Forged Headers got me thinking...

Hi
Ok all of a sudden I am getting messages from all manner of mail servers bouncing back email that claims to come from my own address (my address is in the "Return-Path" ). I realize that these are the result of forged headers in the messages (probably from a zombie PC) but we host a number of virtual domains so I'm beginning to doubt our configuration. (21 bounced messages in the past six hours.)
I even shut down apache to ensure that one of our scripted "comment boxes" has not been hijacked. I have also checked the SMTP logs and don't see the outgoing messages. Our server is not listed as the "Reporting-MTA"
In the email that is coming back the error reports that the mail was "Recieved" by another server not ours...
Is there anything else I can check?
BTW can I redirect a message based on it's subject?

Here you go
The do seem to originate from my server. Are they virus notices being sent back to a forged address? Or is someone relaying of our server some how?
From: [email protected]
Subject: Delivery Status Notification (Failure)
Date: April 13, 2008 1:53:01 AM GMT-04:00
To: [email protected]
Return-Path:
Received: from mail.iplanitonline.com ([unix socket]) by mail.iplanitonline.com (Cyrus v2.2.12-OS X 10.4.8) with LMTPA; Sun, 13 Apr 2008 01:58:35 -0400
Received: from localhost (localhost [127.0.0.1]) by mail.iplanitonline.com (Postfix) with ESMTP id D9B2D1742F66 for <[email protected]>; Sun, 13 Apr 2008 01:58:35 -0400 (EDT)
Received: from mail.iplanitonline.com ([127.0.0.1]) by localhost (zoot.local [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 09275-01 for <[email protected]>; Sun, 13 Apr 2008 01:58:29 -0400 (EDT)
Received: from fredeng.com (adsl-68-78-84-166.dsl.milwwi.ameritech.net [68.78.84.166]) by mail.iplanitonline.com (Postfix) with ESMTP id D90461742F3D for <[email protected]>; Sun, 13 Apr 2008 01:58:28 -0400 (EDT)
X-Sieve: CMU Sieve 2.2
Mime-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status; boundary="9B095B5ADSN=_01C89BC858981CEC00002A85fredeng.com"
X-Dsncontext: 335a7efd - 4523 - 00000001 - 80040546
Message-Id: <[email protected]>
X-Virus-Scanned: by amavisd-new at iplanitonline.com
X-Spam-Status: No, hits=3.093 tagged_above=-999 required=5 tests=BAYES_40, FHDATE_ISNT2006, FHDATE_ISNT200X, HELOMISMATCHCOM, HOSTEQDSL, HOSTEQ_DSLDDDD, HOSTEQ_D_D_DD, HOSTMISMATCHNET, NOREALNAME, URI_REDIRECTOR
X-Spam-Level: *
From: [email protected]
Subject: Returned mail: see transcript for details
Date: April 13, 2008 1:51:33 AM GMT-04:00
To: [email protected]
Return-Path:
Received: from mail.iplanitonline.com ([unix socket]) by mail.iplanitonline.com (Cyrus v2.2.12-OS X 10.4.8) with LMTPA; Sun, 13 Apr 2008 01:57:57 -0400
Received: from localhost (localhost [127.0.0.1]) by mail.iplanitonline.com (Postfix) with ESMTP id 64C571742F37 for <[email protected]>; Sun, 13 Apr 2008 01:57:57 -0400 (EDT)
Received: from mail.iplanitonline.com ([127.0.0.1]) by localhost (zoot.local [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 05151-07 for <[email protected]>; Sun, 13 Apr 2008 01:57:50 -0400 (EDT)
Received: from server1.smartbiz.com (server1.smartbiz.com [72.19.246.178]) by mail.iplanitonline.com (Postfix) with ESMTP id 01B2E1742F0D for <[email protected]>; Sun, 13 Apr 2008 01:57:49 -0400 (EDT)
Received: from localhost (localhost) by server1.smartbiz.com (8.13.6/8.13.1) id m3D5pXVN022288; Sat, 12 Apr 2008 22:51:33 -0700
X-Sieve: CMU Sieve 2.2
Message-Id: <[email protected]>
Mime-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status; boundary="m3D5pXVN022288.1208065893/server1.smartbiz.com"
Auto-Submitted: auto-generated (failure)
X-Virus-Scanned: by amavisd-new at iplanitonline.com
X-Spam-Status: No, hits=-2.395 tagged_above=-999 required=5 tests=ALL_TRUSTED, AWL, BAYES_00, FHDATE_ISNT2006, FHDATE_ISNT200X, URI_REDIRECTOR
X-Spam-Level:
From: [email protected]
Subject: Message status - undeliverable
Date: April 13, 2008 1:51:22 AM GMT-04:00
To: [email protected]
Return-Path: <[email protected]>
Received: from mail.iplanitonline.com ([unix socket]) by mail.iplanitonline.com (Cyrus v2.2.12-OS X 10.4.8) with LMTPA; Sun, 13 Apr 2008 01:57:44 -0400
Received: from localhost (localhost [127.0.0.1]) by mail.iplanitonline.com (Postfix) with ESMTP id B16F41742EF8 for <[email protected]>; Sun, 13 Apr 2008 01:57:44 -0400 (EDT)
Received: from mail.iplanitonline.com ([127.0.0.1]) by localhost (zoot.local [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 04832-10 for <[email protected]>; Sun, 13 Apr 2008 01:57:38 -0400 (EDT)
Received: from mail.smarthealth.com (mail.smarthealth.com [207.114.156.132]) by mail.iplanitonline.com (Postfix) with ESMTP id E4C131742ED6 for <[email protected]>; Sun, 13 Apr 2008 01:57:37 -0400 (EDT)
Received: from HERMES.smarthealth.com (hermes.smarthealth.com [172.16.3.31]) by mail.smarthealth.com (8.13.7+Sun/8.12.10) with ESMTP id m3D5pMxe019552 for <[email protected]>; Sat, 12 Apr 2008 22:51:22 -0700 (MST)
Received: from SmartComm-MTA by HERMES.smarthealth.com with Novell_GroupWise; Sat, 12 Apr 2008 22:51:22 -0700
X-Sieve: CMU Sieve 2.2
Message-Id: <[email protected]>
X-Mailer: Novell GroupWise Internet Agent 6.5.7
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="=_PartF4DDB04A.0_="
X-Virus-Scanned: by amavisd-new at iplanitonline.com
X-Spam-Status: No, hits=-0.993 tagged_above=-999 required=5 tests=BAYES_00, FHDATE_ISNT2006, FHDATE_ISNT200X, NOREALNAME
X-Spam-Level:
From: [email protected]
Subject: failure notice
Date: April 13, 2008 1:51:12 AM GMT-04:00
To: [email protected]
Return-Path:
Received: from mail.iplanitonline.com ([unix socket]) by mail.iplanitonline.com (Cyrus v2.2.12-OS X 10.4.8) with LMTPA; Sun, 13 Apr 2008 01:57:37 -0400
Received: from localhost (localhost [127.0.0.1]) by mail.iplanitonline.com (Postfix) with ESMTP id 676F51742ED0 for <[email protected]>; Sun, 13 Apr 2008 01:57:37 -0400 (EDT)
Received: from mail.iplanitonline.com ([127.0.0.1]) by localhost (zoot.local [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 05151-06 for <[email protected]>; Sun, 13 Apr 2008 01:57:30 -0400 (EDT)
Received: from mail.cside.jp (ph00190.cside.jp [202.191.117.176]) by mail.iplanitonline.com (Postfix) with SMTP id C465E1742EAC for <[email protected]>; Sun, 13 Apr 2008 01:57:28 -0400 (EDT)
Received: (qmail 15460 invoked for bounce); 13 Apr 2008 14:51:12 +0900
X-Sieve: CMU Sieve 2.2
Message-Id: <[email protected]>
X-Virus-Scanned: by amavisd-new at iplanitonline.com
X-Spam-Status: No, hits=3.309 tagged_above=-999 required=5 tests=AWL, BAYES_00, FHDATE_ISNT2006, FHDATE_ISNT200X, HELOEQJP, HOSTEQJP, MSGIDFROM_MTAID, NOREALNAME
X-Spam-Level: *

Similar Messages

  • Started movie download and its got stuck, think its cos i did a firmware

    I started movie download and at the same time did a firmware upgrade, the movie has stopped downloading and wont restart. A new download is working fine.
    How do I delete the stuck movie, and restart it as a new download
    Thanks

    I would let it finish if it's proceeding.  Then if they still aren't there, try restoring from backup again (by right-clicking on the name of your phone on the left panel of iTunes and selecting Restore from Backup, then choosing your most recent backup to restore from).  Suggest you go to iTunes preferences and on the Devices tab check "Prevent...from syncing automatically".  This will prevent iTunes from automatically syncing when you connect your phone and overwriting the backup you are trying to restore to.

  • Something that got me thinking

    Will I be able to use my grandma's upgrade, even though shes on a different AT&T account??? Will she just upgrade to the iphone, and not get it activated, and give it to me? Is there a different way this works? Or does it just not work like this??
    Please Help!!

    Wont she incur the 2 year agreement on her account. And the sim cards can be switched moving the settings to the iPhone? I called the AT&T store when a friend of mine was out of his 2 year. I was going to give him my 3G if he would let me buy a 3Gs on his account. He incurs the 2 year agreement, we switch the information from phone to phone he takes my 3G I get the new 3GS. AT&T guy said, on their network they cant tell what kind of phone someone has just that they have a phone, 3G 8 GB, 3G 16GB, 3GS, they cant tell without looking up the account.

  • Remote works on my iPhone 4, but not the new iPad2 I just got.  Both setup the same ios5.1.1 9B206.  remote 2.3 (379)

    Remote sharing is on.  Verified my account and password are same.  When I launch remote I get the  "Turn on Home Sharing in iTunes on your computer or on Apple TV using the account [email protected]"
    If I go to settings, I see home sharing is on, and it says "Remote will autonatically find the iTunes libraries and Apple TV's that have Home Sharing turned on using the account [email protected]
    Just to test connectivity, I clicked on "Add an iTunes Library to add a computer that is NOT using home sharing and it gives a code, and under devices on iTunes, you see "iPAd".  So iTunes recognizes the iPad.
    But what it SHOULD do is automatically connect, because Home Sharing is on, and I've put in a valid ID and password on the iPad.
    I can launch Remote on my iPhone 4, right next to it, using same ID, and it works fine
    On both devices, ios is 5.1.1 (9B206)   Remote is 2.3 (379)
    It sounds like an issue with the iPad2 itself
    As I was typing this out, I got to thinking about any router changes I had made.
    I remembered that recently I had changed my WLAN settings from WPA2 Personal and AES algorithm to Mixed WPA/WPA2 Personal and TKP & AES algorithm.  But this was before I setup the iPad2, so it may not have any bearing.  But because I was thinking about it.........
    So even though WIFI seemed to be working OK for everything, I removed my automatic connection to my WIFI, and recreated the connection, and Remote came right up when I launched it.

    Hi, thanks for the suggestion. I have tried as you suggested, and when opening the "purchased" apps some have the icloud logo next to them, but I only have "OPEN" against "Find My iPhone". When opening it up, it goes through the same routine; needs to be updated before proceeding, and wouldn't update because I don't have IOS8.
    Anything else I could try, or am I doomed!
    All of your help is much appreciated, thanks

  • I tried to delete and reinstall Lightroom 5 and have the same problems. I was on chat last night and got a reinstall. This Am The shortcut is broken and when I open directly it is asking me for my serial number. I did that last night.

    I successfully got Lightroom to open, it does not show my SD drive. I added the SD drive (folder) and it opened a few photos but then opened an old catalog. I tried again and got grey thumbnails with the correct Canon file numbers but no images. When I selected import, it opened an old catalog and began to convert it. I recently got the creative cloud subscription and I can open these photos there after pinning.  The problem is, I don't have time to figure out Photoshop before I need these photos.

    Thank you for responding. I can display my CR2 files in any program that
    will show them. I can drag or "pin' them to the Ps logo or button at on the
    task bar and they will be available in Photoshop. I purchased Lightroom
    before the Creative cloud was available. that's why I have a serial number.
    You've got me thinking I have two "dueling" programs of Lightroom. Could
    this be the problem? I have now deleted Lightroom and was going to
    reinstall. I will wait and figure out the reinstall from the Creative
    Cloud. thank you again.

  • Very strange!! i got the old web?

    I have a very strange thing that happened and iam trying to figureout what is going on after i tried modifying tens or maybe hundreds of setting trying to solve it.
    I have a motorola sbg6580 for my home perimeter i have forwared port 80 to my webserver and it works fine jst like always.
    Now i also have an ASA 5505 which i configured for the webserver, after i put the webserver behind it the topology config was like this:
    motorola sbg6580>ASA>switch>webserver1+webserver2+laptop. (forworded port 80 from the moto to the ASA external interface).
    strangely, from the outside internet i can access only the old version of the website (i did updated the website the night before and it worked fine when connected directlly to the moto with out the ASA).
    Then i found out that the old version of the website (website contects before update) also exist on the other web server so i figured OK i forgot to stop the other server's website, but when i stopped the other server'ways website the same thing keeps happening..i get the old website.
    By the way (when i type the address of the intended website (ip address http://x.x.x.x) from a computer on the VLAN or the LAN I Get the updated view of the website and everything is fine, but when i access it from the internet i get the old unupdated view!!!
    After that i got the webserver off the ASA's network and connected it directly to the moto like before when it was working fine (and i did the port forwarding to the server again) i got the same problem again..i get the old view of the website not the updated when i try to open it from the internet,but when i open it locally from the LAN i get the new updated website with no problem.
    This got me thinking of three possibilities:(which are impossible to even think about):
    1-Is there some caching function of the webserver it self for the old website or some where on the network? (if yes then how come i can open it just fine and view the updated website from the LAN or from the webserver host it self?) so this might be impossible which brings the thought of the second and most likely possibility which is:
    2-The Motorolla router somehow have a malfunction wth it's forwarding capability (which is also not possible because when i send http request from the internet i do get the website but not the updated one but the old version which does not even exist on the server.
    3-The ASA firewall is somehow contagious!!!
    The question is (where exactly is this old website is view or layout is coming from after i tookout it's files from the server it self and replaced it with new files when are for the new updated website) , and how to fix it?
    This is the first time i see such a thing and i have been trying for hours and hors to solve it or see where the problem is (i suspect problem in the moto router)

    Apple has an out of warranty replacement program, the cost in the US is $199. I don't know if any original iPhones are still available under this program(remember, that phone was discontinued sometime ago), but even if they were, why would you spend $200 on a discontinued phone?

  • Got Pacifist..but am I lost on trying to use it ! Expert help please !

    Having trouble with lost files like everyone else,sssoooo... I got Pacifist, thinking I can do this! I havn't a clue on what I am doing! Just not "techy enough" to know what to do. I open Pacifist with the "open package button, then where to and what next ? Would appreicate help in getting me started! thanks..... cd

    Firstly, the installation pacakges on the install disks are hidden, so you'll need to be able to see hidden files.
    An easy way to do this is to download and install Tinkertool and enable the "show hidden files" option.
    Once you've done that, you should be able to inspect the Logic install disks and see the various packages.
    Use Pacifist to open a package, and you'll see a list of the files contained within - just extract what you want to where you want.

  • Httpservice POST headers/XML payload formation

    I am trying to use the Quickbase API (see reference below) with a POST.  I am having trouble forming it; specifically, I am clueless as to how to format the header (headers="").  I think the XML Payload is correct, but who knows.  Thanks for your help!
    Quickbase API reference:
    Example XML Request
    POST /db/6c5xatxy HTTP/1.0
    Content-Type: application/xml
    Content-Length: 88
    QUICKBASE-ACTION: API_GetRecordInfo
    <qdbapi>
    <rid>4</rid>
    <ticket>1_6c6482m9_j36_c7mdvh9cmmtn9c8qtr5qchvw33v</ticket>
    </qdbapi>
    My code:
    <fx:Declarations>
      <s:HTTPService id="serviceQBPost" method="POST"
                     url="https://www.quickbase.com/db/beu45unrw"
                 headers="Content-Type: application/xml Content-Length: 88 QUICKBASE-ACTION: API_GetRecordInfo"
             result="serviceQBPost_resultHandler(event)"
             fault="serviceQBPost_faultHandler(event)">
                     <s:request xmlns="">
               <qdbapi>
                 <rid>4</rid>
                         <ticket>1_6c6482m9_j36_c7mdvh9cmmtn9c8qtr5qchvw33v</ticket>
               </qdbapi>
             </s:request>
      </s:HTTPService>
    </fx:Declarations>

    Well, I solved my performance problem by using XMLSocket,
    instead of HTTPService - a shame, since HTTPService is more
    appropriate.
    Question: how do I determine whether Adobe knows about this
    issue, and whether they care?

  • I got this from Amazon, what's wrong with these pics?

    Great share!  I hate to see this type of thing happen, but glad to see you got it resolved. 
    For everyone's knowledge... if you feel that you purchased sketch software, you can definitely call the Microsoft anti-piracy hotline at (800) RU-LEGIT, e-mail Microsoft at [email protected] or contact the Business Software Alliance (BSA) anti-piracy hotline at (888) NO-PIRACY to report them like the above post.

    I needed another copy of Office 2010 for a new user here. I needed2010 since 2013 isn’t compatible with our PM/EMR systems. I went to Amazon anddid a search for Office 2010. In the list that came up there was a new copy forsale. I ordered this and it came in 2 days later. I already had copies of Office 2010 on our systems so I loadedit off a share and just needed the key. I went to put the new key in and it wouldn’ttake it. Tried it again just to make sure I didn’t fumble the key, still tellingme not a valid key. This got me thinking, OK why isn’t it taking the key. Iwent to one of my coworkers and asked them to read the key off so I can makesure my old eyes were not failing me. Same digits I just tried. He put the disk in his PC and it took a fewminutes to come up to the install screen asking for the key. He inputted thekey and it...
    This topic first appeared in the Spiceworks Community

  • Do You Think Software Developers Are Obligated To Have A Windows 10 Build?

    I don't think they have an obligation, but there can be a risk of losing customers if they don't keep current.

    So I'm sure like many of you, I'm a part of a few different communities and forums. One that I'm a part of reacted to an announcement by a software developer that they were waiting 6 to 9 months to get a Win 10 version of their software ready. General reaction was not positive.
    So it got me thinking, do you think Software Developers have an obligation to support a new OS like Windows 10 from the get-go? Or do you think developers have the right to wait to see how a new OS runs first before releasing a public build?
    This topic first appeared in the Spiceworks Community

  • Yikes! I think I goofed permissions, but not sure...(help!)

    Sometimes I sit at the wifey's computer to access my Aperture file which is another room residing on the hard drive of my machine. Well, sometimes when I'm at her machine and navigate (with Finder) to my computer wherein the Aperture file resides and attempt to launch it, I get a message that I don't have proper permissions. If I log in to my computer with my logon and password, I can access it, but to save time, I did the following:
    I changed the permissions on my Aperture file and EVERY file and folder within to be "read + write" by everyone. Now I can launch the Aperture file from any computer on my home network, but I've got this sinking feeling that I've screwed up and I will have problems somewhere down the line (with Vault, Time Machine, or something sinister just lying out there waiting on me).
    So, do you think changing all the permssions essentially was an error I need to correct (somehow)? Or, does it really matter if I control my home network and I'm not worried about security.
    Any advice? Please?
    Charles

    Nuclear launch codes - now that's an idea...
    Thanks John, I feel much better. I got to thinking that maybe, somehow, Aperture itself might overwrite some data unless it was protected or something like that. Whew, glad I didn't screw up. I have 14,000 family pics in one library alone! I have way too much time on my hands.
    The Fast User Switching is definitely the way to go. I didn't even think of that.
    Thanks again,
    Charles

  • A31 video...thinking out loud

    Greetings,
    New user here...  I've been spending lots of my spare time reading all the fun things about the A31 that I have and its known issues.  I'm having fun with what looks to be a pretty solid machine with some "character"   I've already learned a lot from this forum.
    Here is a quick question for the pro's...
    With regard to the GPU problem that a machine of this age sometimes has, is there any advantage to running the A31 in a dock and would this alleviate or somehow lessen the burden on the GPU?  Thinking out loud, with the A31 in a dock, there is less actual handling of the laptop and therefore less stress to the solder joints on the GPU. 
    On a related note to this subject, I seem to have read about a Thinkpad dock II that you can actually put a video card in, which got me thinking that this may be a way to continue to use an A31 that may have had a developing GPU solder joint issue or even a full blown dead GPU.  Its obviously not so much as laptop at that point as it would be a desktop, but... would it still be functional as a "desktop"?
    Im thinking out loud at this point as (knock on wood), my A31 is working perfectly...this is more about the future for this machine.
    Regards to all,
    N5XL
    Message Edited by N5XL on 03-20-2009 08:58 AM

    @gehageh:
    You may want to give it a try, although I believe that your problem is somewhere on the motherboard...
    Good luck.
    Cheers,
    George
    In daily use: R60F, R500F, T61, T410
    Collecting dust: T60
    Enjoying retirement: A31p, T42p,
    Non-ThinkPads: Panasonic CF-31 & CF-52, HP 8760W
    Starting Thursday, 08/14/2014 I'll be away from the forums until further notice. Please do NOT send private messages since I won't be able to read them. Thank you.

  • Exporting ADF Table Headers to an EXCEL sheet

    Hello,
    We have an adf table (Jdev10.1.3g). We need to export the Headers of the table to an excel sheet. I have hold on the headers and can put it in an array/arrayList. Basically, I need help with how to browse to the file where user wants to store the table headers._ I think once we can browse to the file location, we can use the POI HSSF API as we have for the task below. Any code examples are welcome.
    We are already SUCCESSFULLY uploading the contents of the excel sheet (using <af:inputFile> tag) and writing the contents to adf table. Lucas Jellema's article and code example was very helpful.
    Thanks,

    Hi,
    this thread is duplicate of this.... Exporting ADF table Headers to Excel
    Please be patience untill the reply comes.... dont duplicate the thread its meaningless
    Regards,
    Suganth.G

  • Outlook 2010 - connect headers only

    I'm using outlook 2010 and it says 'connected to microsoft exchange headers'. I think this is giving me a strange thing that searching for emails is only returning emails that I've read.
    Kevin

    udenit, I'll bet if you were to go into the 'Download Preferences' and uncheck 'On Slow Connections Download Only Headers' then it will return to Connected to Microsoft Exchange.
    (I realize that udenit has probably already resolved this issue, but I wanted to make sure others we able to find the answer, cause it took me some trial and error before I finally figured it out)

  • JB1 - Who's still got 1 going str

    Hi All,
    I was just thinking that my JB is doing dam well, never had a problem with it and it is still used every day for the last 4-5 years on my HiFi, used to take it on holiday with me but it being the dinosaur it is I thought it would be best get a Zen Micro instead.
    This got me thinking about how many other users are still using the old JB's, mine is a 0GB version and has around 800 tracks on it.

    Have to agree with the latest firmware, it works just perfect.
    Transfer speeds are a little slow, but thats just the technology that has improved on the new players.
    Could this be the best player creative made? although I do like my Zen Micro, but it can be a little awkward compared to the JB. If the touch was as good as the JB it would have easily beat the iPod into a corner!!
    <SPAN class=time_text>
    Message Edited by bigred on 05-3-2005 0:6 AM

Maybe you are looking for