Community Discussions and Support
Mercury unwanted relaying :(

omg , im sooooooo stupid .... sorry [:$]

looks like a mail account that i made for testing purposes and deleted short time later  . Im very sorry that ive wasted ur time with this [:'(]

Anyway .. thx 4 the help as i now understand much more of the functionality of mercury now [8-|] , if someone of u guys ever visit duesseldorf , Germany i invite u for a Drink

<p>omg , im sooooooo stupid .... sorry [:$]</p><p>looks like a mail account that i made for testing purposes and deleted short time later  . Im very sorry that ive wasted ur time with this [:'(]</p><p>Anyway .. thx 4 the help as i now understand much more of the functionality of mercury now [8-|] , if someone of u guys ever visit duesseldorf , Germany i invite u for a Drink [B] </p>

Hi , i tried to use mercury for my personal mailadress and as an mailer for my private webpages . Unfortunately mercury relays some spam mail although i checked the "do not permit relaying of non local mail " and i also tried the "use strict relaying " :( anyone can tell me whats goin on there ?

as u can see in the picture an non local user send mail to nonlocal recipients and i dunno how he can do that ... :(


 http://img23.imageshack.us/img23/9374/unbenanntkiw.jpg 

<p>Hi , i tried to use mercury for my personal mailadress and as an mailer for my private webpages . Unfortunately mercury relays some spam mail although i checked the "do not permit relaying of non local mail " and i also tried the "use strict relaying " :( anyone can tell me whats goin on there ?</p><p>as u can see in the picture an non local user send mail to nonlocal recipients and i dunno how he can do that ... :( </p><p>  <a href="http://img23.imageshack.us/img23/9374/unbenanntkiw.jpg" mce_href="http://img23.imageshack.us/img23/9374/unbenanntkiw.jpg">http://img23.imageshack.us/img23/9374/unbenanntkiw.jpg  </a></p>

Hi , i tried to use mercury for my personal mailadress and as an

mailer for my private webpages . Unfortunately mercury relays some spam

mail although i checked the "do not permit relaying of non local mail "

and i also tried the "use strict relaying " :( anyone can tell me whats

goin on there ?

as u can see in the picture an non local user send mail to nonlocal recipients and i dunno how he can do that ... :(

Show us the [MercuryS] section of your mercury.ini file.

 

<blockquote><p>Hi , i tried to use mercury for my personal mailadress and as an mailer for my private webpages . Unfortunately mercury relays some spam mail although i checked the "do not permit relaying of non local mail " and i also tried the "use strict relaying " :( anyone can tell me whats goin on there ?</p></blockquote><blockquote>as u can see in the picture an non local user send mail to nonlocal recipients and i dunno how he can do that ... :( </blockquote><p>Show us the [MercuryS] section of your mercury.ini file.</p><p> </p>

Hello Mr.Stephenson and thx for your reply , here it comes  :

[MercuryS]
Debug : 0
HELO : mail.rayes.de
Logfile : C:\Programme\xampp\MERCURYMAIL\Logs\MERCURYS.LOG
Timeout : 20
Relay : 0
Strict_Relay : 1
8BitMime : 1
Interface : 83.136.81.6
Allow_Illegals : 0
SMTP_Authentication : 1
Auth_File : c:\programs\xampp\mercurymail\auth.pwd
Killfile : C:\Programs\xampp\mercurymail\killfile.txt
Session_logging : C:\Programs\xampp\MERCURYMAIL\Logs\sessionlogs
Session_logmode : 1
Compliance_Settings : 432
Maximum_Failed_Rcpts : 3
Max_Relay_Attempts : 2
SSL_Mode : 0
ST_Blacklisting : 288
No_VRFY : 1
SMTP_ConnFlags : 0

<p>Hello Mr.Stephenson and thx for your reply , here it comes  :</p><p>[MercuryS] Debug : 0 HELO : mail.rayes.de Logfile : C:\Programme\xampp\MERCURYMAIL\Logs\MERCURYS.LOG Timeout : 20 Relay : 0 Strict_Relay : 1 8BitMime : 1 Interface : 83.136.81.6 Allow_Illegals : 0 SMTP_Authentication : 1 Auth_File : c:\programs\xampp\mercurymail\auth.pwd Killfile : C:\Programs\xampp\mercurymail\killfile.txt Session_logging : C:\Programs\xampp\MERCURYMAIL\Logs\sessionlogs Session_logmode : 1 Compliance_Settings : 432 Maximum_Failed_Rcpts : 3 Max_Relay_Attempts : 2 SSL_Mode : 0 ST_Blacklisting : 288 No_VRFY : 1 SMTP_ConnFlags : 0 </p>

Relay : 0
Strict_Relay : 1
8BitMime : 1
Interface : 83.136.81.6
Allow_Illegals : 0
SMTP_Authentication : 1
Auth_File : c:\programs\xampp\mercurymail\auth.pwd

Ok, the relaying is turned off and you are allowing relaying via authorized connections.   Now you need to see what you have entered in the "Allow" section under connection control.  If you checked the "Connections may relay through this server" control for any IP address Mercury will allow connections from this IP address to relay no matter what these settings say.

<blockquote><p>Relay : 0 Strict_Relay : 1 8BitMime : 1 Interface : 83.136.81.6 Allow_Illegals : 0 SMTP_Authentication : 1 Auth_File : c:\programs\xampp\mercurymail\auth.pwd</p></blockquote><p>Ok, the relaying is turned off and you are allowing relaying via authorized connections.   Now you need to see what you have entered in the "Allow" section under connection control.  If you checked the "Connections may relay through this server" control for any IP address Mercury will allow connections from this IP address to relay no matter what these settings say. </p>

i dont have any allow entry at connection control ..... it drives me mad that some spammers abuse my mailserver :( , i checked everything i can imagine that would allow that :(

maybe its the MercuryE smtp end to end client ? without it i cant send any mail and i read in some tutorials that i need it ?! isnt the smtp server supposed to send the mail ? 

<p>i dont have any allow entry at connection control ..... it drives me mad that some spammers abuse my mailserver :( , i checked everything i can imagine that would allow that :(</p><p>maybe its the MercuryE smtp end to end client ? without it i cant send any mail and i read in some tutorials that i need it ?! isnt the smtp server supposed to send the mail ?  </p>

i don't have any allow entry at connection control ..... it drives me

mad that some spammers abuse my mail server :( , i checked everything i

can imagine that would allow that :(

If you have no allows under connection conmtrol then I suspect that someone with the authorization username and password is sending via MercuryS

maybe its the MercuryE smtp

end to end client ? without it i cant send any mail and i read in some

tutorials that i need it ?! isnt the smtp server supposed to send the

mail ? 

The SMTP function is split.  MercuryS receives the mail; MercuryE (or MercuryC)  sends the mail.  Mail can also be received in the mail queue directly as a 101 file.   Mail received via the queue is not tested for relaying since it's obviously comming from the local system.
<blockquote><p>i don't have any allow entry at connection control ..... it drives me mad that some spammers abuse my mail server :( , i checked everything i can imagine that would allow that :(</p></blockquote><p>If you have no allows under connection conmtrol then I suspect that someone with the authorization username and password is sending via MercuryS </p><blockquote>maybe its the MercuryE smtp end to end client ? without it i cant send any mail and i read in some tutorials that i need it ?! isnt the smtp server supposed to send the mail ? </blockquote>The SMTP function is split.  MercuryS receives the mail; MercuryE (or MercuryC)  sends the mail.  Mail can also be received in the mail queue directly as a 101 file.   Mail received via the queue is not tested for relaying since it's obviously comming from the local system.

Could you show us the log entries from MercuryS and MercuryE for a spam message that was relayed?

