Displaying 1 result from an estimated 1 matches for "r95ehqoc006972".
2013 Oct 05
2
SMTP Auth Spam Mail Attack
...5 15:17:53 www sendmail[6972]: AUTH=server,
relay=pppoe9.net109-120-27.se1.omkc.ru [109.120.27.9] (may be forged),
authid=jon, mech=LOGIN, bits=0
This then seemingly passes the AUTH for the user jon and allows the system
to send e-mails such as the following.
Oct 5 15:17:58 www sendmail[6982]: r95EHqoc006972:
to=<qqueenllouise at aol.com>, ctladdr=<jon at xxxxxxxx.co.uk> (516/100),
delay=00:00:05, xdelay=00:00:02, mailer=esmtp, pri=300552,
relay=mailin-03.mx.aol.com. [205.188.156.193], dsn=2.0.0, stat=Sent (2.0.0
Ok: queued as B648F3800008D)
Now there seem to be 2 user names that appear in...