Overclockers Australia Forums
OCAU News - Wiki - QuickLinks - Pix - Sponsors  

Go Back   Overclockers Australia Forums > Specific Hardware Topics > Networking, Telephony & Internet

Notices


Sign up for a free OCAU account and this ad will go away!
Search our forums with Google:
Reply
 
Thread Tools
Old 24th November 2007, 12:02 AM   #1
fref99 Thread Starter
Member
 
fref99's Avatar
 
Join Date: Aug 2002
Location: Switzerland
Posts: 819
Default wierd "spam"

Hi All,

Maybe someone can explain what's the point of the e-mail listed below. It's not coming from my router or my server, the IP address the emails are coming from are not even my ISP.

Code:
Received: from brnt ([83.76.143.246]:34455) 
 by planet-ian.com with [XMail 1.24 ESMTP Server] 
 id <S29F75> for <i.dobson@planet-ian.com> from <i.dobson@planet-ian.com>; 
 Fri, 23 Nov 2007 12:38:33 +0100 
From: <i.dobson@planet-ian.com> 
To: i.dobson@planet-ian.com 
Subject: Alert Message!!!  
 
Dear User 
Your router has detected and protected you against an attempt to gain access to your network.  This may have been an attempted hacker intrusion, or perhaps just your Internet Service Provider doing routine network maintenance. 
Most of these network probes are nothing to be worried about - these types of random probes should NOT be reported, but you may want to report repeated intrusions attempts.  Save this email for comparison with future alert messages. 
Your router Alert Information 
 
Time: 11/23/2007, 12:38:38 
Message: Smurf 
Source: 169.254.255.255 
Destination:169.254.53.156, Type:3, Code:3 (from PPPoE1 Outbound) 
  
 
Visit the UXN Combat Spam web site to get more detailed information about the intruder - http://combat.uxn.com/ 
1. Type the intruder's IP address into the IP WHOIS search engine 
2. Click the Query Button 
3. Detailed network and administration information will be displayed
For information planet-ian.com is my domain, xmail is the mail sever sw I'm running under linux. The server sits behind a NAT/Firewall router. Running spamassassin (spamd/c) on the server.

I've now had 3,000 of these emails in the last 24hours, no worries spamassassin blocks them. It's just a pain in the butt.

I'll bang off an email the the ISP for the IP range thats "bothering" me but I can't see the point of this and the other 2,999 emails.

Regards
FREF99
__________________
Walking on water and writing software to specification is easy, if they are frozen

home of the mobile webcam - OCAU thread
fref99 is offline   Reply With Quote

Join OCAU to remove this ad!
Old 24th November 2007, 8:32 AM   #2
Sprinker
Member
 
Sprinker's Avatar
 
Join Date: Aug 2006
Location: Adelaide, South Australia
Posts: 177
Default

Looks very dodgy whatever it is. It's trying to entice you to go to a website as well, steer clear. Are all the messages coming from the same IP? If so, I know Postfix under Linux has a way of blacklisting IP's. but I don't know about your software. Blocking the IP might be the best solution because there seems to be no "fix" for stopping these emails from being sent from you. The email is BS, block the IP and care no more.

If you want you can drop an email to your ISP explaining the "spam", but I don't know how much they will do about it.
__________________
Apple MacBook Pro, i7 2Ghz, 8GB RAM, 500GB HDD, OS X 10.7 - Lion Goodness
Apple iPad, Gen 3 - 32GB WiFi + 3.5G, Black

Carbonite - i7 3770, 16GB DDR3 1600, Gigabyte GTX 560 - Ubuntu 12.04 x86_64
Sprinker is offline   Reply With Quote
Old 24th November 2007, 11:21 AM   #3
andrewbt
Member
 
Join Date: Jan 2005
Location: Canberra
Posts: 238
Default

you didnt own a bit of SMC kit and then sold it/gave it to someone? :P
andrewbt is offline   Reply With Quote
Old 24th November 2007, 2:08 PM   #4
mpot
<blank>
 
mpot's Avatar
 
Join Date: Jun 2001
Location: Perth, WA
Posts: 5,345
Default

Quote:
Originally Posted by fref99 View Post
Source: 169.254.255.255
Destination:169.254.53.156, Type:3, Code:3 (from PPPoE1 Outbound)
All IPs in the 169.254.0.0/16 subnet are not valid internet IPs - that's a subnet used by Microsoft for NICs that fail to get an IP via DHCP (as per RFC 3330).

Cheers,
Martin.
__________________
[ photography blog | redbubble | flickr ]
mpot is offline   Reply With Quote
Old 24th November 2007, 6:11 PM   #5
fref99 Thread Starter
Member
 
fref99's Avatar
 
Join Date: Aug 2002
Location: Switzerland
Posts: 819
Default

Hi andrewbt when I'm finished with a router no one will want it (mod it until it breaks).

All the emails are comming from a ADSL user so the IP address changes every so often, but it's always from the same system.

I've already sent a mail off to the ISP and blocked the subnet range that this system lives in.

Regards
FREF99
__________________
Walking on water and writing software to specification is easy, if they are frozen

home of the mobile webcam - OCAU thread
fref99 is offline   Reply With Quote
Old 25th November 2007, 6:46 PM   #6
fref99 Thread Starter
Member
 
fref99's Avatar
 
Join Date: Aug 2002
Location: Switzerland
Posts: 819
Default

Hi All,

The "attacks" have stopped now. Almost 5,000 emails (or attempts) within 1 1/2 days.

After I blocked the IP range from this idiot it started to attempt to connect every 10 seconds, but at the mail server was blocking the emails at source rather than sending them to spamassassin it cut down the CPU load ito almost 0, which was OK for me.

Regards
FREF99

ps.I would still love to know what the fuck is this.
__________________
Walking on water and writing software to specification is easy, if they are frozen

home of the mobile webcam - OCAU thread
fref99 is offline   Reply With Quote
Reply

Bookmarks

Sign up for a free OCAU account and this ad will go away!

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time now is 8:24 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. -
OCAU is not responsible for the content of individual messages posted by others.
Other content copyright Overclockers Australia.
OCAU is hosted by Internode!