/Rolf 

<p>Could you show us the log entries from MercuryS and MercuryE for a spam message that was relayed? </p><p>/Rolf </p>

in the mercuryS log i dont find any of the sender or recipient email adresses , if u like i can post the log but its about 4,5 MB big ;)

now im examing MercuryE log ... be right back

damn ... doesnt configured an MercuryE log :( but now its done ..... can examine it when it happens again .... what confuses me too is that a local account that dont exists seems to answer the spammer i marked it on that screenshot http://img13.imageshack.us/img13/3341/wootf.jpg

<p>in the mercuryS log i dont find any of the sender or recipient email adresses , if u like i can post the log but its about 4,5 MB big ;)</p><p>now im examing MercuryE log ... be right back </p><p>damn ... doesnt configured an MercuryE log :( but now its done ..... can examine it when it happens again .... what confuses me too is that a local account that dont exists seems to answer the spammer i marked it on that screenshot <a href="http://img13.imageshack.us/img13/3341/wootf.jpg" target="_blank" mce_href="http://img13.imageshack.us/img13/3341/wootf.jpg">http://img13.imageshack.us/img13/3341/wootf.jpg </a> </p>

Looks to me like the server is refusing relay attempts, and that the outgoing messages probably are failed delivery notifications for non-existent local addresses from Mercury postmaster. To avoid getting those, make sure that "Accept mail for invalid local addresses" isn't checked in MercuryS configuration.

/Rolf 

<p>Looks to me like the server is refusing relay attempts, and that the outgoing messages probably are failed delivery notifications for non-existent local addresses from Mercury postmaster. To avoid getting those, make sure that "Accept mail for invalid local addresses" isn't checked in MercuryS configuration.</p><p>/Rolf </p>

it wasnt checked ........ really strange ....

i mean im not dreaming , this guy somehow managed to relay / send messages because the queue  was filled with messages ( that i delayed as far as i saw it )

<p>it wasnt checked ........ really strange .... </p><p>i mean im not dreaming , this guy somehow managed to relay / send messages because the queue  was filled with messages ( that i delayed as far as i saw it ) </p>

Well, the message you marked in the Mercury core window isn't really relayed, it's causing a bounce notification or some other notification from Postmaster. If you still have the message files from the queue directory you can check the contents of the outgoing messages there.

/Rolf 

<p>Well, the message you marked in the Mercury core window isn't really relayed, it's causing a bounce notification or some other notification from Postmaster. If you still have the message files from the queue directory you can check the contents of the outgoing messages there.</p><p>/Rolf </p>

only got the spam messages in the queue , im waiting that he spams again now with mercuryE logged ....

only got the spam messages in the queue , im waiting that he spams again now with mercuryE logged ....

Heres the session log , seems like he managed to authencitate , but just dunno how , got 5or 6 local users and i set all different passwords with 8 characters ... can i see somewhere which users credentials he abused ? :

