Ondanks dat ik mijn server goed dichtgetimmerd heb tegen relaying, twee antiviruspakketten draai, GFI mailsecurity en GFI Mailessentials draai zijn er vorige week zaterdag en vandaag toch een hoop spambercten verstuur.
De queue gestopt en vervolgen de map queue leeggemaakt.
Hierin stonden enkele honderden eml files.
Deze zouden van de sec@i-r-s.org zijn.
hieronder de message source van dit bericht.
Received: from User ([216.153.68.26]) by domeinnaam.nl with Microsoft
SMTPSVC(6.0.3790.3959); Sun, 13 Jul 2008 11:10:57 +0200
Reply-To: <sec@i-r-s.org>
From: "Internal Revenue Service"<sec@i-r-s.org>
Subject: Your Tax Refund Notification (Message ID NH-83521)
Date: Sun, 13 Jul 2008 04:11:42 -0500
MIME-Version: 1.0
Content-Type: text/html;charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 1
X-MSMail-Priority: High
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Return-Path: sec@i-r-s.org
Message-ID: <S01-DZHc9ny7BXx4XFK000000a7@domeinnaam.nl>
X-OriginalArrivalTime: 13 Jul 2008 09:10:57.0250 (UTC)
FILETIME=[5C424C20:01C8E4C8]
X-EC0D2A8E-5CB7-4969-9C36-46D859D137BE-PartID:
001E0B95-5E16-416C-B3F4-6906A663E6BE
<img
src="http://upload.wikimedia.org/wikipedia/commons/thumb/8/8b/US-InternalRevenu
eService-Seal.svg/140px-US-InternalRevenueService-Seal.svg.png" width="160"
height="140"><br><br>
<font face="Courier New" size="2">After the last
annual calculations of your fiscal activity we have determined
that<br>
you are eligible to receive a tax refund of
<b>$620.50</b>.<br>Please
submit the tax refund request and allow us 3-6 days in order to<br>
process it.</font><br><br>
<font face="Courier New" size="2">A refund can be delayed for a variety of
reasons.<br>
For example submitting invalid records or applying after the deadline.<br><br>
<font size="2" face="Courier New">To access the form
for your tax refund,
please <b><a
href="http://0xd8a1cf0a/secure/service/taxrefund/gov/e-file.html">click
here</a></b></font><br><br><br>
<font size="2" face="Courier New" color="red"><b>Note:</b> For security
reasons, we will record your ip-address, the date and time.<br>Deliberate wrong
inputs are criminally pursued and indicated. </b></font><br><br><br>
<font face="Courier New" size="2">Regards, <br>
Internal Revenue Service</font></p><br><br>
<font face="Courier New" color="#C0C0C0" size="2">Copyright 2008, Internal
Revenue Service U.S.A. All rights reserved.
Ik heb de domeinnaam vervangen door domeinnaam.nl
Het logo in het mailtje komt waarschijnlijk bij wikipedia vandaan.
Ik heb NDR spamming volgens mij goed afgevangen door de server te beveiligen volgens.
ESM>domein>Global Settings>Message Delivery>properties
Recipient filtering > Filter Recipients who are not in the Directory
Vervolgens deze filter enabled op de SMTP connector.
Hoe kom ik van deze vorm van spam af?
De queue gestopt en vervolgen de map queue leeggemaakt.
Hierin stonden enkele honderden eml files.
Deze zouden van de sec@i-r-s.org zijn.
hieronder de message source van dit bericht.
Received: from User ([216.153.68.26]) by domeinnaam.nl with Microsoft
SMTPSVC(6.0.3790.3959); Sun, 13 Jul 2008 11:10:57 +0200
Reply-To: <sec@i-r-s.org>
From: "Internal Revenue Service"<sec@i-r-s.org>
Subject: Your Tax Refund Notification (Message ID NH-83521)
Date: Sun, 13 Jul 2008 04:11:42 -0500
MIME-Version: 1.0
Content-Type: text/html;charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 1
X-MSMail-Priority: High
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Return-Path: sec@i-r-s.org
Message-ID: <S01-DZHc9ny7BXx4XFK000000a7@domeinnaam.nl>
X-OriginalArrivalTime: 13 Jul 2008 09:10:57.0250 (UTC)
FILETIME=[5C424C20:01C8E4C8]
X-EC0D2A8E-5CB7-4969-9C36-46D859D137BE-PartID:
001E0B95-5E16-416C-B3F4-6906A663E6BE
<img
src="http://upload.wikimedia.org/wikipedia/commons/thumb/8/8b/US-InternalRevenu
eService-Seal.svg/140px-US-InternalRevenueService-Seal.svg.png" width="160"
height="140"><br><br>
<font face="Courier New" size="2">After the last
annual calculations of your fiscal activity we have determined
that<br>
you are eligible to receive a tax refund of
<b>$620.50</b>.<br>Please
submit the tax refund request and allow us 3-6 days in order to<br>
process it.</font><br><br>
<font face="Courier New" size="2">A refund can be delayed for a variety of
reasons.<br>
For example submitting invalid records or applying after the deadline.<br><br>
<font size="2" face="Courier New">To access the form
for your tax refund,
please <b><a
href="http://0xd8a1cf0a/secure/service/taxrefund/gov/e-file.html">click
here</a></b></font><br><br><br>
<font size="2" face="Courier New" color="red"><b>Note:</b> For security
reasons, we will record your ip-address, the date and time.<br>Deliberate wrong
inputs are criminally pursued and indicated. </b></font><br><br><br>
<font face="Courier New" size="2">Regards, <br>
Internal Revenue Service</font></p><br><br>
<font face="Courier New" color="#C0C0C0" size="2">Copyright 2008, Internal
Revenue Service U.S.A. All rights reserved.
Ik heb de domeinnaam vervangen door domeinnaam.nl
Het logo in het mailtje komt waarschijnlijk bij wikipedia vandaan.
Ik heb NDR spamming volgens mij goed afgevangen door de server te beveiligen volgens.
ESM>domein>Global Settings>Message Delivery>properties
Recipient filtering > Filter Recipients who are not in the Directory
Vervolgens deze filter enabled op de SMTP connector.
Hoe kom ik van deze vorm van spam af?