Community Discussions and Support
Compromised Mercury/32 server/account? or e-mail sent from Admin - How?

Try something like this:

H, "[EHeh][EHeh]LO normie.com*", R, "554 Illegal HELO, connection refused."

/Rolf

 

<p>Try something like this: </p><blockquote><i>H, "[EHeh][EHeh]LO normie.com*", R, "554 Illegal HELO, connection refused."</i></blockquote><p>/Rolf </p><p> </p>

Hello all.

            Here is an interesting problem I am facing right now and affects my "Admin" account for Merc/32.  There have been a fair number of boucning e-mails for which I receive notification to the Admin mailbox (see example below).  In reading the entries, it appears that the message is orginating from the Admin account itself and is trying to send specially-crafted messages to bunches of addresses.  One problem: I am certainly NOT sending them!  As well, my server has no relaying whatsoever turned on.  I'm worried that the server itself (or at least the Admin account) has been compromised in some way I haven't been able to detect.  I am not seeing any unusual access or activity on the firewall nor the IPS and the Admin password has been changed several times in the last month.

Any thoughts?  Ruminations?  Comments?  :-)

If need be, please reply directly to normang at normie.com and I'll post a fix if I get one. 

Thank you in advance. 

-Norman 

 

Message from Admin account:

--------------------------------------------------------------

This is a delivery status message from the electronic mail server at
normie.com. A message appearing to originate from your address
has been delayed during delivery.

Message details:
------------------------------------------------------------------
Originally submitted:      27 Dec 07, 9:16:42
Originator address:        admin@normie.com
Message's subject:         ¾î·Á¿î¶§Àϼö·Ï Èû³»¼¼¿ä! ÀúÀÌÀ²·Î µµ¿òÀ̵ǰڽÀ´Ï´Ù30585
Message's ID:              <A7D650A57295@normie.com>

After 3 hours, the following addresses had delivery problems:

   chphyuns@yahoo.co.kr [Temporary failure - still trying to deliver]
   wnqn21@yahoo.co.kr [Temporary failure - still trying to deliver]
   kbshon47@yahoo.co.kr [Temporary failure - still trying to deliver]
   wodyd557@yahoo.co.kr [Temporary failure - still trying to deliver]
   forfashs2000@yahoo.co.kr [Temporary failure - still trying to deliver]

The server will continue to attempt to deliver your message to any
addresses showing temporary errors. You do not need to take any
further action at this time - this message is for your information
only.

&lt;P&gt;Hello all.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is an interesting problem I am facing right now and affects my &quot;Admin&quot; account for Merc/32.&amp;nbsp; There have been a fair number of boucning e-mails for which I receive notification to the Admin mailbox (see example below).&amp;nbsp; In reading the entries, it appears that the message is orginating from the Admin account itself and is trying to send specially-crafted messages to bunches of addresses.&amp;nbsp; One problem: I am certainly NOT sending them!&amp;nbsp; As well, my server has no relaying whatsoever turned on.&amp;nbsp; I&#039;m worried that the server itself (or at least the Admin account) has been compromised in some way I haven&#039;t been able to detect.&amp;nbsp; I am not seeing any unusual access or activity on the firewall nor the IPS and the Admin password has been changed several times in the last month.&lt;/P&gt; &lt;P&gt;Any thoughts?&amp;nbsp; Ruminations?&amp;nbsp; Comments?&amp;nbsp; :-)&lt;/P&gt; &lt;P&gt;If need be, please reply directly to normang at normie.com and I&#039;ll post a fix if I get one.&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you in advance.&amp;nbsp;&lt;/P&gt; &lt;P&gt;-Norman&amp;nbsp;&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Message from Admin account:&lt;/P&gt; &lt;P&gt;--------------------------------------------------------------&lt;/P&gt; &lt;P&gt;This is a delivery status message from the electronic mail server at normie.com. A message appearing to originate from your address has been delayed during delivery. Message details: ------------------------------------------------------------------ Originally submitted:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27 Dec 07, 9:16:42 Originator address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:admin@normie.com&quot;&gt;&lt;FONT color=#02469b&gt;admin@normie.com&lt;/FONT&gt;&lt;/A&gt; Message&#039;s subject:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &frac34;&icirc;&middot;&Aacute;&iquest;&icirc;&para;&sect;&Agrave;&Iuml;&frac14;&ouml;&middot;&Iuml; &Egrave;&ucirc;&sup3;&raquo;&frac14;&frac14;&iquest;&auml;! &Agrave;&uacute;&Agrave;&Igrave;&Agrave;&sup2;&middot;&Icirc; &micro;&micro;&iquest;&ograve;&Agrave;&Igrave;&micro;&Ccedil;&deg;&Uacute;&frac12;&Agrave;&acute;&Iuml;&acute;&Ugrave;30585 Message&#039;s ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&lt;A href=&quot;mailto:A7D650A57295@normie.com&quot;&gt;&lt;FONT color=#02469b&gt;A7D650A57295@normie.com&lt;/FONT&gt;&lt;/A&gt;&amp;gt; After 3 hours, the following addresses had delivery problems: &amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:chphyuns@yahoo.co.kr&quot;&gt;&lt;FONT color=#02469b&gt;chphyuns@yahoo.co.kr&lt;/FONT&gt;&lt;/A&gt; [Temporary failure - still trying to deliver] &amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:wnqn21@yahoo.co.kr&quot;&gt;&lt;FONT color=#02469b&gt;wnqn21@yahoo.co.kr&lt;/FONT&gt;&lt;/A&gt; [Temporary failure - still trying to deliver] &amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:kbshon47@yahoo.co.kr&quot;&gt;&lt;FONT color=#02469b&gt;kbshon47@yahoo.co.kr&lt;/FONT&gt;&lt;/A&gt; [Temporary failure - still trying to deliver] &amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:wodyd557@yahoo.co.kr&quot;&gt;&lt;FONT color=#02469b&gt;wodyd557@yahoo.co.kr&lt;/FONT&gt;&lt;/A&gt; [Temporary failure - still trying to deliver] &amp;nbsp;&amp;nbsp; &lt;A href=&quot;mailto:forfashs2000@yahoo.co.kr&quot;&gt;&lt;FONT color=#02469b&gt;forfashs2000@yahoo.co.kr&lt;/FONT&gt;&lt;/A&gt; [Temporary failure - still trying to deliver] The server will continue to attempt to deliver your message to any addresses showing temporary errors. You do not need to take any further action at this time - this message is for your information only. &lt;/P&gt;