10:35:11.312: Connection from 187.27.199.251, Mon Apr 06 10:35:11 2009<lf>
10:35:11.328: << 220 mail.rayes.de ESMTP server ready.<cr><lf>
10:35:21.359: >> EHLO User<cr><lf>
10:35:21.359: << 250-mail.rayes.de Hello User; ESMTPs are:<cr><lf>250-TIME<cr><lf>
10:35:21.359: << 250-SIZE 0<cr><lf>
10:35:21.359: << 250-8BITMIME<cr><lf>
10:35:21.359: << 250-AUTH CRAM-MD5 LOGIN<cr><lf>
10:35:21.359: << 250-AUTH=LOGIN<cr><lf>
10:35:21.359: << 250 HELP<cr><lf>
10:35:28.328: >> AUTH LOGIN<cr><lf>
10:35:28.328: << 334 VXNlcm5hbWU6<cr><lf>
10:35:32.765: >> dGVzdA==<cr><lf>
10:35:32.765: << 334 UGFzc3dvcmQ6<cr><lf>
10:35:36.406: >> dGVzdA==<cr><lf>
10:35:36.406: << 235 Authentication successful.<cr><lf>
10:35:41.421: >> RSET<cr><lf>
10:35:41.421: << 250 Command processed OK.<cr><lf>
10:35:52.937: >> MAIL FROM:<onlinejobs@gmail.com><cr><lf>
10:35:52.937: << 250 Sender OK - send RCPTs.<cr><lf>
10:35:57.437: >> RCPT TO:<martyseightysixed@yahoo.com><cr><lf>
10:35:57.437: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:03.265: >> RCPT TO:<martyventura@metrocast.net><cr><lf>
10:36:03.265: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:08.609: >> RCPT TO:<marvelis@sbcglobal.net><cr><lf>
10:36:08.609: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:13.250: >> RCPT TO:<marvincarter63@sbcglobal.net><cr><lf>
10:36:13.250: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:17.250: >> RCPT TO:<mary.suderley@nsc.com><cr><lf>
10:36:17.250: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:27.078: >> RCPT TO:<mary.vaughn@flagstar.com><cr><lf>
10:36:27.078: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:31.421: >> RCPT TO:<mary@artsbeatseats.com><cr><lf>
10:36:31.421: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:35.000: >> RCPT TO:<mary@mleziva.com><cr><lf>
10:36:35.000: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:39.281: >> RCPT TO:<mary@schmolkelaw.com><cr><lf>
10:36:39.281: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:44.062: >> RCPT TO:<mary_bahnf@yahoo.com><cr><lf>
10:36:44.062: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
10:36:49.500: >> DATA<cr><lf>
10:36:49.500: << 354 OK, send data, end with CRLF.CRLF<cr><lf>
10:36:55.062: >> Reply-To: <anthonyvassallo02@hotmail.com><cr><lf>
10:36:55.093: >> From: "GET PAID WITHOUT STRESS"<onlinejobs@gmail.com><cr><lf>
10:36:55.093: >> Subject: EARN EXTRA CASH WITHOUT QUITTING YOUR PRESENT JOB<cr><lf>
10:36:55.093: >> Date: Mon, 6 Apr 2009 09:36:12 -0700<cr><lf>
10:36:55.093: >> MIME-Version: 1.0<cr><lf>
10:36:55.093: >> Content-Type: text/plain;<cr><lf>
10:36:55.093: >>     charset="Windows-1251"<cr><lf>
10:36:55.093: >> Content-Transfer-Encoding: 7bit<cr><lf>
10:36:55.093: >> X-Priority: 3<cr><lf>
10:36:55.093: >> X-MSMail-Priority: Normal<cr><lf>
10:36:55.093: >> X-Mailer: Microsoft Outlook Express 6.00.2800.1081<cr><lf>
10:36:55.093: >> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081<cr><lf>
10:36:55.093: >> <cr><lf>
10:36:55.093: >> ****PLS READ CAREFULLY & REPLY BELOW IF INTERESTED IN GETTING PAID****<cr><lf>
10:36:55.093: >>  <cr><lf>
10:36:55.093: >> Pls Pardon me for not having the pleasure of knowing your mindset before making you this offer. I write to solicit your services by offering you a lucrative job in which you would be earning alot of extra cash without quitting your present job or having any problems with your employers/ employees. <cr><lf>
10:36:55.093: >> <cr><lf>
10:36:55.093: >> I work with an independent group of investors in the UK and We supply metallic materials to some clients in the US. These Clients pay for the materials via BANK WIRE TRANSFERS, but we do not have a payment receiving personnel to help us receive the funds, so we approach you to help us receive these payments in your Account.<cr><lf>
10:36:55.093: >> <cr><lf>
10:36:57.046: >> This is a 100% legit job, we deal directly with the banks so you have nothing to worry about its legitimacy. All you have to do is simply to go withdraw the funds after they have been wired to you, take a 10% as your commission and send the remaining to our Associates. You require no fee to get started, infact you can withdraw all funds in your Account so you wont think we need your money or anything contrary to our terms and conditions. All we require is where our clients can wire funds to. Below is the list of Banks available for wire transfer, so if you have an account with any of the below banks, then indicate precisely the account you have and reply with your name and phone number.<cr><lf>
10:36:59.953: >>  <cr><lf>
10:36:59.953: >> PLS INDICATE CLEARLY IF YOU HAVE AN ACCOUNT WITH ANY OF THESE BANKS<cr><lf>
10:36:59.953: >> *******************************************************************************************<cr><lf>
10:36:59.953: >> 1. Any Credit Card (not a debit card)<cr><lf>
10:36:59.953: >> 2. Any Business/ Company Account<cr><lf>
10:36:59.953: >> 3. Wellsfargo Bank<cr><lf>
10:36:59.953: >> 4. Bank of the West<cr><lf>
10:36:59.953: >> 5. Compass Bank<cr><lf>
10:36:59.953: >> 6. Trustmark National Bank<cr><lf>
10:36:59.953: >> 7. Hancock Bank<cr><lf>
10:36:59.953: >> 8. First Citizens Bank<cr><lf>
10:36:59.953: >> 9. Colonial Bank<cr><lf>
10:36:59.953: >> 10. US Bank<cr><lf>
10:36:59.953: >> 11. Arvest bank<cr><lf>
10:36:59.953: >> 12. City Bank<cr><lf>
10:36:59.953: >> 13. Bank of America<cr><lf>
10:36:59.953: >>  <cr><lf>
10:36:59.953: >>     If you have any of these accounts, then reply with your Name, phone number and the type of account you have, so we can contact you and give you commencement modalities.<cr><lf>
10:36:59.953: >>  <cr><lf>
10:36:59.953: >> Best regards<cr><lf>
10:36:59.953: >> Mr. Anthony Vassallo (recruitment officer)<cr><lf>
10:36:59.953: >> anthonyvassallo01@gmail.com<cr><lf>
10:36:59.953: >> .<cr><lf>
10:36:59.953: << 250 Data received OK.<cr><lf>
10:37:02.453: >> QUIT<cr><lf>
10:37:02.453: << 221 mail.rayes.de Service closing channel.<cr><lf>
10:37:02.453: --- Connection closed normally at Mon Apr 06 10:37:02 2009. -

