Hello all.
Here is an interesting problem I am facing right now and affects my "Admin" account for Merc/32. There have been a fair number of boucning e-mails for which I receive notification to the Admin mailbox (see example below). In reading the entries, it appears that the message is orginating from the Admin account itself and is trying to send specially-crafted messages to bunches of addresses. One problem: I am certainly NOT sending them! As well, my server has no relaying whatsoever turned on. I'm worried that the server itself (or at least the Admin account) has been compromised in some way I haven't been able to detect. I am not seeing any unusual access or activity on the firewall nor the IPS and the Admin password has been changed several times in the last month.
Any thoughts? Ruminations? Comments? :-)
If need be, please reply directly to normang at normie.com and I'll post a fix if I get one.
Thank you in advance.
-Norman
Message from Admin account:
--------------------------------------------------------------
This is a delivery status message from the electronic mail server at
normie.com. A message appearing to originate from your address
has been delayed during delivery.
Message details:
------------------------------------------------------------------
Originally submitted: 27 Dec 07, 9:16:42
Originator address: admin@normie.com
Message's subject: ¾î·Á¿î¶§Àϼö·Ï Èû³»¼¼¿ä! ÀúÀÌÀ²·Î µµ¿òÀ̵ǰڽÀ´Ï´Ù30585
Message's ID: <A7D650A57295@normie.com>
After 3 hours, the following addresses had delivery problems:
chphyuns@yahoo.co.kr [Temporary failure - still trying to deliver]
wnqn21@yahoo.co.kr [Temporary failure - still trying to deliver]
kbshon47@yahoo.co.kr [Temporary failure - still trying to deliver]
wodyd557@yahoo.co.kr [Temporary failure - still trying to deliver]
forfashs2000@yahoo.co.kr [Temporary failure - still trying to deliver]
The server will continue to attempt to deliver your message to any
addresses showing temporary errors. You do not need to take any
further action at this time - this message is for your information
only.
<P>Hello all.</P>
<P>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Here is an interesting problem I am facing right now and affects my "Admin" account for Merc/32.&nbsp; There have been a fair number of boucning e-mails for which I receive notification to the Admin mailbox (see example below).&nbsp; In reading the entries, it appears that the message is orginating from the Admin account itself and is trying to send specially-crafted messages to bunches of addresses.&nbsp; One problem: I am certainly NOT sending them!&nbsp; As well, my server has no relaying whatsoever turned on.&nbsp; I'm worried that the server itself (or at least the Admin account) has been compromised in some way I haven't been able to detect.&nbsp; I am not seeing any unusual access or activity on the firewall nor the IPS and the Admin password has been changed several times in the last month.</P>
<P>Any thoughts?&nbsp; Ruminations?&nbsp; Comments?&nbsp; :-)</P>
<P>If need be, please reply directly to normang at normie.com and I'll post a fix if I get one.&nbsp;</P>
<P>Thank you in advance.&nbsp;</P>
<P>-Norman&nbsp;</P>
<P mce_keep="true">&nbsp;</P>
<P>Message from Admin account:</P>
<P>--------------------------------------------------------------</P>
<P>This is a delivery status message from the electronic mail server at
normie.com. A message appearing to originate from your address
has been delayed during delivery.
Message details:
------------------------------------------------------------------
Originally submitted:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 27 Dec 07, 9:16:42
Originator address:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <A href="mailto:admin@normie.com"><FONT color=#02469b>admin@normie.com</FONT></A>
Message's subject:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ¾î·Á¿î¶§Àϼö·Ï Èû³»¼¼¿ä! ÀúÀÌÀ²·Î µµ¿òÀ̵ǰڽÀ´Ï´Ù30585
Message's ID:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;<A href="mailto:A7D650A57295@normie.com"><FONT color=#02469b>A7D650A57295@normie.com</FONT></A>&gt;
After 3 hours, the following addresses had delivery problems:
&nbsp;&nbsp; <A href="mailto:chphyuns@yahoo.co.kr"><FONT color=#02469b>chphyuns@yahoo.co.kr</FONT></A> [Temporary failure - still trying to deliver]
&nbsp;&nbsp; <A href="mailto:wnqn21@yahoo.co.kr"><FONT color=#02469b>wnqn21@yahoo.co.kr</FONT></A> [Temporary failure - still trying to deliver]
&nbsp;&nbsp; <A href="mailto:kbshon47@yahoo.co.kr"><FONT color=#02469b>kbshon47@yahoo.co.kr</FONT></A> [Temporary failure - still trying to deliver]
&nbsp;&nbsp; <A href="mailto:wodyd557@yahoo.co.kr"><FONT color=#02469b>wodyd557@yahoo.co.kr</FONT></A> [Temporary failure - still trying to deliver]
&nbsp;&nbsp; <A href="mailto:forfashs2000@yahoo.co.kr"><FONT color=#02469b>forfashs2000@yahoo.co.kr</FONT></A> [Temporary failure - still trying to deliver]
The server will continue to attempt to deliver your message to any
addresses showing temporary errors. You do not need to take any
further action at this time - this message is for your information
only.
</P>