couldn't.

I'm really messed up right now. I attached my Exim config file also.

Need guide lines to get this fixed.

Another thing when i took over the old mail server of this domain was
already blacklisted.

Thanks,
Dinoosh.
Attachments: config.txt (76.4 KB)


graeme at graemef

Jun 21, 2012, 1:43 AM

Post #3 of 3 (259 views)
Permalink
Re: Joe job attack to my mail server. [In reply to]

On Thu, 2012-06-21 at 12:40 +0530, Dinoosh Nikapitiya wrote:
> My mail server is in joe job attack.

A "Joe Job" by definition does not involve your server, except that it
receives complaints or bounces aimed at your domain for messages which
did not originate there.

> I cannot send mails coz that ip is
> black listed. I tried to stop sending spam by adding acls and configuring
> SPF but couldn't.

So you're sending spam - that's not a Joe Job.

You should be able to tell from your logs what's happening - either
you're an open relay, or one of your users has had their credentials
pilfered and their account is being used to spam.

If I'm reading your config correctly, acl_check_dkim is not used *but*
is subsequently defined in the middle of acl_check_rcpt, which is
further broken by having "accept" as the first non-commented line. That
makes you an open relay.

You need to reconfigure your system, and you might aswell do it the
right way for your operating system by using the appropriate
dpkg-reconfigure command to do it.

Graeme


--
## List details at https://lists.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/

exim users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.