&lt;p&gt;Heres the session log , seems like he managed to authencitate , but just dunno how , got 5or 6 local users and i set all different passwords with 8 characters ... can i see somewhere which users credentials he abused ? :&lt;/p&gt;&lt;p&gt;10:35:11.312: Connection from 187.27.199.251, Mon Apr 06 10:35:11 2009&amp;lt;lf&amp;gt; 10:35:11.328: &amp;lt;&amp;lt; 220 mail.rayes.de ESMTP server ready.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;gt;&amp;gt; EHLO User&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-mail.rayes.de Hello User; ESMTPs are:&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;250-TIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-SIZE 0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-8BITMIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-AUTH CRAM-MD5 LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-AUTH=LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250 HELP&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:28.328: &amp;gt;&amp;gt; AUTH LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:28.328: &amp;lt;&amp;lt; 334 VXNlcm5hbWU6&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:32.765: &amp;gt;&amp;gt; dGVzdA==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:32.765: &amp;lt;&amp;lt; 334 UGFzc3dvcmQ6&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:36.406: &amp;gt;&amp;gt; dGVzdA==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:36.406: &amp;lt;&amp;lt; 235 Authentication successful.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:41.421: &amp;gt;&amp;gt; RSET&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:41.421: &amp;lt;&amp;lt; 250 Command processed OK.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:52.937: &amp;gt;&amp;gt; MAIL FROM:&amp;lt;onlinejobs@gmail.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:52.937: &amp;lt;&amp;lt; 250 Sender OK - send RCPTs.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:57.437: &amp;gt;&amp;gt; RCPT TO:&amp;lt;martyseightysixed@yahoo.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:57.437: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:03.265: &amp;gt;&amp;gt; RCPT TO:&amp;lt;martyventura@metrocast.net&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:03.265: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:08.609: &amp;gt;&amp;gt; RCPT TO:&amp;lt;marvelis@sbcglobal.net&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:08.609: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:13.250: &amp;gt;&amp;gt; RCPT TO:&amp;lt;marvincarter63@sbcglobal.net&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:13.250: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:17.250: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary.suderley@nsc.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:17.250: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:27.078: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary.vaughn@flagstar.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:27.078: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:31.421: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary@artsbeatseats.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:31.421: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:35.000: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary@mleziva.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:35.000: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:39.281: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary@schmolkelaw.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:39.281: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:44.062: &amp;gt;&amp;gt; RCPT TO:&amp;lt;mary_bahnf@yahoo.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:44.062: &amp;lt;&amp;lt; 250 Recipient OK - send RCPT or DATA.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:49.500: &amp;gt;&amp;gt; DATA&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:49.500: &amp;lt;&amp;lt; 354 OK, send data, end with CRLF.CRLF&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.062: &amp;gt;&amp;gt; Reply-To: &amp;lt;anthonyvassallo02@hotmail.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; From: &quot;GET PAID WITHOUT STRESS&quot;&amp;lt;onlinejobs@gmail.com&amp;gt;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; Subject: EARN EXTRA CASH WITHOUT QUITTING YOUR PRESENT JOB&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; Date: Mon, 6 Apr 2009 09:36:12 -0700&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; MIME-Version: 1.0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; Content-Type: text/plain;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; charset=&quot;Windows-1251&quot;&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; Content-Transfer-Encoding: 7bit&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; X-Priority: 3&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; X-MSMail-Priority: Normal&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; X-Mailer: Microsoft Outlook Express 6.00.2800.1081&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; ****PLS READ CAREFULLY &amp;amp; REPLY BELOW IF INTERESTED IN GETTING PAID****&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt;&amp;nbsp; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; Pls Pardon me for not having the pleasure of knowing your mindset before making you this offer. I write to solicit your services by offering you a lucrative job in which you would be earning alot of extra cash without quitting your present job or having any problems with your employers/ employees. &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; I work with an independent group of investors in the UK and We supply metallic materials to some clients in the US. These Clients pay for the materials via BANK WIRE TRANSFERS, but we do not have a payment receiving personnel to help us receive the funds, so we approach you to help us receive these payments in your Account.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:55.093: &amp;gt;&amp;gt; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:57.046: &amp;gt;&amp;gt; This is a 100% legit job, we deal directly with the banks so you have nothing to worry about its legitimacy. All you have to do is simply to go withdraw the funds after they have been wired to you, take a 10% as your commission and send the remaining to our Associates. You require no fee to get started, infact you can withdraw all funds in your Account so you wont think we need your money or anything contrary to our terms and conditions. All we require is where our clients can wire funds to. Below is the list of Banks available for wire transfer, so if you have an account with any of the below banks, then indicate precisely the account you have and reply with your name and phone number.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt;&amp;nbsp; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; PLS INDICATE CLEARLY IF YOU HAVE AN ACCOUNT WITH ANY OF THESE BANKS&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; *******************************************************************************************&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 1. Any Credit Card (not a debit card)&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 2. Any Business/ Company Account&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 3. Wellsfargo Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 4. Bank of the West&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 5. Compass Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 6. Trustmark National Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 7. Hancock Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 8. First Citizens Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 9. Colonial Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 10. US Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 11. Arvest bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 12. City Bank&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; 13. Bank of America&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt;&amp;nbsp; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you have any of these accounts, then reply with your Name, phone number and the type of account you have, so we can contact you and give you commencement modalities.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt;&amp;nbsp; &amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; Best regards&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; Mr. Anthony Vassallo (recruitment officer)&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; anthonyvassallo01@gmail.com&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;gt;&amp;gt; .&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:36:59.953: &amp;lt;&amp;lt; 250 Data received OK.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:37:02.453: &amp;gt;&amp;gt; QUIT&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:37:02.453: &amp;lt;&amp;lt; 221 mail.rayes.de Service closing channel.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:37:02.453: --- Connection closed normally at Mon Apr 06 10:37:02 2009. - &lt;/p&gt;

