The primary mode of support here is peer-to-peer, meaning users helping other users. (please remember this at all times!)
Another try:
This forum is composed of people who have used spamcop and those who are learning about anti-spam efforts.
![]() ![]() |
| RobertBoogaard |
Mar 3 2004, 12:21 PM
Post
#1
|
|
Newbie ![]() Group: Members Posts: 2 Joined: 3-March 04 Member No.: 583 |
My IP has been blocked by SpamCop. I don't send unsolicited email and my service provider said to run a virus scan to make sure my computer is not being used by someone else to send SPAM. This came up clean.
How can I find out why I am blocked and by who, as the link from SpamCop does not provide me with any information? Thanks, Robert PS the message I receive is: Your message did not reach some or all of the intended recipients. Subject: Test Sent: 03/03/2004 15:54 The following recipient(s) could not be reached: 'robert[at]ticketboy-portugal.pt' on 03/03/2004 15:54 550 5.2.1 Mailbox unavailable. Your IP address 213.22.56.30 is blacklisted using SPAMCOP. Details: Blocked - see http://www.spamcop.net/bl.shtml?213.22.56.30. |
| Ellen |
Mar 3 2004, 12:39 PM
Post
#2
|
|
Advanced Member ![]() ![]() ![]() Group: Validating Posts: 497 Joined: 21-January 04 Member No.: 16 |
There is a user reported spam and a spamtrap hit for IP 213.22.56.30 from yesterday. If that IP is specifically yours (static IP) then you may have a worm/trojan infection. The spams appear to be advertising HGH.
-------------------- Ellen
SpamCop deputies <at> admin.spamcop.net Please do not Private Message me. |
| Merlyn |
Mar 3 2004, 12:41 PM
Post
#3
|
|
Been There Group: Memberp Posts: 1653 Joined: 23-January 04 Member No.: 25 |
If you followed the link you would find spam has been reported coming from this IP.
This is also Dynamic/Residential IP range and many ISP's/email administrators will not accept email coming from these servers. This machine is also an open proxy found Wed Mar 3 00:40:02 2004 Spammers are abusing this machine to send spam. 213.22.56.30 is listed as an open proxy in dnsbl.njabl.org. 213.22.56.30 is listed in dynablock.njabl.org. For more info see: http://www.moensted.dk/spam/?addr=213.22.56.30&Submit=Submit Please secure this machine. (IMG:style_emoticons/default/mad.gif) -------------------- Regards,
Merlyn A Spamcop advocate People demand freedom of speech to make up for the freedom of thought which they avoided! |
| RobertBoogaard |
Mar 3 2004, 01:06 PM
Post
#4
|
|
Newbie ![]() Group: Members Posts: 2 Joined: 3-March 04 Member No.: 583 |
Thanks for your replies. Unfortunately I am not a computer wiz so exuse my ignorance.
I have got a cable account from my local cable provider. Does my IP belong solely to my computer or is it general belonging the the cable provider? As I understand it someone is using this IP to send SPAM email, is that right? How can I secure my machine? I use Norton Antivirus and XP Firewall? Thanks for any help. Robert |
| Merlyn |
Mar 3 2004, 01:27 PM
Post
#5
|
|
Been There Group: Memberp Posts: 1653 Joined: 23-January 04 Member No.: 25 |
Just because you use Norton does not mean you cannot get infected.
Port 65506 is open on the machine currently connected to IP 213.22.56.30. Run Live update and scan your entire machine. Enable scri_pt Blocking in Norton Also. -------------------- Regards,
Merlyn A Spamcop advocate People demand freedom of speech to make up for the freedom of thought which they avoided! |
| turetzsr |
Mar 3 2004, 01:40 PM
Post
#6
|
|
T-shirt wearing out Group: Membersph Posts: 3575 Joined: 26-January 04 From: Michigan USA Member No.: 59 |
Hi, Robert,
QUOTE(RobertBoogaard @ Mar 3 2004, 01:06 PM) <snip> I have got a cable account from my local cable provider. Does my IP belong solely to my computer or is it general belonging the the cable provider? As I understand it someone is using this IP to send SPAM email, is that right? ...It appears that the IP address in question belongs to Portugal Cable Modem Network, which I presume is your Cable provider, not you. That means it is their problem, not yours (except that you are suffering from their inability or unwillingness to stop spam from going through their server). E-mails should be going to their abuse address so they should be fully aware of the problem. You may wish to complain to them that you are not getting the e-mail service you contracted for because of their inaction in shutting down the spam. If they will not respond, you should try to find a more responsive provider. ...Good luck! -------------------- ..Regards,
...Steve T ...A Happy SpamCop.net user (not an employee) ...Please avoid replying via e-mail, as it is not secure |
| Spambo |
Mar 3 2004, 02:01 PM
Post
#7
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 293 Joined: 28-January 04 Member No.: 72 |
QUOTE(RobertBoogaard @ Mar 3 2004, 11:21 AM) My IP has been blocked by SpamCop. I don't send unsolicited email and my service provider said to run a virus scan to make sure my computer is not being used by someone else to send SPAM. This came up clean. How can I find out why I am blocked and by who, as the link from SpamCop does not provide me with any information? Thanks, Robert PS the message I receive is: Your message did not reach some or all of the intended recipients. Subject: Test Sent: 03/03/2004 15:54 The following recipient(s) could not be reached: 'robert[at]ticketboy-portugal.pt' on 03/03/2004 15:54 550 5.2.1 Mailbox unavailable. Your IP address 213.22.56.30 is blacklisted using SPAMCOP. Details: Blocked - see http://www.spamcop.net/bl.shtml?213.22.56.30. 213.22.56.30 seems to have an open proxy that spammers are using to hijack the machine in order to hide their true identity. This open proxy was last confirmed on 02 Mar 2004: See: Proxy Test Results for 213.22.56.30 CODE 213.22.56.30:hc:65506: >> CONNECT 209.208.0.16:25 HTTP/1.0\r\n 213.22.56.30:hc:65506: >> \r\n 213.22.56.30:hc:65506: >> help njablproxytest\r\n 213.22.56.30:hc:65506: << HTTP/1.0 200 Connection established\r\n 213.22.56.30:hc:65506: << \r\n 213.22.56.30:hc:65506: HTTP request successeful (200) 213.22.56.30:hc:65506: << 220 rt.njabl.org ESMTP Sendmail 8.11.6/8.11.6; Tue, 2 Mar 2004 18:39:09 -0500\r\n 213.22.56.30:hc:65506: << 214-2.0.0 njabl.org proxytest response to 213.22.56.30\r\n 213.22.56.30:hc:65506: << 214 2.0.0 End of HELP info\r\n 213.22.56.30 hc:65506 open The IP is also listed in the following blocklists according to OpenRBL
-------------------- |
| turetzsr |
Mar 3 2004, 02:03 PM
Post
#8
|
|
T-shirt wearing out Group: Membersph Posts: 3575 Joined: 26-January 04 From: Michigan USA Member No.: 59 |
QUOTE(Spambo @ Mar 3 2004, 02:01 PM) <snip> b]You seriously need to have your computer checked for security issues, it is being used to abuse other people and networks.[/b] ...Why do you say that? The IP in question appears to be the OP's service provider, not the OP her/himself. -------------------- ..Regards,
...Steve T ...A Happy SpamCop.net user (not an employee) ...Please avoid replying via e-mail, as it is not secure |
| yourbuddy |
Mar 3 2004, 02:05 PM
Post
#9
|
|
Advanced Member ![]() ![]() ![]() Group: Banned Posts: 280 Joined: 15-February 04 Member No.: 381 |
Instead of Windows XP Firewall, you migh also want to invest in Norton
Personal Firewall (to also stop the unauthorized traffic from going out). |
| Spambo |
Mar 3 2004, 02:23 PM
Post
#10
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 293 Joined: 28-January 04 Member No.: 72 |
QUOTE(turetzsr @ Mar 3 2004, 01:03 PM) QUOTE(Spambo @ Mar 3 2004, 02:01 PM) <snip> You seriously need to have your computer checked for security issues, it is being used to abuse other people and networks. ...Why do you say that? The IP in question appears to be the OP's service provider, not the OP her/himself. Sorry. Perhaps you can explain why I shouldn't believe Robert? So far I have no reason to think he's been untruthful and the IP is listed on more than one DUL list.. QUOTE(RobertBoogaard @ Mar 3 2004, 12:06 PM) ]I have got a cable account from my local cable provider. Does my IP belong solely to my computer or is it general belonging the the cable provider? -------------------- |
| turetzsr |
Mar 3 2004, 06:03 PM
Post
#11
|
|
T-shirt wearing out Group: Membersph Posts: 3575 Joined: 26-January 04 From: Michigan USA Member No.: 59 |
Hi, Spambo!
QUOTE(Spambo @ Mar 3 2004, 02:23 PM) QUOTE(turetzsr @ Mar 3 2004, 01:03 PM) QUOTE(Spambo @ Mar 3 2004, 02:01 PM) <snip> You seriously need to have your computer checked for security issues, it is being used to abuse other people and networks. ...Why do you say that? The IP in question appears to be the OP's service provider, not the OP her/himself. Sorry. Perhaps you can explain why I shouldn't believe Robert? So far I have no reason to think he's been untruthful and the IP is listed on more than one DUL list.. <snip> ...Sorry, I do not see what I wrote that makes you believe that I said that you should not believe Robert. ...You wrote to him that his PC "is being used to abuse other people and networks." The IP in question (213.22.56.30 ) appears to belong to an ISP, not to Robert. -------------------- ..Regards,
...Steve T ...A Happy SpamCop.net user (not an employee) ...Please avoid replying via e-mail, as it is not secure |
| StevenUnderwood |
Mar 3 2004, 08:10 PM
Post
#12
|
|
What Life? Group: Membersph Posts: 5141 Joined: 20-January 04 From: Whitinsville, MA USA Member No.: 12 |
To me, an address with rDNS of a213-22-56-30.netcabo.pt looks like a client IP of netcabo.pt, which I assume is the OP's address.
-------------------- Steven P. Underwood, DNRC
Whitinsville, MA underwood+forum[at]spamcop.net -No trees were killed in the sending of this message. However, a large number of electrons were terribly inconvenienced.- |
| Spambo |
Mar 3 2004, 08:16 PM
Post
#13
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 293 Joined: 28-January 04 Member No.: 72 |
QUOTE(turetzsr @ Mar 3 2004, 05:03 PM) ...Sorry, I do not see what I wrote that makes you believe that I said that you should not believe Robert. ...You wrote to him that his PC "is being used to abuse other people and networks." The IP in question (213.22.56.30 ) appears to belong to an ISP, not to Robert. 213.22.56.30 [a213-22-56-30.netcabo.pt] appears to be an IP used by netcabo.pt for DHCP assignment to cable modem users. The fact that at least two lists report it as being a "DUL" IP (which by current definitions includes consumer cable modems as well as standard modem connections).reinforces my conclusion. Two other lists reporting it as an open proxy isn't encouraging either. While I can't state with any certainty that his machine owned the "lease" on 213.22.56.30 when the open proxy test was run yesterday (?) or when the spams were actually sent, cable modems tend to keep the same IP for rather long periods periods of time which is one reason that spammers target them for trojan infections Maybe I'm being an "alarmist" but I think there's ample reason he should give serious consideration about ensuring that his machine is secure and trojan free. And it's a win-win situation, if my suspicion is correct then there's one less vulnerable machine for spammers to abuse and if I'm wrong - well, everyone with an always on connection should ensure their machine is secure and occasional "in depth" checks aren't a bad thing. -------------------- |
| turetzsr |
Mar 3 2004, 08:35 PM
Post
#14
|
|
T-shirt wearing out Group: Membersph Posts: 3575 Joined: 26-January 04 From: Michigan USA Member No.: 59 |
QUOTE(Spambo @ Mar 3 2004, 08:16 PM) QUOTE(turetzsr @ Mar 3 2004, 05:03 PM) ...Sorry, I do not see what I wrote that makes you believe that I said that you should not believe Robert. ...You wrote to him that his PC "is being used to abuse other people and networks." The IP in question (213.22.56.30 ) appears to belong to an ISP, not to Robert. 213.22.56.30 [a213-22-56-30.netcabo.pt] appears to be an IP used by netcabo.pt for DHCP assignment to cable modem users. <snip> Hi, Spambo! ...OIC! Thanks for the patient explanation. Man, I learn a lot from my fellow SpamCop users! (IMG:style_emoticons/default/biggrin.gif) -------------------- ..Regards,
...Steve T ...A Happy SpamCop.net user (not an employee) ...Please avoid replying via e-mail, as it is not secure |
| WB8TYW |
Mar 3 2004, 10:14 PM
Post
#15
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 191 Joined: 30-January 04 Member No.: 141 |
Since his ISP was aware of the infection, he should be asking them why they did not take action to limit the damage that the open proxy was doing to him, them and the rest of the internet.
He should be very unhappy that they knew his machine was infected and did not tell him. When a spammer exploits an open proxy on a cable modem, it can use so much of the network capacity that the other cable modem users are either reduced to speeds worse than dial-ups if they do not get knocked off completely. For an ISP to ignore an open proxy and leave it able to send e-mail on the internet costs them hard operating cash. These costs are passed on to their customers one way or another. It is with in the techology of an ISP to lock a cable modem to a DHCP issued address until it is fixed so that they know where the problem is. They can then block that I.P. address from sending out the infection through e-mail while still allowing their customer to download patches and de-worming software from trusted vendors. If they were organized, this could all be automated from the receipt of a spam or open proxy report, which would cause the I.P. address to be scanned for vulnerabilites, and automatically isolated. Some claiming to be from an ISP said that they had implemented a program to read spamcop reports from their mail box to prioritize them to get the open proxies off of their network. They apparently realize that an open proxy is a cash drain on a network. Also be aware that some of the internet connection sharing programs have two passwords, one for local adminstration and one for remote administration. If you do not change the remote password, then every hacker on the internet can use it. -John Personal Opinion Only |
![]() ![]() |
|
Lo-Fi Version | Time is now: 21st November 2009 - 06:41 PM |