How have you turned relaying off?  You *must* ensure that the top two checkboxes in MercuryS/Connection control are ticked or else your machine can be used for relaying.  Turn on logging and check your logs.

Also run a scan on the machine and all other network computers.

 

 

&lt;P&gt;How have you turned relaying off?&amp;nbsp; You *must* ensure that the top two checkboxes in MercuryS/Connection control are ticked or else your machine can be used for relaying.&amp;nbsp; Turn on logging and check your logs.&lt;/P&gt; &lt;P&gt;Also run a scan on the machine and all other network computers.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

Check the log files for outgoing SMTP to see if there are any unknown messages sent with your admin account as sender. If not it's probably just someone using your mail address as faked sender in their spam.

/Rolf 

&lt;p&gt;Check the log files for outgoing SMTP to see if there are any unknown messages sent with your admin account as sender. If not it&#039;s probably just someone using your mail address as faked sender in their spam.&lt;/p&gt;&lt;p&gt;/Rolf&amp;nbsp;&lt;/p&gt;

Yup.  Relaying turned off correctly (never had this problem before....) - even had an outside service check it.

Logs don't seem to give much.  I can't seem to correlate the "outbound" messages with a particular connection source.

-Norm

&lt;P&gt;Yup.&amp;nbsp; Relaying turned off correctly (never had this problem before....) - even had an outside service check it.&lt;/P&gt; &lt;P&gt;Logs don&#039;t seem to give much.&amp;nbsp; I can&#039;t seem to correlate the &quot;outbound&quot; messages with a particular connection source.&lt;/P&gt; &lt;P&gt;-Norm&lt;/P&gt;

This is the first time I've had messages with forged headers like this.  It's a little weird that Mercury reports the messages via a failed attempt to deliver....

 

 Is there an entry I can make in the TRAMSFLT.MER that can check if the HELO or EHLO is right?  I'm seeing log entrie like the following:

T 20080101 000733 4748f9ec Connection from 123.111.206.91
T 20080101 000733 4748f9ec HELO normie.com
T 20080101 000733 4748f9ec MAIL From: <admin@normie.com>

If it WAS from me, it wouldn't have my own domain as HELO, no?

-N

&lt;P&gt;This is the first time I&#039;ve had messages with forged headers like this.&amp;nbsp; It&#039;s a little weird that Mercury reports the messages via a failed attempt to deliver....&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;Is there an entry I can make in the TRAMSFLT.MER that can check if the HELO or EHLO is right?&amp;nbsp; I&#039;m seeing log entrie like the following:&lt;/P&gt; &lt;P&gt;T 20080101 000733 4748f9ec Connection from 123.111.206.91 T 20080101 000733 4748f9ec &lt;STRONG&gt;HELO normie.com&lt;/STRONG&gt; T 20080101 000733 4748f9ec MAIL From: &amp;lt;&lt;A href=&quot;mailto:admin@normie.com&quot;&gt;admin@normie.com&lt;/A&gt;&amp;gt;&lt;/P&gt; &lt;P&gt;If it WAS from me, it wouldn&#039;t have my own domain as HELO, no?&lt;/P&gt; &lt;P&gt;-N&lt;/P&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft