Hi folks , i got an issue with an spammer / scammer again i just dont have a clue how he could spoof the right credentials ...
heres a session log , maybe someone can gimme a hint , i tried to decrypt the md5 pass and username but no success ...
i use dns blacklists , not permitting relay from non local , auth users can relay and spamhalter with all options except greylisting
03:30:49.062: Connection from 64.220.121.86, Wed Mar 11 03:30:49 2009<lf>
03:30:49.078: << 220 mail.xxx.org ESMTP server ready.<cr><lf>
03:30:50.250: >> EHLO User<cr><lf>
03:30:50.250: << 250-mail.xxx.org Hello User; ESMTPs are:<cr><lf>250-TIME<cr><lf>
03:30:50.250: << 250-SIZE 0<cr><lf>
03:30:50.265: << 250-8BITMIME<cr><lf>
03:30:50.265: << 250-AUTH CRAM-MD5 LOGIN<cr><lf>
03:30:50.265: << 250-AUTH=LOGIN<cr><lf>
03:30:50.265: << 250 HELP<cr><lf>
03:30:50.859: >> AUTH LOGIN<cr><lf>
03:30:50.859: << 334 VXNlcm5hbWU6<cr><lf>
03:30:50.031: >> dGVzdA==<cr><lf>
03:30:50.031: << 334 UGFzc3dvcmQ6<cr><lf>
03:30:51.218: >> dGVzdA==<cr><lf>
03:30:51.218: << 235 Authentication successful.<cr><lf>
03:30:51.406: >> RSET<cr><lf>
03:30:51.406: << 250 Command processed OK.<cr><lf>
03:30:51.578: >> MAIL FROM:<support@securityi.com><cr><lf>
03:30:51.593: << 250 Sender OK - send RCPTs.<cr><lf>
03:30:51.781: >> RCPT TO:<marco@addr.com><cr><lf>
03:30:51.781: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:51.968: >> RCPT TO:<marco@adhoc.ch><cr><lf>
03:30:51.968: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:52.156: >> RCPT TO:<marco@drco.com><cr><lf>
03:30:52.156: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:52.359: >> RCPT TO:<marco@econophone.ch><cr><lf>
03:30:52.359: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:52.546: >> RCPT TO:<marco@geocities.com><cr><lf>
03:30:52.546: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:52.718: >> RCPT TO:<marco@gmail.com><cr><lf>
03:30:52.718: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:52.906: >> RCPT TO:<marco@gonnapuke.com><cr><lf>
03:30:52.906: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.093: >> RCPT TO:<marco@hgsi.com><cr><lf>
03:30:53.093: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.281: >> RCPT TO:<marco@hicom.net><cr><lf>
03:30:53.281: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.453: >> RCPT TO:<marco@hongkong.com><cr><lf>
03:30:53.453: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.656: >> RCPT TO:<marco@iland.net><cr><lf>
03:30:53.656: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.859: >> RCPT TO:<marco@ime.net><cr><lf>
03:30:53.859: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:53.046: >> RCPT TO:<marco@ina.com><cr><lf>
03:30:53.046: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:54.234: >> RCPT TO:<marco@inforamp.net><cr><lf>
03:30:54.234: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:54.421: >> RCPT TO:<marco@interaccess.net><cr><lf>
03:30:54.421: << 250 Recipient OK - send RCPT or DATA.<cr><lf>
03:30:54.593: >> DATA<cr><lf>
03:30:54.593: << 354 OK, send data, end with CRLF.CRLF<cr><lf>
03:30:54.796: >> From: "Support"<support@securityi.com><cr><lf>
03:30:55.250: >> Subject: Notification from PayPal<cr><lf>
03:30:55.250: >> Date: Tue, 10 Mar 2009 19:30:54 -0700<cr><lf>
03:30:55.250: >> MIME-Version: 1.0<cr><lf>
03:30:55.250: >> Content-Type: text/plain;<cr><lf>
03:30:55.250: >> charset="Windows-1251"<cr><lf>
03:30:55.250: >> Content-Transfer-Encoding: 7bit<cr><lf>
03:30:55.250: >> X-Priority: 3<cr><lf>
03:30:55.250: >> X-MSMail-Priority: Normal<cr><lf>
03:30:55.250: >> X-Mailer: Microsoft Outlook Express 6.00.2600.0000<cr><lf>
03:30:55.250: >> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000<cr><lf>
03:30:55.250: >> <cr><lf>
03:30:55.250: >> Dear PayPal Member,<cr><lf>
03:30:55.250: >> <cr><lf>
03:30:55.250: >> We recently have determined that different computers have logged onto<cr><lf>
03:30:55.250: >> your PayPal account, and multiple password failures were present before<cr><lf>
