<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Scotia Systems Blog &#187; spam</title>
	<atom:link href="http://www.scotiasystems.com/blog/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.scotiasystems.com/blog</link>
	<description>Web Design, SEO and IT Tips</description>
	<lastBuildDate>Fri, 03 Feb 2012 22:18:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>UCEProtect Strike Again!  Backscatterer.org Blacklisting</title>
		<link>http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=uceprotect-strike-again-backscatterer-org-blacklisting</link>
		<comments>http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 12:39:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Hints and Tips]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[UCEProtect]]></category>

		<guid isPermaLink="false">http://www.scotiasystems.com/blog/?p=462</guid>
		<description><![CDATA[Tweet A while ago I wrote about UCEProtect and how they were blocking a mail server due to an IP on a nearby segment being classed as a spam sender. Well today, I&#8217;ve hit another problem with UCEProtect &#8211; and this time it&#8217;s worse! It started when the client started getting bounce messages on emails [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.scotiasystems.com%2Fblog%2Fit-hints-and-tips%2Fuceprotect-strike-again-backscatterer-org-blacklisting%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/"></g:plusone>
			</div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/"  data-text="UCEProtect Strike Again!  Backscatterer.org Blacklisting" data-count="horizontal">Tweet</a>
			</div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>A while ago I wrote about UCEProtect and how they were blocking a mail server due to an IP on a nearby segment being classed as a spam sender.</p>
<p>Well today, I&#8217;ve hit another problem with UCEProtect &#8211; and this time it&#8217;s worse!</p>
<p>It started when the client started getting bounce messages on emails sent to AT&amp;T&#8217;s network:</p>
<p><strong>#5.3.0 smtp;553 5.3.0 flpd124 &#8211; o2N8qxwF027519, DNSBL:ATTRBL 521&lt; *.*.*.* &gt; _is_blocked.__For_information_see_http://att.net/blocks</strong></p>
<p>Following the link to AT&amp;T, there&#8217;s a form to request a de-listing, however no mention of why you&#8217;re getting blocked?</p>
<p>Now I&#8217;ve seen similar to this before, so knew to check out the following site which searches all the popular blacklists for listings:</p>
<p><a href="http://www.mxtoolbox.com/blacklists.aspx">http://www.mxtoolbox.com/blacklists.aspx</a></p>
<p>All came back clear, apart from one &#8211; backscatterer.org which was a new one to me?     So here&#8217;s the background on backscatterer.org.</p>
<p align="none">&nbsp;</p>
<h2>Non-Delivery Reports and Backscatter</h2>
<p>When you send an email to an organization, but spell the persons name wrongly, you get a bounce message.   This bounce message is generated in one of two ways.</p>
<p><em>1) The recipient server receives the email and then attempts to route it to the destination mailbox.   When it finds the mailbox doesn&#8217;t exist &#8211; it generates the bounce message.</em></p>
<p><em>2) The recipient server looks up the recipient name when the sending server starts the conversation.   When it finds the mailbox doesn&#8217;t exist &#8211; it terminates the connection, leaving the sending server to generate the NDR (non-delivery report)</em></p>
<p>If your server is configured using method (1) above (which is a valid method and withing the guidelines of the SMTP protocol) then backscatterer.org will blacklist you!!!</p>
<p>Now there are valid reasons for this &#8211; spammers are using the NDRs as a way to get your mail server to send spam NDRs by using fake email addresses.</p>
<p>However form them to then charge you 50 Euros to be removed from the list is a joke!   If you don&#8217;t pay to be removed &#8211; they&#8217;ll blacklist you for 4 weeks!</p>
<p>50 Euros to be delisted because your mail server is working correctly&#8230;   Hmmm&#8230;</p>
<p>Anyway, first here&#8217;s how to test your mailserver to see if it it vulnerable:</p>
<p>Telnet to your server on port 25, so : &#8220;telnet &lt;serverip&gt; 25&#8243;</p>
<p>You should receive a response similar to :</p>
<p><strong>220 MAILSERVER.MYDOMAIN.COM Microsoft ESMTP MAIL Service, Version 6.0.3790.3959 ready at Tue, 23 Mar 2010 11:33:16 +0000</strong></p>
<p>Type : &#8220;Helo sample.domain.com&#8221;<strong>Response : &#8220;MAILSERVER.MYDOMAIN.COM Hello&#8221;</strong></p>
<p>Type : &#8220;mail from: fake@fakedomain.com&#8221;<br />
<strong>Response : &#8220;250 2.1.0 fake@fakedomain.com&#8230;.Sender&#8221;fake@fakedomain.com&#8230;.Sender Ok&#8221;</strong></p>
<p>Type : &#8220;RCPT TO:  wrongname@mydomain.com&#8221;</p>
<p>At this point you should receive<strong> &#8220;555 User unknown&#8221;</strong></p>
<p>If you receive <strong>&#8220;250 .2.1.5 wrongname@mydomain.com&#8221;</strong> &#8211; then you have a problem.</p>
<p align="none">&nbsp;</p>
<h2>The Fix (for Exchange 2003)</h2>
<p>1) In System Manager, go to Global Settings, right click Message Delivery and select properties</p>
<p>2) Check the box &#8220;Filter recipients who are not in the directory&#8221;</p>
<p>3) Go To Administrative Group, Servers, Protocols, SMTP, right click and select properties. </p>
<p>4) Under Advanced, select Edit and Check the box that says &#8220;Apply Recipient Filter&#8221;.</p>
<p>5) Restart the SMTP Service for the change to take effect.</p>
<p>If I were you I&#8217;d check my mailserver and apply the above fix before you get blacklisted and have to pay the 50 euros&#8230;</p>
<p>Oh &#8211; and if you&#8217;re blacklisted by AT&amp;T &#8211; here&#8217;s the form to request delisting : <a href="http://worldnet.att.net/general-info/block_admin.html">http://worldnet.att.net/general-info/block_admin.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.scotiasystems.com/blog/it-hints-and-tips/uceprotect-strike-again-backscatterer-org-blacklisting/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Critical Update emails from Microsoft &#8211; BEWARE</title>
		<link>http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-update-emails-from-microsoft-beware</link>
		<comments>http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 09:08:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Hints and Tips]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[critical update]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.scotiasystems.com/blog/?p=90</guid>
		<description><![CDATA[Tweet I&#8217;ve seen a number of emails recently which appear to be from Microsoft with advice about a critical patch you need to install.   The latest one was titled &#8220;Install Critical Update for Microsoft Outlook&#8221; regarding patch &#8220;officexp-KB910721-FullFile-ENU.exe&#8220; Delete these emails &#8211; they&#8217;re not legit!   MS would never email you with advice like this as [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.scotiasystems.com%2Fblog%2Fit-hints-and-tips%2Fcritical-update-emails-from-microsoft-beware%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/"></g:plusone>
			</div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/"  data-text="Critical Update emails from Microsoft &#8211; BEWARE" data-count="horizontal">Tweet</a>
			</div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>I&#8217;ve seen a number of emails recently which appear to be from Microsoft with advice about a critical patch you need to install.  </p>
<p>The latest one was titled &#8220;Install Critical Update for Microsoft Outlook&#8221; regarding patch &#8220;<span style="font-size: x-small;"><strong>officexp-KB910721-FullFile-ENU.exe</strong>&#8220;</span></p>
<p>Delete these emails &#8211; they&#8217;re not legit!   MS would never email you with advice like this as you should be using automatic updates to receive any patches from them.</p>
<p>TIP:</p>
<p>If you hover your mouse over the link in the email &#8211; you&#8217;ll see that it doesn&#8217;t actually link back to Microsoft &#8211; instead it links back to a random address that &#8220;looks&#8221; like Microsoft.  In my example it was linking to a site along the lines of update.microsoft.com.1lfx.mx.com.   If you don&#8217;t pay attention &#8211; it&#8217;s easy to miss the &#8220;1lfx.mx.com&#8221; and think that this is linking to MS.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scotiasystems.com/blog/it-hints-and-tips/critical-update-emails-from-microsoft-beware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNS Blacklist (Email server blocked sending)</title>
		<link>http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dns-blacklist-email-server-blocked-sending</link>
		<comments>http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 22:36:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Hints and Tips]]></category>
		<category><![CDATA[smtp]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.scotiasystems.com/blog/?p=71</guid>
		<description><![CDATA[Tweet Had a client with a blocked SMTP server this week.   After taking a look at a few bounce messages it became evident that the connection had just been terminated by the remote host. Verifying the problem is possible, using telnet to the remote host on port 25 from your local mail server: telnet &#60;remote [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.scotiasystems.com%2Fblog%2Fit-hints-and-tips%2Fdns-blacklist-email-server-blocked-sending%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/"></g:plusone>
			</div>
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/"  data-text="DNS Blacklist (Email server blocked sending)" data-count="horizontal">Tweet</a>
			</div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Had a client with a blocked SMTP server this week.   After taking a look at a few bounce messages it became evident that the connection had just been terminated by the remote host.</p>
<p>Verifying the problem is possible, using telnet to the remote host on port 25 from your local mail server:</p>
<p>telnet &lt;remote mail server&gt; 25</p>
<p>If you get disconnected immediately &#8211; you&#8217;re probably getting blocked as a spam sender.   Here&#8217;s a useful site to check the status of your mail server with a variety of filters:</p>
<p><a href="http://www.mxtoolbox.com/blacklists.aspx">http://www.mxtoolbox.com/blacklists.aspx</a></p>
<p>After clearing an erroneous block, mail started flowing again (albeit after a few hours).</p>
<p>I&#8217;ll be keeping an eye on the above site for any further warnings on this mail server&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scotiasystems.com/blog/it-hints-and-tips/dns-blacklist-email-server-blocked-sending/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

