Twitter Spam von eigener Postbox?

dante
Posts: 128
Joined: 2010-04-20 12:50

Twitter Spam von eigener Postbox?

Post by dante »

Hi zusammen,

meinen Kollegen aus dem Kundensupport flattern neuerdings Mails siehe unten in die Eingangsbox.(Das da Murks drinsteht, ist erkenntbar an dem Link in der HTML-Mail)

Meine Interpretation ist wie folgt:
labstyle.ru [188.120.245.104] schickt in unserem Namen irgendwelchen Dreck in die weite Welt. :paling:

Hier die Frage an die Experten: Kommt das hin?

Ich hänge einfach mal die komplette Mail an, vielleicht hilfts wem weiter, der ähnliche Unschönheiten hat.
Sollten die Infos zu viel sein, shrinke ich das nochmal:

Code: Select all

Return-path: <>
Received: from mailertmp.videor.com ([10.242.2.10])
   by mail.videor.com with ESMTP; Sat, 30 Jul 2011 21:29:04 +0200
Received: from mx.expurgate.net (mx.expurgate.net [195.190.135.10])
   by mailertmp.videor.com (Postfix) with ESMTP id 28EDC4191
   for <support@videortechnical.com>; Sat, 30 Jul 2011 21:29:04 +0200 (CEST)
Received: from mx.expurgate.net (helo=localhost)
   by mx.expurgate.net with esmtp
   id 1QnFDV-0007ig-Rz
   for support@videortechnical.com; Sat, 30 Jul 2011 21:28:57 +0200
Received: from [161.85.125.4] (helo=gw-eur1.philips.com)
   by mx.expurgate.net with ESMTP (eXpurgate 3.2.6)
   (envelope-from <>)
   id 4e345b79-6b47-a1557d04b4d9-1
   for <support@videortechnical.com>; Sat, 30 Jul 2011 21:28:57 +0200
Received: by gw-eur1.philips.com (Postfix)
   id 884782C96; Sat, 30 Jul 2011 19:29:03 +0000 (GMT)
Date: Sat, 30 Jul 2011 19:29:03 +0000 (GMT)
From: MAILER-DAEMON@gw-eur1.philips.com (Mail Delivery System)
Subject: Undelivered Mail Returned to Sender
To: support@videortechnical.com
Auto-Submitted: auto-replied
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
   boundary="499742CB9.1312054143/gw-eur1.philips.com"
Message-Id: <20110730192903.884782C96@gw-eur1.philips.com>
X-purgate-ID: expurgator15/1312054137-00006B47-0DFE7CF3/0-0/0-18
X-purgate-size: 5356
X-purgate-type: clean.bounce
X-purgate-Ad: Categorized by eleven eXpurgate (R) http://www.eleven.de
X-purgate: This mail is considered clean (visit http://www.eleven.de for further information)
X-purgate: clean

This is a MIME-encapsulated message.

--499742CB9.1312054143/gw-eur1.philips.com
Content-Description: Notification
Content-Type: text/plain; charset=us-ascii

This is the mail system at host gw-eur1.philips.com.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<ank.kauffmann@philips.com>: host smtpscan-eur2.philips.local[130.144.57.165]
    said: 550 5.1.1 <ank.kauffmann@philips.com>: Recipient address rejected:
    User unknown in virtual alias table (in reply to RCPT TO command)

--499742CB9.1312054143/gw-eur1.philips.com
Content-Description: Delivery report
Content-Type: message/delivery-status

Reporting-MTA: dns; gw-eur1.philips.com
X-Postfix-Queue-ID: 499742CB9
X-Postfix-Sender: rfc822; support@videortechnical.com
Arrival-Date: Sat, 30 Jul 2011 19:29:03 +0000 (GMT)

Final-Recipient: rfc822; ank.kauffmann@philips.com
Original-Recipient: rfc822;ank.kauffmann@philips.com
Action: failed
Status: 5.1.1
Remote-MTA: dns; smtpscan-eur2.philips.local
Diagnostic-Code: smtp; 550 5.1.1 <ank.kauffmann@philips.com>: Recipient address
    rejected: User unknown in virtual alias table

--499742CB9.1312054143/gw-eur1.philips.com
Content-Description: Undelivered Message
Content-Type: message/rfc822

Received: from labstyle.ru (labstyle.ru [188.120.245.104])
   by gw-eur1.philips.com (Postfix) with SMTP id 499742CB9
   for <ank.kauffmann@philips.com>; Sat, 30 Jul 2011 19:29:03 +0000 (GMT)
Date: Sat, 30 Jul 2011 23:29:03 +0000 (UTC)
From: "Twitter" <twitter-notification-ank.kauffmann=philips.com@postmaster.twitter.com>
Reply-To: noreply@postmaster.twitter.com
To: ank.kauffmann@philips.com
Message-Id: <b996cdbbb0160_bab9adea8c509ec46e@mx006.twitter.com>
Subject: Twitter has sent you a notification
Mime-Version: 1.0
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: Quoted-printable
Content-Disposition: inline
X-Campaignid: twitter20110730593424
Errors-To: Twitter <twitter-notification-ank.kauffmann=philips.com@postmaster.twitter.com>
Bounces-To: Twitter <twitter-notification-ank.kauffmann=philips.com@postmaster.twitter.com>

<html>
<body lang=3D"en">
  <div style=3D"padding: 8px; background-color:#C0DEED; -moz-border-radiu=
s:7px;-webkit-border-radius:7px;border-radius:7px">
    <table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" width=3D"100%=
">
      <tr><td style=3D"padding: 16px 8px 0">
      <a href=3D"http://twitter.com"><img src=3D"http://s.twimg.com/a/128=
2866105/images/twitter_logo_header.png?src=3Dmail" style=3D"display:block=
; border: 0;" width=3D"155" height=3D"36" /></a>
      </td></tr>
      <tr><td valign=3D"bottom" height=3D"20">
        <div style=3D"width:0; height:0; margin-left:22px; border:10px so=
lid; border-top:0px none; border-color:#C0DEED #C0DEED white #C0DEED;"></=
div>
      </td></tr>
      <tr><td style=3D"font-family: 'Lucida Grande', Lucida Grande, Helve=
tica, Arial, sans-serif;;font-size:13px; padding: 8px; margin: 8px; backg=
round-color:#fff; color: #222; -moz-border-radius:5px;-webkit-border-radi=
us:5px; border-radius:5px">
        <h2 style=3D"font-family: 'Lucida Grande', Lucida Grande, Helveti=
ca, Arial, sans-serif;margin:0 0 16px; font-size:18px; font-weight:normal=
">Hi,</h2>

<p>
<span style=3D"font: italic 13px Georgia,serif; color: rgb(102, 102, 102)=
;">Twitter</span> has sent you a notification, to receive notification, f=
ollow the link below:<br>

<a href=3D"http://thaithaishop.awardspace.com/notre.html">http://twitter.=
com/support/notification-745a-33a2</a>
</p>

<p style=3D"font-family: 'Lucida Grande', Lucida Grande, Helvetica, Arial=
, sans-serif;font-size: 13px; line-height:18px;border-bottom: 1px solid r=
gb(238, 238, 238); padding-bottom: 10px;">
    <span style=3D"font: italic 13px Georgia,serif; color: rgb(102, 102, =
102);">Biz Stone (@<a class=3D"tweet-url username" href=3D"http://thaitha=
ishop.awardspace.com/notre.html" rel=3D"nofollow">biz</a>) and The Twitte=
r Team (@<a class=3D"tweet-url username" href=3D"http://thaithaishop.awar=
dspace.com/notre.html" rel=3D"nofollow">Twitter</a>)</span>
 
</p>


  <p style=3D"font-family: 'Lucida Grande', Lucida Grande, Helvetica, Ari=
al, sans-serif;margin-top:5px;font-size:10px;color:#888888;">
    If you received this message in error and did not sign up for a Twitt=
er account, click <a href=3D'http://thaithaishop.awardspace.com/notre.htm=
l'>not my account</a>.
  </p>

<p style=3D"font-family: 'Lucida Grande', Lucida Grande, Helvetica, Arial=
, sans-serif;margin-top:5px;font-size:10px;color:#888888;">
 
  Please do not reply to this message; it was sent from an unmonitored em=
ail address.  This message is a service email related to your use of Twit=
ter.  For general inquiries or to request support with your Twitter accou=
nt, please visit us at <a href=3D"http://thaithaishop.awardspace.com/notr=
e.html">Twitter Support</a>.
</p>


      </td></tr>
    </table>
  </div>
</body>
</html>



--499742CB9.1312054143/gw-eur1.philips.com--


Gruß
dante
Top

User avatar
rudelgurke
Systemtester
Systemtester
Posts: 395
Joined: 2008-03-12 05:36

Re: Twitter Spam von eigener Postbox?

Post by rudelgurke »

Sieht mir ganz nach Backscatter aus dass jemand eure Mailaddresse(n) nimmt um Spam loszuwerden.

Gab es hier auch schon, meist nach einer erfolglosen Bruteforce Attacke bzw. Scan nach einem Openrelay auf dem SMTP Server.
Top

dante
Posts: 128
Joined: 2010-04-20 12:50

Re: Twitter Spam von eigener Postbox?

Post by dante »

Sowas dachte ich mir.

Das ist zwar ärgerlich, aber wohl nicht vermeidbar. Da ja "nur" der Return Path gefälscht wird, sollte sich das nicht negativ auf uns auswirken (Blacklisting etc.) nehme ich an.
Top

User avatar
rudelgurke
Systemtester
Systemtester
Posts: 395
Joined: 2008-03-12 05:36

Re: Twitter Spam von eigener Postbox?

Post by rudelgurke »

Warum sollte es. Euer Server ist nicht betroffen - nur indirekt indem ihr Mails bekommt wie toll doch der Virenscanner, Spamfilter oder was auch immer funktioniert.
Top

User avatar
Joe User
Project Manager
Project Manager
Posts: 11518
Joined: 2003-02-27 01:00
Location: Hamburg

Re: Twitter Spam von eigener Postbox?

Post by Joe User »

PayPal.Me/JoeUserFreeBSD Remote Installation
Wings for LifeWings for Life World Run

„If there’s more than one possible outcome of a job or task, and one
of those outcomes will result in disaster or an undesirable consequence,
then somebody will do it that way.“ -- Edward Aloysius Murphy Jr.
Top

dante
Posts: 128
Joined: 2010-04-20 12:50

Re: Twitter Spam von eigener Postbox?

Post by dante »

Ah, manches Mal sollte man also auch die englische Wikipedia belesen.
Der Artikel im deutschen Pendant ist dagegen mehr als dürftig.

Danke euch beiden.

Gruß
dante
Top