View Full Version : Domain spoofing
duzap
11-04-2007, 02:28 PM
tactical-ops.co.il is my domain.
someone spoofed my domain name and used it to send phishing messages.
it happened by vulnerability that i had in my webserver files (some vulnerable php pages)
I think I have solved this problem, I hope these phishing mails won't come again from my domain, too bad it added my domain/server ip to the mailspam list.
do you know how can I remove it from the list? I didnt know about these emails before... (btw I found this message from google)
Miyuki
11-04-2007, 10:00 PM
Hello duzap, We'll see if we can find an answer for you. It is unfortunately true that scammers not only steal money, they steal service and names etc. of innocent people as well. They could potentially ruin the internet for all of us.
Gordon
11-05-2007, 03:49 PM
tactical-ops.co.il is my domain.
someone spoofed my domain name and used it to send phishing messages.
it happened by vulnerability that i had in my webserver files (some vulnerable php pages)
I think I have solved this problem, I hope these phishing mails won't come again from my domain, too bad it added my domain/server ip to the mailspam list.
do you know how can I remove it from the list? I didnt know about these emails before... (btw I found this message from google)
Hi - Yes that can happen when there is a old written type of program on your web host, or you gave some one log in info to install something for you, and then they left their little trojan program behind to send mail through. An old PHP guest book was another flaw they found to use.
When mails were being sent out in your domain name and IP some of them should have bounced. See if you can locate one or some of the bounced mails. That is where you will find info on how to remove yourself from that list. Maybe go to your control panel and look in your web mail, if you don't have any bounced ones on your POP mail account.
There are several companies that will do that blocking and all you need to know is which one it is by reading one bounced email that tells you that they have placed you into their SPAM system . They have a simple web form to fill out to have yourself removed.
duzap
11-11-2007, 02:30 AM
Hi - Yes that can happen when there is a old written type of program on your web host, or you gave some one log in info to install something for you, and then they left their little trojan program behind to send mail through. An old PHP guest book was another flaw they found to use.
When mails were being sent out in your domain name and IP some of them should have bounced. See if you can locate one or some of the bounced mails. That is where you will find info on how to remove yourself from that list. Maybe go to your control panel and look in your web mail, if you don't have any bounced ones on your POP mail account.
There are several companies that will do that blocking and all you need to know is which one it is by reading one bounced email that tells you that they have placed you into their SPAM system . They have a simple web form to fill out to have yourself removed.
yes I sent mail to "spamhaus.org" before some days but they didnt remove me yet.
and I know how they sent these mails, they used the following vulnerability that I had on my website:
http://www.acunetix.com/vulnerabilities/SQuery-v.4.5--Remote-File.htm
now I removed it and I dont get anymore bounced mails, no more scam messages from my domain :)
I am still waiting for an answer from spamhaus, I dont know whats going on with that :/ I hope they will remove me from their blacklist.
and I got a question: if I send mails to Gmail the mails are coming to "spam" instead of the regular inbox... should I contact Gmail to remove it from their blacklist?
Powered by vBulletin® Version 4.2.0 Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.