Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-19, 20:06:05

Author Topic: [QMAIL] Recipient Verification to avoid spamming  (Read 18494 times)

0 Members and 1 Guest are viewing this topic.

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #15 on: 2014-02-25, 18:43:11 »
Imagine someone have many servers in cluster. One server as frontend (like cdn/google do), some server as database server, someserver as web server, some servers as mail server and so on and so on.

So, in the feature, Kloxo-MR (or the successor) can handle efficiently.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #16 on: 2014-02-25, 19:21:10 »
Hi Mustafa,

Imagine someone have many servers in cluster. One server ..., some server ..., some server as xxx, some servers as yyy and so on and so on.

Imagine means to dream. Yes. I can dream of this. Currently, I, and the entire tiny community of Kloxo-MR, would be soooo must happy, if we must be able to sleep. If we can sleep, only then we can dream...

I cannot sleep because my server was hacked. So, my very sincere and honest suggestioon is to first have all the features stable and enhance the existing features dramatically.

Now just the fundamental things does not work and its development has remained to minimum. Ofcourse you have done the most excelent job. No doubt about it. But the development should remain within kloxo-mr targetting on drastic enhancement of existing features.

Look at backups and restore. This area is not good from the view point of its state of stagnant adter its development.

So, Mustafa I really hope that you bring kloxo-mr to a very decent and mature development. It would be really sad to have it's progress slowed down.
« Last Edit: 2014-03-29, 09:36:24 by Kloxo-DR »

Offline zenkul

  • Global Moderator
  • Master
  • *****
  • Posts: 383
  • Karma: +3/-0
    • View Profile
    • home & decor
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #17 on: 2014-02-25, 20:09:44 »
I agree with the strategic issues raised Kloxo-DR. It's time to do a middle ground that stabilization measures, including security issues. I think developing for this stabilization is very important.

No problem, for example there are other web panels that have compatible with Apache 2.4 ... as the day is long .. and it's time for rest. I think
easy, secure and speed up web panel ===> Kloxo-MR

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #18 on: 2014-02-25, 21:45:39 »
I agree with keeping updated and newest versions of software.

We should always do what will keep our servers safe, security first, bells and whistles second.

Updating spamdyke,  Apache, qmail-toaster, etc... these are important issues, and need to be addressed.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #19 on: 2014-02-27, 10:36:25 »
Qmail-toaster in Kloxo-MR (taken from qmailtoaster) already include patch for chkuser.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #20 on: 2014-02-28, 03:58:31 »
Hi, qmail-toaster in Kloxo-MR not use tcp.smtp but supervise.

netqmail is different way compare to qmail-toaster. So, for chkuser must set inside run file.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #21 on: 2014-02-28, 07:00:32 »
Hi Mustafa,

Hi, qmail-toaster in Kloxo-MR not use tcp.smtp but supervise.

netqmail is different way compare to qmail-toaster. So, for chkuser must set inside run file.

Should I write a cronjob to constantly reinstall and overwrite your run files with better run files to prevent spam attacks? Should everyone do that? Is the solution to overwrite your run files to prevent spam attacks and illegal email content logging a very special wish of mine?

I suggest to make a feature request to create a web interface for configuring Qmailtoaster and spamdyke. Both are just inevitable functions, as inevitable as apache and mysql, and, thus, require much better possibility for administrators for configuration.
« Last Edit: 2014-03-29, 09:38:37 by Kloxo-DR »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #22 on: 2014-02-28, 13:51:44 »
Investigate /etc/tcprules.d/tcp.smtp because smtp read this content.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #23 on: 2014-02-28, 17:45:47 »
Good bye.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline vpsbox

  • Junior Member
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
    • http://www.vpsbox.eu
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #24 on: 2014-03-03, 00:29:25 »
choose spamassaing form menu, than install razor2, pyzor, dcc (think dcc was instaled just need to update it)  (just lik it is shown  in this thread step 8 http://technotes.trostfamily.org/?p=184


ad rbl to qmail block list - manualy in config file /var/qmail/control/ blaclists ( -r xen.spamhaus.org is includet put others on new line include b.batacudacen... from the blog post i mentioned)

regeneratethe .cdb files with

qmailctl cdb

and you are ready 85 -90% of will gone


btw - to my opinion kloxo is very close good usable standart - and is the pannel with fastest options... only lack documentation...

« Last Edit: 2014-03-03, 00:31:47 by vpsbox »

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #25 on: 2014-03-03, 09:19:09 »
I want to say something about this discussion.  I am by skill a programmer.  I have recently spent time in Linux server admin class and my business partner is by skill, server admin.  We have tried to reproduce your bounce relay spam attack, and have been unable.  I am NOT saying it didn't happen, just that I can not reproduce.

Next, recipient blocking prior to qmail handling is not an option for me.  We have clients that have catchall set to postmaster, so they can have unlimited aliases without setting anything up.  Therefore, if example@domain.com doesn't exist,  what you propose by blocking at spamdyke level, client doesn't get mail even if catchall is set to a valid email.

On my tests, qmail properly deleted all mail sent to a known domain, unknown recipient.  We bombarded server4 with a literal mail syn flood, and although CSF shut down the flood, qmail bounced no messages.  Also, on all connections, log shows spamdyke operational.  Why was yours only on first connection?

Is it most efficient way, to process mail, then delete... no.  However, as I stated, it is not an option for me to block unknown recipient at spamdyke level.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #26 on: 2014-03-04, 07:36:09 »
Hello Chris,
We have tried to reproduce your bounce relay spam attack, and have been unable.  I am NOT saying it didn't happen, just that I can not reproduce.
There seem to be anathor victimized server in the other thread:
http://forum.mratwork.com/kloxo-mr-technical-helps/how-to-uninstall-qmail-toaster/

@hoangsang
The spammer have found your server, if my assumtion is correct. In that case, your server is being used to send emails to innocent victims. Then, you cannot use Kloxo-MR anymore. You must compile the Qmailtoaster with CHKUSER or stop using Kloxo-MR. Thats what Mustafa said to me!!!
Yes, CPU always load 100% because processing qmail-remote
When the spammer uses a special technique, then CPU gets overloaded that normal. In the TOP monitor you see many process active by the user qmaild. The CPU always load 100% because processing qmail-remote.

THIS IS WHAT HAPPENED ON MY SERVER, when the catchall was activated and setup to delete all emails to non-existent users!

Kloxo-MR is vulnerable to spamming because a spammer is able to make connections throuch CHKUSER and sidetrack the catchall and all other spamdyke protections. Thereafter, Kloxo-MR becomes a spamming server and can send emails to innocent victims.

For the spammer, it is the best that the Admin of Kloxo-MR does not even know if his server has converted into a spamming server and all email "as undelivered emails" gets relayed from the victimized server.

Chris, could you reproduce the above characteristics of blasting CPU and invoking the qmail-remote in your series of testing based on your extraordinary expertise? You and your partner, both are an inexperienced spammers and the testing you both conducted are useless!

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #27 on: 2014-03-04, 07:41:38 »
@Kloxo-DR,

if your qmail setting is correct, impossible your server as 'smtp relay' from outside. Like I said before, qmail-toaster in Kloxo-MR already have chkuser-patch.

Rule for relay is inside /etc/tcp.rules.d/tcp.smtp. This read my stmp-run.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #28 on: 2014-03-04, 07:50:52 »
Hi Mustafa,
if your qmail setting is correct, impossible your server as 'smtp relay' from outside.

There is no smtp-relay from outside in this case. The emails are sent from inside because those email addresses did not exist on the server. They are sent to innocent victims mentioned in "Recipient Path".
« Last Edit: 2014-03-29, 09:41:43 by Kloxo-DR »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [QMAIL] Recipient Verification to avoid spamming
« Reply #29 on: 2014-03-04, 09:00:59 »
One possibility, one or more domain inside your server send a spam. Remember, it's possible php send email via SMTP with 'unknown' identity (aka domain) but qmail-toaster permit because from inside (aka localhost). You can try modified tcp.smtp:

from:
Code: [Select]
127.:allow,RELAYCLIENT="",DKSIGN="/var/qmail/control/domainkeys/%/private"
:allow,BADMIMETYPE="",BADLOADERTYPE="M",CHKUSER_RCPTLIMIT="50",CHKUSER_WRONGRCPTLIMIT="10",DKSIGN="/var/qmail/control/domainkeys/%/private"

to:
Code: [Select]
127.:allow,BADMIMETYPE="",BADLOADERTYPE="M",CHKUSER_RCPTLIMIT="50",CHKUSER_WRONGRCPTLIMIT="10",DKSIGN="/var/qmail/control/domainkeys/%/private"
:allow,BADMIMETYPE="",BADLOADERTYPE="M",CHKUSER_RCPTLIMIT="50",CHKUSER_WRONGRCPTLIMIT="10",DKSIGN="/var/qmail/control/domainkeys/%/private"

With this trick, qmail will process all smtp (inside or outside) with the same rule.

..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

 


MRatWork Affiliates:    BIGRAF(R) Inc.    House of LMAR    EFARgrafix

Page created in 0.031 seconds with 18 queries.

web stats analysis