Spammel a T-Online / ex-IWIW?

A privát levelezésem egy kicsi, bérelt virtuális szerveren üzemel. Ez minimális forgalmat jelent, ennek ellenére feltűnt nemrég, hogy a T-Online-tól rendszeresen jönne spam.

Egy kiragadott példa a mai napról:


Jan 7 12:22:31 HOSTNAME postfix/smtpd[6216]: connect from iwiw02d.mail.t-online.hu[84.2.42.67]
Jan 7 12:22:31 HOSTNAME policyd-spf[5420]: None; identity=helo; client-ip=84.2.42.67; helo=iwiw02d.mail.t-online.hu; envelope-from=dulavicsncwgyr1katinka@jeune-asiatique.com; receiver=RECIPIENT
Jan 7 12:22:31 HOSTNAME policyd-spf[5420]: Permerror; identity=mailfrom; client-ip=84.2.42.67; helo=iwiw02d.mail.t-online.hu; envelope-from=dulavicsncwgyr1katinka@jeune-asiatique.com; receiver=RECIPIENT
Jan 7 12:22:31 HOSTNAME postfix/smtpd[6216]: 65AB5A861: client=iwiw02d.mail.t-online.hu[84.2.42.67]
Jan 7 12:22:31 HOSTNAME postfix/cleanup[53444]: 65AB5A861: message-id=<144b30f988919348e1cc39dfd94cb7bf@jeune-asiatique.com>
Jan 7 12:22:31 HOSTNAME postfix/qmgr[22865]: 65AB5A861: from=, size=5178, nrcpt=2 (queue active)
Jan 7 12:22:31 HOSTNAME postfix/smtpd[6216]: disconnect from iwiw02d.mail.t-online.hu[84.2.42.67]

Számomra attól igazán pikáns, hogy ex-iwiwes hostnevekkel kapcsolódnak a küldő MTA-k (iwiw01d és iwiw03d is volt a naplóban).

Hozzászólások

A code taget zard le, mert elrontja a blogoldalt.

Az a trukk, hogy a drupal nem kepes felismerni a code taget a teaser keszitesnel, igy celszeru manualisan beszurni a <!--break--> taget - ertelemszeruen a beszurt kod ele.
--
Ki oda vágyik, hol száll a galamb, elszalasztja a kincset itt alant:


()=() 
('Y') Blog | @hron84
C . C Üzemeltető macik
()_()

A *@freemail.hu átirányitások miatt lehetnek ilyenek, valamiért az iwiw* hostokat használják a levelezésre.

HA URIBL-t használsz, akkor ilyet már nem kapnál, de persze a legjobb lenne, ha a T-Online (is) használná és/vagy blokkolná a notórius magyar spammerek tartományait. Jelen esetben pl. a 188.42.255.64-127 tartományt (de az egész 188.42.252.0-188.42.255.255 tartományért sem lenne kár)

Ezt az AS5577 résztartományt 2014.12.07 óta használja a cimlistak.com / ugyismegveszel.hu "csoport" és még használni is fogja egy ideig.

# inetnum: 188.42.252.0 - 188.42.255.255 / netname: WZSG-1 / descr: Webzilla Singapore Pte Ltd / country: SG
# org: / admin-c: AB29962-RIPE / tech-c: AB29962-RIPE / status: ASSIGNED PA / mnt-by: ROOT-MNT / changed: noc@as5577.net 20131004
# organisation: ->Person: Andy BIERLAIR / org-name: / org-type:
# address: Webzilla Singapore PTE LTD; 10C Ubi Crescent; 408564, Singapore / e-mail: andy@webzilla.com / abuse-mailbox: / phone: +65 6742 9698

