LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-22-2012, 02:39 AM   #1
jsaravana87
Member
 
Registered: Aug 2011
Location: Chennai,India
Distribution: Redhat,Centos,Ubuntu,Dedian
Posts: 558
Blog Entries: 5

Rep: Reputation: Disabled
Ipaddess is frequently getting into spamhaus blacklist in mxtool box


Dear All.

Quote:
i have a firewall interface interface ex 1.2.3.4 . Inside the firewall i have aroung 300 linux user with ubuntu 10.04 and centos 5.4. They have been using sendmail to send mail to there user account to test there project.But everyday my firewall interface ipaddress is getting into blacklist and everyday i have to clear my firewall interface ipaddress from blacklist in mxtoolbox.
Quote:
Since inside the firewall interface we had blocked gmail access .so i could int able use gmail smtp to send mail to outside world.
Can anyone advise me how can i send mail to outside word without getting spamhaus

Last edited by jsaravana87; 05-22-2012 at 02:45 AM.
 
Old 05-22-2012, 02:54 AM   #2
descendant_command
Senior Member
 
Registered: Mar 2012
Posts: 1,876

Rep: Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643
Maybe try not sending spam?

But seriously, what list do you 'keep getting on' and what is the reason given?
Once you know what the problem is, it is a lot easier to solve.
 
Old 05-22-2012, 04:39 AM   #3
jsaravana87
Member
 
Registered: Aug 2011
Location: Chennai,India
Distribution: Redhat,Centos,Ubuntu,Dedian
Posts: 558

Original Poster
Blog Entries: 5

Rep: Reputation: Disabled
MX TOOL BOX. i use diagnostic options to diagnotic the blocklisterror .it show as follow

Quote:
220 mail-desktop ESMTP Postfix (Ubuntu) (it shows my local machine inside our firewall interface causing these problem)
Status Result
OK - 1.2.3.4 resolves to domainname
Warning - Reverse DNS does not match SMTP Banner
OK - Supports TLS.
0 seconds - Good on Connection time
OK - Not an open relay.
3.635 seconds - Good on Transaction Time
Session Transcript:
EHLO please-read-policy.mxtoolbox.com
250-siva-desktop
250-PIPELINING
250-SIZE 10240000
250-VRFY
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN [265 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Ok [312 ms]
RCPT TO: <test@example.com>
554 5.7.1 <test@example.com>: Relay access denied [281 ms]
QUIT
221 2.0.0 Bye [265 ms]
 
Old 05-22-2012, 05:10 AM   #4
descendant_command
Senior Member
 
Registered: Mar 2012
Posts: 1,876

Rep: Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643
All good.
This
Quote:
Originally Posted by arun5002 View Post
Warning - Reverse DNS does not match SMTP Banner
is not a showstopper but some (very few really) servers will reject based on this.

You need to do the blacklist report, then go to the sites that are listing you and find the reason.
 
Old 05-22-2012, 07:29 AM   #5
dinakumar12
Member
 
Registered: Mar 2010
Location: INDIA (chennai)
Distribution: centos
Posts: 271
Blog Entries: 7

Rep: Reputation: 18
Hi,

As stated find the reason for why your ip blacklisted.Its better to use two static ip addresses in firewall one for browsing and another for mail purpose.
 
Old 05-23-2012, 01:42 AM   #6
jsaravana87
Member
 
Registered: Aug 2011
Location: Chennai,India
Distribution: Redhat,Centos,Ubuntu,Dedian
Posts: 558

Original Poster
Blog Entries: 5

Rep: Reputation: Disabled
Hi
when i checked out the cause of blacklisting it shows sue to heloing as localhost.localdomain ,Can anyone help wat its means


At the time of removal, this was the explanation for this listing:
Quote:
This IP address is HELO'ing as "localhost.localdomain" which violates the relevant standards (specifically: RFC5321).
The CBL does not list for RFC violations per-se. This _particular_ behaviour, however, correlates strongly to spambot infections. In other words, out of thousands upon thousands of IP addresses HELO'ing this way, all but a handful are infected and spewing junk. Even if it isn't an infection, it's a misconfiguration that should be fixed, because many spam filtering mechanisms operate with the same rules, and it's best to fix it regardless of whether the CBL notices it or not.

DO NOT TELNET TO YOUR SERVER TO SEE WHAT IT SAYS. Telnet will show you the banner, not the HELO.

EVEN IF YOU TEST YOUR MAIL SERVER SOFTWARE AND IT HELOS PROPERLY, THAT DOES NOT MEAN THAT THIS LISTING IS IN ERROR - YOUR IP REALLY DID HELO AS "localhost.localdomain". Our system doesn't make mistakes about this. This just means that something OTHER than your mail server software is making the connections. In fact,
Quote:
finding that your mail server is NOT HELO'ing as "localhost.localdomain" essentially proves this is an infection, not a misconfiguration.
There is often confusion between the SMTP "banner" and the SMTP "HELO" (or EHLO) command. These are completely different things, and proper understanding is important.

First some terminology (somewhat simplified to aid understanding):

A "SMTP client" is a piece of software that makes SMTP connections to SMTP servers to send a piece of email to the server. Most E-mail servers consist of an "SMTP listener" (to listen for and handle connections made to them by SMTP clients), an SMTP client (to send emails to other mail servers) and a local delivery agent (LDA) to deliver email to "local" users (eg: via POP or IMAP).

Thus, SMTP clients make connections to SMTP listeners, and issue SMTP commands to the listener.

The "HELO" (or "EHLO") command (see RFC2821) is a command issued by the SMTP client to an SMTP server to identify the name of the client. "HELO mail.example.com" means, essentially, "Hi there, my name is mail.example.com".

The "SMTP banner" is what the listener says in response the initial connection or in response to the HELO command.

The CBL works in many cases by seeing what SMTP clients say (in the HELO/EHLO command) when the client connects to a CBL detector. Since the CBL NEVER does SMTP probes, it has no way of knowing how a given IP banners.

You can test SMTP banners with telnet and other similar diagnostic tools, but you CANNOT test SMTP HELO/EHLO with telnet.

For that, you can send an email to helocheck@cbl.abuseat.org. That will reject the email (as an error), and the error will show you what the HELO/EHLO was.

If this IP is a mail server: please read namingproblems to find out why your IP was listed, and ways to fix it so it doesn't relist.

This IP is infected (or NATting for a computer that is infected) with a spam-sending infection. In other words, it's participating in a botnet. If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.
 
Old 05-23-2012, 04:03 AM   #7
descendant_command
Senior Member
 
Registered: Mar 2012
Posts: 1,876

Rep: Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643
Well there's ya problem ...
Fix your HELO
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Spamhaus PBL carlosinfl Linux - Server 3 10-25-2010 04:31 AM
Spamhaus Question carlosinfl Linux - Server 5 10-01-2008 03:01 PM
spamhaus/cbl keep blocking my ip! efm Linux - Networking 5 01-10-2007 12:40 AM
?Odd bug. modprobe.blacklist~ behaves as modprobe.blacklist arubin Slackware 1 11-05-2006 07:08 PM
rblsmtpd & spamhaus.org ziggie216 Linux - General 1 12-19-2005 12:14 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration