[GSA-RG] Problems with the mailing list

Donal K. Fellows donal.k.fellows at manchester.ac.uk
Tue Sep 26 04:55:23 CDT 2006


Ramin Yahyapour wrote:
> I saw that we received several spams and error messages from
> the list. I do not know what to do about that. I can only
> tell Joel Repogle and Andre Merzky about it.

There's been an enormous amount of viral spam directed at many GGF/OGF
lists over the past month or two (hardly unusual on the modern internet,
alas) but there's also been a mailserver somewhere that's insisted on
sending bounce reports to the wrong place. It's those bounce reports
that have been the real source of trouble.

My guess is that someone harvested the addresses of all GGF lists and
used those as From/Sender addresses, and that the host 62.118.48.58[*]
(claims its name is "sklad10", is located somewhere inside Russia,
possibly in the Moscow area given traceroute info) is running a
boneheaded open relay.

Donal.
[* I don't know if this is a permanent address; I haven't retained a
    long enough history of deleted messages to tell. The host does not
    have a reverse-DNS entry, but that's not necessarily malicious. ]


More information about the gsa-rg mailing list