Domain map history:
201412081200 088ww.com + betuuu.com
201412081400 088ww.com + betuuu.com + pillsgreentea.com + zrserwis.com
201412091200 pillsgreentea.com + zrserwis.com
201412101800 nitsys.com + zrserwis.com
201412102000 ksliebei.com + nitsys.com + webdesignoregon-or.com
201412111000 ksliebei.com + webdesignoregon-or.com
201412111200 kiyavia-tour.com + ksliebei.com + webdesignoregon-or.com
201412111600 kiyavia-tour.com + qazvinarchery.com + webdesignoregon-or.com
201412121000 kiyavia-tour.com + qazvinarchery.com
201412121200 asfrdev.com + kiyavia-tour.com + qazvinarchery.com
201412121400 asfrdev.com + hzgreat100.com + kiyavia-tour.com
201412131000 asfrdev.com + hzgreat100.com
201412131200 asfrdev.com + hzgreat100.com + jslbgg.com
201412141000 asfrdev.com + jslbgg.com
201412221000 517dcgz.com + jslbgg.com
201412221200 hct56.com + hennessieblog.com
201412231000 colomaoutlet.com + fsblph.com + hct56.com + hennessieblog.com
201412231200 colomaoutlet.com + fsblph.com + gbrchem.com + gogreenbarter.com + hct56.com + hennessieblog.com + imktkorea.com
201501051000 fsblph.com + gbrchem.com + gogreenbarter.com + imktkorea.com
201501051200 culs-de-salopes.com + ezcmedical.com + gogreenbarter.com + lunatechconsulting.com
201501051400 culs-de-salopes.com + ezcmedical.com + fenottecreations.com + gogreenbarter.com + lunatechconsulting.com
201501061000 culs-de-salopes.com + ezcmedical.com + fenottecreations.com + lunatechconsulting.com
201501061200 cousinbasil.com + culs-de-salopes.com + ezcmedical.com + fenottecreations.com + jolielesbienne.com + lunatechconsulting.com
201501071000 cousinbasil.com + dy5778.com + jolielesbienne.com + pf59.com
201501071200 baike3.com + cousinbasil.com + dy5778.com + jolielesbienne.com + pf59.com
201501071400 7nef.com + baike3.com + jeune-asiatique.com + jolielesbienne.com + petitsseinsnus.com + pf59.com

