Discussion:
abuse from the anti-abuusers??
(too old to reply)
Mike Scott
2005-05-12 15:56:30 UTC
Permalink
The logs of the sendmail server I run showed the following entries today:

May 12 13:58:42 data sendmail[15813]: j4CCwgft015813:
Cygnus.Mail-Abuse.ORG did not issue MAIL/EXPN/VRFY/ETRN during
connection to MTA
May 12 13:58:43 data sendmail[15814]: j4CCwhj1015814:
Cygnus.Mail-Abuse.ORG [168.61.4.13] did not issue MAIL/EXPN/VRFY/ETRN
during connection to MTA

Turns out Mail-Abuse.ORG is mail-abuse.com is MAPS is now a security
outfit called kelkea, inc.

But I'm puzzled about why they should be probing my mail server -
there's nothing else in the logs to do with them, nor any outbound mail
likely to have triggered any checks.

Anyone else noticed anything like this?
--
Please use the corrected version of the address below for replies.
Replies to the header address will be junked, as will mail from
various domains listed at www.scottsonline.org.uk
Mike Scott Harlow Essex England.(unet -a-t- scottsonline.org.uk)
Robert Moir
2005-05-12 21:53:40 UTC
Permalink
Post by Mike Scott
Cygnus.Mail-Abuse.ORG did not issue MAIL/EXPN/VRFY/ETRN during
connection to MTA
Cygnus.Mail-Abuse.ORG [168.61.4.13] did not issue MAIL/EXPN/VRFY/ETRN
during connection to MTA
Turns out Mail-Abuse.ORG is mail-abuse.com is MAPS is now a security
outfit called kelkea, inc.
But I'm puzzled about why they should be probing my mail server -
there's nothing else in the logs to do with them, nor any outbound
mail likely to have triggered any checks.
Why not ask them?

Maybe they think they've got something that suggests an open relay up your
way?

Maybe they do scans without waiting for a reason these days!
Mark McIntyre
2005-05-12 22:09:09 UTC
Permalink
On Thu, 12 May 2005 15:56:30 GMT, Mike Scott
Post by Mike Scott
But I'm puzzled about why they should be probing my mail server -
Possibly probing to see if you're an open relay, or responding to a
report that spam originated from your domain.
Grahame Cooper
2005-05-13 15:25:27 UTC
Permalink
Post by Mark McIntyre
On Thu, 12 May 2005 15:56:30 GMT, Mike Scott
Post by Mike Scott
But I'm puzzled about why they should be probing my mail server -
Possibly probing to see if you're an open relay, or responding to a
report that spam originated from your domain.
I once followed one of these up with the mail abuse organization that
did the probe. It turned out that they had received a false report about
me from the owner of a machine that was the source of a spam that I had
earlier reported to Spamcop. The prat still didn't close his open relay
though.

Loading...