[quote user="Sammy123"]Heres the session log , seems like he managed to authencitate , but just dunno how , got 5or 6 local users and i set all different passwords with 8 characters ... can i see somewhere which users credentials he abused ? [/quote]

test

It's all base64 encoded in the log, so please change it now!  And it's never a good idea to have the password the same as the username.

 

[quote user=&quot;Sammy123&quot;]Heres the session log , seems like he managed to authencitate , but just dunno how , got 5or 6 local users and i set all different passwords with 8 characters ... can i see somewhere which users credentials he abused ? [/quote] &lt;P&gt;test&lt;/P&gt; &lt;P&gt;It&#039;s all base64 encoded in the log, so please change it now!&amp;nbsp; And it&#039;s never a good idea to have the password the same as the username.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

Heres the session log , seems like he managed to authenticate , but

just dunno how , got 5or 6 local users and i set all different

passwords with 8 characters ... can i see somewhere which users

credentials he abused ? :

You need to use some sort of base64 decoder to translate the strings.  I used CubedLabs Encode/Decode for this. It's pretty easy to guess this one since the username and password are the same and the user "test" is quite common.

10:35:11.312: Connection from 187.27.199.251, Mon Apr 06 10:35:11 2009<lf>
10:35:11.328: << 220 mail.rayes.de ESMTP server ready.<cr><lf>
10:35:21.359: >> EHLO User<cr><lf>
10:35:21.359: << 250-mail.rayes.de Hello User; ESMTPs are:<cr><lf>250-TIME<cr><lf>
10:35:21.359: << 250-SIZE 0<cr><lf>
10:35:21.359: << 250-8BITMIME<cr><lf>
10:35:21.359: << 250-AUTH CRAM-MD5 LOGIN<cr><lf>
10:35:21.359: << 250-AUTH=LOGIN<cr><lf>
10:35:21.359: << 250 HELP<cr><lf>
10:35:28.328: >> AUTH LOGIN<cr><lf>
10:35:28.328: << 334 VXNlcm5hbWU6<cr><lf>
VXNlcm5hbWU6 = Username:
10:35:32.765: >> dGVzdA==<cr><lf>
dGVzdA== = test
10:35:32.765: << 334 UGFzc3dvcmQ6<cr><lf>
UGFzc3dvcmQ6 = Password:
10:35:36.406: >> dGVzdA==<cr><lf>
dGVzdA== = test
10:35:36.406: << 235 Authentication successful.<cr><lf>
 
&lt;blockquote&gt;&lt;p&gt;Heres the session log , seems like he managed to authenticate , but just dunno how , got 5or 6 local users and i set all different passwords with 8 characters ... can i see somewhere which users credentials he abused ? :&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;You need to use some sort of base64 decoder to translate the strings.&amp;nbsp; I used CubedLabs Encode/Decode for this. It&#039;s pretty easy to guess this one since the username and password are the same and the user &quot;test&quot; is quite common. &lt;/p&gt;&lt;blockquote&gt;10:35:11.312: Connection from 187.27.199.251, Mon Apr 06 10:35:11 2009&amp;lt;lf&amp;gt; 10:35:11.328: &amp;lt;&amp;lt; 220 mail.rayes.de ESMTP server ready.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;gt;&amp;gt; EHLO User&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-mail.rayes.de Hello User; ESMTPs are:&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;250-TIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-SIZE 0&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-8BITMIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-AUTH CRAM-MD5 LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250-AUTH=LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:21.359: &amp;lt;&amp;lt; 250 HELP&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:28.328: &amp;gt;&amp;gt; AUTH LOGIN&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt; 10:35:28.328: &amp;lt;&amp;lt; 334 VXNlcm5hbWU6&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/blockquote&gt;VXNlcm5hbWU6 = Username: &lt;blockquote&gt;10:35:32.765: &amp;gt;&amp;gt; dGVzdA==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/blockquote&gt;dGVzdA== = test &lt;blockquote&gt;10:35:32.765: &amp;lt;&amp;lt; 334 UGFzc3dvcmQ6&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/blockquote&gt;UGFzc3dvcmQ6 = Password: &lt;blockquote&gt;10:35:36.406: &amp;gt;&amp;gt; dGVzdA==&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/blockquote&gt;dGVzdA== = test &lt;blockquote&gt;10:35:36.406: &amp;lt;&amp;lt; 235 Authentication successful.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;&lt;/blockquote&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft