The IP **.**.**.*** was detected most recently at:
2008:12:13 ~10:30 UTC+/- 15 minutes (approximately 6 hours, 30 minutes ago)
sending email in such a way as to strongly indicate that the IP itself
was operating an open http or socks proxy, or a trojan spam package.
You will need to examine the machine for a spam trojan or open
proxy. Up-to-date anti-virus tools are essential.
If the IP is a NAT firewall, we strongly recommend configuring the
firewall to prevent machines on your network connecting to the Internet
on port 25, except for machines that are supposed to be mail servers.
Useful links:
FTC - SPAM - Operation Secure Your Server Spam Links - the anti-spam portal (see "Securing your System" and "proxies")
Spam Links - securing systems
For more information on securing NAT firewalls/gateways, please
see
NATs
Note: **.***.*.*** appeared to be suspicious because it was using the
following name to identify itself during email (port 25) connections
via the SMTP HELO/EHLO commands:
client-***-*-***-**.reverse.ni.net.tr
This MAY have been spamware, or it would be a misconfiguration
in your mail server. The CBL attempts to distinguish real mail
server software from malware SMTP clients by expecting users
to name their mail server[s] to indicate who _they_ are, not
some random home PC in a generic end-user pool that's probably
infected.
By causing your mail server to claim to be, for example,
mail.<your domain>
Chances are you won't be relisted.
If you're running Qmail, please see:
Qmail Issues
I've removed the entry from the list.
It may take a few hours to propogate to the public nameservers.
WARNING: the CBL WILL relist this IP if the underlying issues are not
resolved, and the CBL detects the same thing again.
--
Jay, CBL Team