Aktuális reverse-k (bár lehet, hogy ez kicsit hosszú lesz...)
2.255.42.188.in-addr.arpa domain name pointer aback.jeune-asiatique.com.
3.255.42.188.in-addr.arpa domain name pointer abed.jeune-asiatique.com.
4.255.42.188.in-addr.arpa domain name pointer aborigine.jeune-asiatique.com.
5.255.42.188.in-addr.arpa domain name pointer absence.jeune-asiatique.com.
6.255.42.188.in-addr.arpa domain name pointer academic.jeune-asiatique.com.
7.255.42.188.in-addr.arpa domain name pointer achy.jeune-asiatique.com.
8.255.42.188.in-addr.arpa domain name pointer acolyte.jeune-asiatique.com.
9.255.42.188.in-addr.arpa domain name pointer additive.jeune-asiatique.com.
10.255.42.188.in-addr.arpa domain name pointer addle.jeune-asiatique.com.
11.255.42.188.in-addr.arpa domain name pointer adhesive.jeune-asiatique.com.
12.255.42.188.in-addr.arpa domain name pointer adjust.jeune-asiatique.com.
13.255.42.188.in-addr.arpa domain name pointer aerate.jeune-asiatique.com.
14.255.42.188.in-addr.arpa domain name pointer aerobic.jeune-asiatique.com.
15.255.42.188.in-addr.arpa domain name pointer agonizing.jeune-asiatique.com.
16.255.42.188.in-addr.arpa domain name pointer aimless.jeune-asiatique.com.
17.255.42.188.in-addr.arpa domain name pointer airbrake.jeune-asiatique.com.
18.255.42.188.in-addr.arpa domain name pointer airman.jeune-asiatique.com.
19.255.42.188.in-addr.arpa domain name pointer airstrike.jeune-asiatique.com.
20.255.42.188.in-addr.arpa domain name pointer ammeter.jeune-asiatique.com.
21.255.42.188.in-addr.arpa domain name pointer amorphous.jeune-asiatique.com.
22.255.42.188.in-addr.arpa domain name pointer amphibian.jeune-asiatique.com.
23.255.42.188.in-addr.arpa domain name pointer anemone.jeune-asiatique.com.
24.255.42.188.in-addr.arpa domain name pointer anomalous.jeune-asiatique.com.
25.255.42.188.in-addr.arpa domain name pointer antidote.jeune-asiatique.com.
26.255.42.188.in-addr.arpa domain name pointer anyplace.jeune-asiatique.com.
27.255.42.188.in-addr.arpa domain name pointer apiece.jeune-asiatique.com.
28.255.42.188.in-addr.arpa domain name pointer appendix.jeune-asiatique.com.
29.255.42.188.in-addr.arpa domain name pointer applaud.jeune-asiatique.com.
30.255.42.188.in-addr.arpa domain name pointer appraisal.jeune-asiatique.com.
31.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-31.server.lu.
32.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-32.server.lu.
33.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-33.server.lu.
34.255.42.188.in-addr.arpa domain name pointer aback.petitsseinsnus.com.
35.255.42.188.in-addr.arpa domain name pointer abed.petitsseinsnus.com.
36.255.42.188.in-addr.arpa domain name pointer aborigine.petitsseinsnus.com.
37.255.42.188.in-addr.arpa domain name pointer absence.petitsseinsnus.com.
38.255.42.188.in-addr.arpa domain name pointer academic.petitsseinsnus.com.
39.255.42.188.in-addr.arpa domain name pointer achy.petitsseinsnus.com.
40.255.42.188.in-addr.arpa domain name pointer acolyte.petitsseinsnus.com.
41.255.42.188.in-addr.arpa domain name pointer additive.petitsseinsnus.com.
42.255.42.188.in-addr.arpa domain name pointer addle.petitsseinsnus.com.
43.255.42.188.in-addr.arpa domain name pointer adhesive.petitsseinsnus.com.
44.255.42.188.in-addr.arpa domain name pointer adjust.petitsseinsnus.com.
45.255.42.188.in-addr.arpa domain name pointer aerate.petitsseinsnus.com.
46.255.42.188.in-addr.arpa domain name pointer aerobic.petitsseinsnus.com.
47.255.42.188.in-addr.arpa domain name pointer agonizing.petitsseinsnus.com.
48.255.42.188.in-addr.arpa domain name pointer aimless.petitsseinsnus.com.
49.255.42.188.in-addr.arpa domain name pointer airbrake.petitsseinsnus.com.
50.255.42.188.in-addr.arpa domain name pointer airman.petitsseinsnus.com.
51.255.42.188.in-addr.arpa domain name pointer airstrike.petitsseinsnus.com.
52.255.42.188.in-addr.arpa domain name pointer ammeter.petitsseinsnus.com.
53.255.42.188.in-addr.arpa domain name pointer amorphous.petitsseinsnus.com.
54.255.42.188.in-addr.arpa domain name pointer amphibian.petitsseinsnus.com.
55.255.42.188.in-addr.arpa domain name pointer anemone.petitsseinsnus.com.
56.255.42.188.in-addr.arpa domain name pointer anomalous.petitsseinsnus.com.
57.255.42.188.in-addr.arpa domain name pointer antidote.petitsseinsnus.com.
58.255.42.188.in-addr.arpa domain name pointer anyplace.petitsseinsnus.com.
59.255.42.188.in-addr.arpa domain name pointer apiece.petitsseinsnus.com.
60.255.42.188.in-addr.arpa domain name pointer appendix.petitsseinsnus.com.
61.255.42.188.in-addr.arpa domain name pointer applaud.petitsseinsnus.com.
62.255.42.188.in-addr.arpa domain name pointer appraisal.petitsseinsnus.com.
63.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-63.server.lu.
64.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-64.server.lu.
65.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-65.server.lu.
66.255.42.188.in-addr.arpa domain name pointer aback.baike3.com.
67.255.42.188.in-addr.arpa domain name pointer abed.baike3.com.
68.255.42.188.in-addr.arpa domain name pointer aborigine.baike3.com.
69.255.42.188.in-addr.arpa domain name pointer absence.baike3.com.
70.255.42.188.in-addr.arpa domain name pointer academic.baike3.com.
71.255.42.188.in-addr.arpa domain name pointer achy.baike3.com.
72.255.42.188.in-addr.arpa domain name pointer acolyte.baike3.com.
73.255.42.188.in-addr.arpa domain name pointer additive.baike3.com.
74.255.42.188.in-addr.arpa domain name pointer addle.baike3.com.
75.255.42.188.in-addr.arpa domain name pointer adhesive.baike3.com.
76.255.42.188.in-addr.arpa domain name pointer adjust.baike3.com.
77.255.42.188.in-addr.arpa domain name pointer aerate.baike3.com.
78.255.42.188.in-addr.arpa domain name pointer aerobic.baike3.com.
79.255.42.188.in-addr.arpa domain name pointer agonizing.baike3.com.
80.255.42.188.in-addr.arpa domain name pointer aimless.baike3.com.
81.255.42.188.in-addr.arpa domain name pointer airbrake.baike3.com.
82.255.42.188.in-addr.arpa domain name pointer airman.baike3.com.
83.255.42.188.in-addr.arpa domain name pointer airstrike.baike3.com.
84.255.42.188.in-addr.arpa domain name pointer ammeter.baike3.com.
85.255.42.188.in-addr.arpa domain name pointer amorphous.baike3.com.
86.255.42.188.in-addr.arpa domain name pointer amphibian.baike3.com.
87.255.42.188.in-addr.arpa domain name pointer anemone.baike3.com.
88.255.42.188.in-addr.arpa domain name pointer anomalous.baike3.com.
89.255.42.188.in-addr.arpa domain name pointer antidote.baike3.com.
90.255.42.188.in-addr.arpa domain name pointer anyplace.baike3.com.
91.255.42.188.in-addr.arpa domain name pointer apiece.baike3.com.
92.255.42.188.in-addr.arpa domain name pointer appendix.baike3.com.
93.255.42.188.in-addr.arpa domain name pointer applaud.baike3.com.
94.255.42.188.in-addr.arpa domain name pointer appraisal.baike3.com.
95.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-95.server.lu.
96.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-96.server.lu.
97.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-97.server.lu.
98.255.42.188.in-addr.arpa domain name pointer aback.7nef.com.
99.255.42.188.in-addr.arpa domain name pointer abed.7nef.com.
100.255.42.188.in-addr.arpa domain name pointer aborigine.7nef.com.
101.255.42.188.in-addr.arpa domain name pointer absence.7nef.com.
102.255.42.188.in-addr.arpa domain name pointer academic.7nef.com.
103.255.42.188.in-addr.arpa domain name pointer achy.7nef.com.
104.255.42.188.in-addr.arpa domain name pointer acolyte.7nef.com.
105.255.42.188.in-addr.arpa domain name pointer additive.7nef.com.
106.255.42.188.in-addr.arpa domain name pointer addle.7nef.com.
107.255.42.188.in-addr.arpa domain name pointer adhesive.7nef.com.
108.255.42.188.in-addr.arpa domain name pointer adjust.7nef.com.
109.255.42.188.in-addr.arpa domain name pointer aerate.7nef.com.
110.255.42.188.in-addr.arpa domain name pointer aerobic.7nef.com.
111.255.42.188.in-addr.arpa domain name pointer agonizing.7nef.com.
112.255.42.188.in-addr.arpa domain name pointer aimless.7nef.com.
113.255.42.188.in-addr.arpa domain name pointer airbrake.7nef.com.
114.255.42.188.in-addr.arpa domain name pointer airman.7nef.com.
115.255.42.188.in-addr.arpa domain name pointer airstrike.7nef.com.
116.255.42.188.in-addr.arpa domain name pointer ammeter.7nef.com.
117.255.42.188.in-addr.arpa domain name pointer amorphous.7nef.com.
118.255.42.188.in-addr.arpa domain name pointer amphibian.7nef.com.
119.255.42.188.in-addr.arpa domain name pointer anemone.7nef.com.
120.255.42.188.in-addr.arpa domain name pointer anomalous.7nef.com.
121.255.42.188.in-addr.arpa domain name pointer antidote.7nef.com.
122.255.42.188.in-addr.arpa domain name pointer anyplace.7nef.com.
123.255.42.188.in-addr.arpa domain name pointer apiece.7nef.com.
124.255.42.188.in-addr.arpa domain name pointer appendix.7nef.com.
125.255.42.188.in-addr.arpa domain name pointer applaud.7nef.com.
126.255.42.188.in-addr.arpa domain name pointer appraisal.7nef.com.
127.255.42.188.in-addr.arpa domain name pointer ip-static-188-42-255-127.server.lu.

@dq ha kiraknad gist-re/pastebinre, akkor automatikusan letoltheto is lenne...

Amugy koszi a tippet, fel is vettem a tartomanyt par kezelt gepre.
--
Ki oda vágyik, hol száll a galamb, elszalasztja a kincset itt alant:


()=() 
('Y') Blog | @hron84
C . C Üzemeltető macik
()_()

Nem kell ehhez pastebin:

188.42.0.0/16 #teljes LU-ROOT-20090427 tartomány

Ha szűkiteni akarsz, akkor:
188.42.252.0/22 # WZSG-1 (Webzilla Singapore Pte Ltd)

Ha még akarsz szűkíteni, akkor (jelenleg) ez a kettő a cimlistak.com/ugyismegveszel.hu spamtartomány:
188.42.252.64/27
188.42.255.0/25

(a többin jellemzően egyéb random spammerek vannak)