Category Archives: MX Alerts

This blog will contain updates on MxToolBox Services including maintenance schedules, upgrades, bug fixes and more. Please follow us on Twitter at http://twitter.com/mxtoolbox

JAMM DNSBL Blacklist Removed

We have received reports that the RBL (Real Time Blacklists) JAMM DNSBL has gone down. We have removed it from our database and no more alerts should be received.

The JAMM DNSBL was a public data base which listed suspected sources of spam which has recently closed its doors. Most RBLS (Real Time Blacklists) when they wish to dissolve will commonly blacklist the entire internet in order to get the attention of those people using them to stop attempting to contact their IPs.

We apologize for any inconvenience this may have caused, please let us know if you have any other questions or concerns.

http://www.jammconsulting.com/policies/dnsbl.shtml

MxToolBox is not affiliated with any Blacklists, we just provide a public tool that can be utilized to see if you are on a Blacklist. If you are on a Blacklist, rest assured as we do offer Blacklist Protection! For more information please feel free to visit our website or email us at info@mxtoolbox.com.

We’re always looking for new Blacklists to add, so if you want to suggest one to us, please send an email to support@mxtoolbox.com.

For information about other Blacklists that have shut down or Blacklists that are having problems, view this forum post.

TQMCUBE Blacklist Removed

We have received reports that the RBL (Real Time Blacklists) TQMCUBE went down. We have removed it from our database and no more alerts should be received.

The TQMCUBE was an open relay data base which listed open relays which has recently closed its doors. Most RBLS (Real Time Blacklists)
when they wish to dissolve will commonly blacklist the entire internet
in order to get the attention of those people using them to stop
attempting to contact their IPs.

MxToolBox is not affiliated with any Blacklists, we just provide a public tool that can be utilized to see if you are on a Blacklist. If you are on a Blacklist, rest assured as we do offer Blacklist Protection! For more information please feel free to visit our website or email us at info@mxtoolbox.com.

We’re always looking for new Blacklists to add, so if you want to suggest one to us, please send an email to support@mxtoolbox.com.

For information about other Blacklists that have shut down or Blacklists that are having problems, view this forum post.

Informationwave Blacklist Removed

We received reports last night that the RBL (Real Time Blacklists) InformationWave went down. We have removed it from our database and no more alerts should be received.

The Informationwave was an open relay data base which listed open relays which has recently closed its doors. Most RBLS (Real Time Blacklists)
when they wish to dissolve will commonly blacklist the entire internet
in order to get the attention of those people using them to stop
attempting to contact their IPs.

MxToolBox is not affiliated with any Blacklists, we just provide a public tool that can be utilized to see if you are on a Blacklist. If you are on a Blacklist, rest assured as we do offer Blacklist Protection! For more information please feel free to visit our website or email us at info@mxtoolbox.com.

We’re always looking for new Blacklists to add, so if you want to suggest one to us, please send an email to support@mxtoolbox.com.

For information about other Blacklists that have shut down or Blacklists that are having problems, view this forum post.

Fixing ORDB Blacklist (ordb.org) Bounce Back Problems – Exchange

If you are encountering problems with mail referencing
ORDB.org on your Microsoft Exchange 2003 or 2007 server, or mail being blocked with a return message stating that the
sender’s IP was on relays.ordb.org, please ensure that you do not have
relays.ordb.org entry configured in the IMF settings. You MUST restart the SMTP Virtual Server to release this setting.

microsoft exchange ordb removal 

The ORDB was an open relay data base which listed open relays which has recently closed its doors. Most RBLS (real time blacklists) when they wish to dissolve will commonly blacklist the entire internet in order to get the attention of those people using them to stop attempting to contact their IPs.

For more information please see the ORDB Problems page on our support site.
 

Starloop Blacklist

We have disabled lookups to the STARLOOP Blacklist. Our lookup tool is not checking Starloop as of 9 AM CST 9/10/07.Starloop began listing all IP Addresses sometime late Sunday evening. These listings are false positives. The Starloop website is down and the blacklist is now timing out. If you experience bounce backs as a result of a recipient system using Starloop, your best course of action is to contact the recipient email team and inform them that Starloop is not a current, working RBL.


We will monitor the sitatution and post any updates here.  

FLOWGO Goes Away

The FLOWGO RBL has gone offline. As a result all IP Addresses are now “listed.” Anyone who is using FLOWGO as an anti-spam measure on their server should remove it. If you receive a bounce message saying your mail was rejected due to listing on FLOWGO, please contact the recipient email administrator and advise them that FLOWGO is now offline.


We have removed FLOWGO from our lookup tool as of 7:30 AM CST. However, after FLOWGO went offline sometime lastnight, our server monitoring tool sent out noticies to roughly 1000 of our monitoring customers. If you received one of these alerts, you can disregard it. 


   

How Legitimate IP Addresses Get Blacklisted

“I’m Not a Spammer, so why is my IP Address Blacklisted?”


Everyday, legitimate email users find their outbound email flow blocked by recipient email servers using blacklists (aka Blocklists, RBLs) to block spam. Most of these users are shocked to find their IP Addresses on a list with IP Addresses used to flood the world’s inboxes with spam and malware. The news of their listing stirs up fear, anger, and righteous indignation. “How can we be on a blacklist when we don’t spam?” they ask. That is a great question–how do business email IP Addresses operated by non-spammers get placed on legitimate, targeted spam blacklists (i.e. blacklists that list IP Addresses that have recently sent spam, instead of lists that include large ranges of IP Addresses by default)? Simple…by spamming.


“What,” you ask, “A non-spammer that doesn’t spam gets listed on a spam blacklist for spamming?” Yes. For several years, spammers have hijacked mail servers and other computers to send spam. The spammer’s strategy has always been to find a quiet, undefended place on a network where they can send spam and perform other illicit acts without detection. A recent example from one of our clients provides a real life illustration of how this works.


Spammers Hide Clever Tools Where You Least Expect


This particular client (who will remain un-named) runs an email server, as well as an internal document server. They utilize an enterprise-grade email spam and virus filter for security and are relatively proactive in managing their network for security risks. Despite these efforts, a spammer was able to download a mass mailer program onto the client’s document server. How the spammer bypassed the client’s security is a question that remains unanswered. The payload was most likely delivered via a malware infected website. In this case a simple anti virus software solution that stops executable programs from loading without administration permissions would have stopped it, but the document server had no anti virus services running at all. What is most important to note, though, is where the spammer put the program and what the program did.


The program was a modified commercial mass mailing program know as Advanced Mass Sender 4.3 (published by KBB Software. This screenshot was forwarded to us after our client discovered the program on the document server:


Botnet Mass Mailer Screenshot


The program is touted as a powerful email marketing tool that is developed to manage and send mass quantities of email to a large number of clients, quickly and affordably. The program’s features include:



  • Built-in SMTP server, powerful, supporting packet-sending emails without using the SMTP server of your provider allows you do send up to 500 emails a minute using a modem. The unique ability to send through several SMTP servers simultaneously allows you to send up to 1500 emails a minute using a fast connection.


  • Support for large sender lists – 200000+ addresses per group.


  • Support for proxy servers.

The spammer managed to download the program onto a document server, a machine with no SMTP capabilities that most network administrators would not associate with email. But, because the program has a built-in SMTP, the spammer was able to send a high volume of spam from the server–40,000 messages in total at a rate of 1,500 per minute. (note: these volumes indicate that the perpetrator was not particularly sophisticated when compared to other bot herders. Most spammers today prefer to send low volumes of messages from multiple machines to avoid detection).


The Fallout from Hosting a Spammer


The client’s public IP address was blacklisted instantly on five widely used blacklists. Fortunately, we handle the client’s outbound mail flow through or secured connections so the backlist listings did not effect their ability to send email. Had they been sending outbound email from their own IP address, most major ISP’s and many business mail servers would have blocked their email. And, if their local service provider would have seen the traffic coming off of his network they likely would have stopped all SMTP traffic, causing catastrophic email failure.


This particular client is proactive and technologically savvy, so they quickly determined that something was not right on their network, found the problem and terminated it. But, what if they had not been so fast? What if they did not use our outbound mail filtering service? The consequences could have been devastating. Not only would they have inadvertently contributed to the global spam scourge, they would have suffered extreme email failure due to large scale listings on blacklists.


How to Protect Yourself


There are several lessons you should take from this study:


1) Spammers can use any part of your network that is connected to the internet to send spam, whether it is part of your email system or not.


2) Even well defended networks can fall victim, which is why you have to move from a well-defended network to an extraordinarily well-defended network. Block threats from all potential entry points, instead            of the most common entry points.


3) Constantly monitor your network for intrusions and infections


This case certainly does not resemble every bot infection, but is a real-world illustration of how an infection can occur.