03:30:55.250: >> the logins. We now need you to re-confirm your account information to us.<cr><lf>
03:30:55.250: >> If this is not completed by March 08, 2009, we will be forced to suspend<cr><lf>
03:30:55.250: >> your account indefinitely, as it may have been used for fraudulent purposes.<cr><lf>
03:30:55.250: >> We thank you for your cooperation in this manner. To confirm your Account<cr><lf>
03:30:55.250: >> records click on the following link:<cr><lf>
03:30:55.250: >> <cr><lf>
03:30:55.250: >> http://www.paypal.com.cgi-bin.webscr.ki2row.es:8085/service/login.htm<cr><lf>
03:30:55.250: >> <cr><lf>
03:30:55.250: >> Thank you for your patience in this matter.<cr><lf>
03:30:55.250: >> PayPal Customer Service.<cr><lf>
03:30:55.250: >> Please do not reply to this e-mail as this is only a notification.<cr><lf>
03:30:55.250: >> <cr><lf>
03:30:55.250: >> 1999-2009 PayPal. All rights reserved.<cr><lf>
03:30:55.250: >> .<cr><lf>
03:30:55.250: << 250 Data received OK.<cr><lf>
03:30:55.437: >> QUIT<cr><lf>
03:30:55.437: << 221 mail.xxx.org Service closing channel.<cr><lf>
03:30:55.437: --- Connection closed normally at Wed Mar 11 03:30:55 2009. ---
<p>Hi folks , i got an issue with an spammer / scammer again i just dont have a clue how he could spoof the right credentials ...</p><p>heres a session log , maybe someone can gimme a hint , i tried to decrypt the md5 pass and username but no success ...</p><p>i use dns blacklists , not permitting relay from non local , auth users can relay and spamhalter with all options except greylisting
</p><p>&nbsp;03:30:49.062: Connection from 64.220.121.86, Wed Mar 11 03:30:49 2009&lt;lf&gt;
03:30:49.078: &lt;&lt; 220 mail.xxx.org ESMTP server ready.&lt;cr&gt;&lt;lf&gt;
03:30:50.250: &gt;&gt; EHLO User&lt;cr&gt;&lt;lf&gt;
03:30:50.250: &lt;&lt; 250-mail.xxx.org Hello User; ESMTPs are:&lt;cr&gt;&lt;lf&gt;250-TIME&lt;cr&gt;&lt;lf&gt;
03:30:50.250: &lt;&lt; 250-SIZE 0&lt;cr&gt;&lt;lf&gt;
03:30:50.265: &lt;&lt; 250-8BITMIME&lt;cr&gt;&lt;lf&gt;
03:30:50.265: &lt;&lt; 250-AUTH CRAM-MD5 LOGIN&lt;cr&gt;&lt;lf&gt;
03:30:50.265: &lt;&lt; 250-AUTH=LOGIN&lt;cr&gt;&lt;lf&gt;
03:30:50.265: &lt;&lt; 250 HELP&lt;cr&gt;&lt;lf&gt;
03:30:50.859: &gt;&gt; AUTH LOGIN&lt;cr&gt;&lt;lf&gt;
03:30:50.859: &lt;&lt; 334 VXNlcm5hbWU6&lt;cr&gt;&lt;lf&gt;
03:30:50.031: &gt;&gt; dGVzdA==&lt;cr&gt;&lt;lf&gt;
03:30:50.031: &lt;&lt; 334 UGFzc3dvcmQ6&lt;cr&gt;&lt;lf&gt;
03:30:51.218: &gt;&gt; dGVzdA==&lt;cr&gt;&lt;lf&gt;
03:30:51.218: &lt;&lt; 235 Authentication successful.&lt;cr&gt;&lt;lf&gt;
03:30:51.406: &gt;&gt; RSET&lt;cr&gt;&lt;lf&gt;
03:30:51.406: &lt;&lt; 250 Command processed OK.&lt;cr&gt;&lt;lf&gt;
03:30:51.578: &gt;&gt; MAIL FROM:&lt;support@securityi.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:51.593: &lt;&lt; 250 Sender OK - send RCPTs.&lt;cr&gt;&lt;lf&gt;
03:30:51.781: &gt;&gt; RCPT TO:&lt;marco@addr.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:51.781: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:51.968: &gt;&gt; RCPT TO:&lt;marco@adhoc.ch&gt;&lt;cr&gt;&lt;lf&gt;
03:30:51.968: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:52.156: &gt;&gt; RCPT TO:&lt;marco@drco.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:52.156: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:52.359: &gt;&gt; RCPT TO:&lt;marco@econophone.ch&gt;&lt;cr&gt;&lt;lf&gt;
03:30:52.359: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:52.546: &gt;&gt; RCPT TO:&lt;marco@geocities.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:52.546: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:52.718: &gt;&gt; RCPT TO:&lt;marco@gmail.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:52.718: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:52.906: &gt;&gt; RCPT TO:&lt;marco@gonnapuke.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:52.906: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.093: &gt;&gt; RCPT TO:&lt;marco@hgsi.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.093: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.281: &gt;&gt; RCPT TO:&lt;marco@hicom.net&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.281: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.453: &gt;&gt; RCPT TO:&lt;marco@hongkong.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.453: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.656: &gt;&gt; RCPT TO:&lt;marco@iland.net&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.656: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.859: &gt;&gt; RCPT TO:&lt;marco@ime.net&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.859: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:53.046: &gt;&gt; RCPT TO:&lt;marco@ina.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:53.046: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:54.234: &gt;&gt; RCPT TO:&lt;marco@inforamp.net&gt;&lt;cr&gt;&lt;lf&gt;
03:30:54.234: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:54.421: &gt;&gt; RCPT TO:&lt;marco@interaccess.net&gt;&lt;cr&gt;&lt;lf&gt;
03:30:54.421: &lt;&lt; 250 Recipient OK - send RCPT or DATA.&lt;cr&gt;&lt;lf&gt;
03:30:54.593: &gt;&gt; DATA&lt;cr&gt;&lt;lf&gt;
03:30:54.593: &lt;&lt; 354 OK, send data, end with CRLF.CRLF&lt;cr&gt;&lt;lf&gt;
03:30:54.796: &gt;&gt; From: "Support"&lt;support@securityi.com&gt;&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Subject: Notification from PayPal&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Date: Tue, 10 Mar 2009 19:30:54 -0700&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; MIME-Version: 1.0&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Content-Type: text/plain;&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &nbsp;&nbsp; &nbsp;charset="Windows-1251"&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Content-Transfer-Encoding: 7bit&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; X-Priority: 3&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; X-MSMail-Priority: Normal&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; X-Mailer: Microsoft Outlook Express 6.00.2600.0000&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Dear PayPal Member,&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; We recently have determined that different computers have logged onto&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; your PayPal account, and multiple password failures were present before&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; the logins. We now need you to re-confirm your account information to us.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; If this is not completed by March 08, 2009, we will be forced to suspend&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; your account indefinitely, as it may have been used for fraudulent purposes.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; We thank you for your cooperation in this manner. To confirm your Account&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; records click on the following link:&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; http://www.paypal.com.cgi-bin.webscr.ki2row.es:8085/service/login.htm&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Thank you for your patience in this matter.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; PayPal Customer Service.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; Please do not reply to this e-mail as this is only a notification.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; &lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; 1999-2009 PayPal. All rights reserved.&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &gt;&gt; .&lt;cr&gt;&lt;lf&gt;
03:30:55.250: &lt;&lt; 250 Data received OK.&lt;cr&gt;&lt;lf&gt;
03:30:55.437: &gt;&gt; QUIT&lt;cr&gt;&lt;lf&gt;
03:30:55.437: &lt;&lt; 221 mail.xxx.org Service closing channel.&lt;cr&gt;&lt;lf&gt;
03:30:55.437: --- Connection closed normally at Wed Mar 11 03:30:55 2009. ---</p>