×

Loading...
Ad by
  • 推荐 OXIO 加拿大高速网络,最低月费仅$40. 使用推荐码 RCR37MB 可获得一个月的免费服务
Ad by
  • 推荐 OXIO 加拿大高速网络,最低月费仅$40. 使用推荐码 RCR37MB 可获得一个月的免费服务

Need your response

Hi all,

Till now I have sent you about 5 emails. But not all of you have received it. I attached the message I sent out before at the end of the email.

It seems that Chinese version hotmail and email with domain .cn doesn't work very well. It may caused by chi gov internet firewall.

If you have such email, please let me know, you'd better change it. Since there still 2 month to the sensitive date.

Always some people are than others. From my statistics, there are 12 people login and changed their password in the Linux server. If you do received my email, do two things please:

1. Check the content of this email, if you received email contain the same content. And, send an email to me, just let me know you have receive all my email i sent to you before. This is to confirm that your email works.
2. Login to the linux server and change ur password.

Since this is public forum, I prefer to get in touch with you then send u the message I sent before(if u didn't received any).
Report

Replies, comments and Discussions:

  • 工作学习 / IT技术讨论 / Unix server problem, need help
    本文发表在 rolia.net 枫下论坛最近受到一种叫W32.Sircam.Worm的病毒的攻击。
    此君很有意思,变换着地址给我的各种EMAIL地址发信,
    因为服务器设置成所有 xxxx@mydomain.com的信,如果没有设帐号就发到默认信箱,所以我每天大概可以受到几十封这个病毒的email, 一般是个附件,附件是 .pif 或者是.zip ,从来没敢打开过,有一次好奇想看看到底是什么,查了下属性,我的病毒防火墙就报警了。

    应该不是我自己发出去的,因为收件人的地址都是每次不同的,好象针对我的域名一样。

    有时候还可以收到来自其他服务器的退信说明,好象也是以我的名义发的,结果有病毒,被退回。
    注:mydomain为我实际域名
    我用的服务器装的是qmail + vPopmail
    是服务器中了病毒吗?linux的病毒?还是有人在专门攻击我?
    谢谢!!!

    Header:
    MAILFROM: helina.hao@mydomain.com
    Received: from unknown (HELO impextransport.com) (61.219.209.162)
    by 0 (qmail 1.03 + ejcp v14) with SMTP;
    9 Apr 2004 02:44:34 -0700
    From: helina.hao@mydomain.com
    To: account.chi@impextransport.com
    Subject: Re: Important document
    Date: Fri, 9 Apr 2004 17:46:17 +0800
    MIME-Version: 1.0
    Content-Type: multipart/mixed;
    boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
    X-Priority: 3
    X-MSMail-Priority: Normal更多精彩文章及讨论,请光临枫下论坛 rolia.net
    • 有时候还可以收到来自其他服务器的退信说明,好象也是以我的名义发的,结果有病毒,被退回。 注:mydomain为我实际域名 Because some ISP SMTP does "open relay", the SMTP server doesn't check if the sender is real sender.
    • There are not too many Linux virus. what email did you use when you register domain name?
      • actually, I use my Yahoo mailbox when I register mydomain.com.
      • 哦,对了,647i大侠,办的linux 技术讨论组的事怎么样了?什么时候开课,我还等着学呢。
    • 可能是他自己的smtp发的或者是象楼上的一样, 其他的smtp server relay了, 或者没有身份验证就发了....我的email地址也常常收到退信...和你的情况一样...一般来说, 即使有病毒, 你查你的smtp的log应该能看到有没有异常
      • remember, any time when you host a smtp server. use authrization method to valid if the sender is your register user. Or somebody will use your server to send junk mail. will you be happy your smtp server are very busy?
        • 实际上,当我试图用mail.mydomain.com来当smtp server的时候,根本就发不出去,连接总是失败,所以我从来不用我的domain做SMTP,可能我们的配置已经把SMTP给限制了。
          • 如果你的log文件没有异常...多半是人家架了server冒你名往外发的, 没关系... 天要下雨
            • 很佩服他这种锲而不舍的精神,哈哈……可以长年累月的发,而且还都是以我自己网站的名义给我发,有的时候,还警告我一下,信的内容从来没一样过。有的时候病毒还冒充是退信。但判断好象是国人干的,因为有的时候退信来自sina
      • smtp server without authrization will be block by other ISP(black list). Then email send from this domain can't be receive by user in other domain. Like sina and some china ISP email before.
        • maybe....但是前不久我还用自己的smtp.(没有验证, 仅仅限制了ip)发出去不少信...所有的isp或者邮件服务提供商都不能够100%限制这种邮件呀
          • not really, for qmail, there is auth extension. check this link http://www.cuni.cz/~vhor/qmail/smtpauth-en.html
          • this link give better explaination about SMTP AUTH. http://members.elysium.pl/brush/smtp-auth/index.html
    • 有没有其他和我一样对UNIX是菜鸟一个,但却非常想学的同学?大家组织个GROUP一起交流一下吧。伪劣和647i可以给大家当Tutor,哈哈……
      • 我也是菜鸟...不过, 以前自己试着做免费邮件提供者的时候, 弄的基于NT或者linux的smtp服务器曾经被人利用过, 长了点实践经验...
      • 这个是647i大侠想免费给大家培训的帖子:(注意:不是商业广告,人家是FREE的,就是想以UNIX会友)//我认为这是对于我这样的有兴趣却没钱参加正规培训的菜鸟的一个很好的办法。难得有这样的热心人。
        本文发表在 rolia.net 枫下论坛***************
        关于UNIX程序员交流(提供免费培训)的说明

        这几天陆续收到一些朋友的EMAIL.对大家在EMAIL里提到的一些问题,
        现一并答复如下并欢迎有兴趣的朋友继续和我联系:

        一. 举办这次UNIX培训目的:
        1. 为对UNIX感兴趣的朋友提供一个认识和学习UNIX的机会( 知识和操作并重 )
        2. 能顺利完成的朋友可以选择将来推出的更深入的培训(shell script, database ....).

        二.几点说明及具体培训安排
        1. 为使本次培训更有条理,本次培训暂定位于基本UNIX的操作和命令的使用.(不涉及高级的程序技巧.高级的编程将在以后推出)
        2. 此培训纯属我个人行为,一切与培训有关的内容(软件,使用服务器等)均****免费******,因此将无法提供认证,文凭,更没有loan和助学金(^v^).

        三.学习方式:
        1. 培训基于INTERNET. (你可以住在任何地方)
        2. 培训设计为6周.
        3. 培训的时间安排/方式:
        自主阅读: 30% 本培训网站提供阅读材料
        上机练习: 40% 通过Internet(ssh)提供24HOUR
        assignment: 20% 网站/Email
        答疑: 10% Email/Yahoo Messenger/ talk(chat utility in Unix)
        4. 培训环境及要求: 有计算机及能够上网.
        5. 培训语言: 英语.
        5. 报名方式:
        来信写出你的:
        姓名(必填)
        年龄(可选)
        性别(可选)
        Email(必填)
        电话(可选)
        身份(PR or citizenship,学生) (必填)
        国内和加拿大所学的专业(可选)
        现在工作还是学习(可选)
        你的userid将以你的姓名命名,我将通过Email将userid和passwd发送给你.
        6. 联系方式:
        Email: systemdevelopermtl@yahoo.ca (不是.com, 我会在24尽快给你回信)
        Yahoo Messenger: systemdevelopermtl (我在办公室和家里都会开着. 如果状态是IDLE说明我不在电脑边或正在忙)
        7. 报名之后:
        我会提供培训网址及你所需要安装的软件(客户端,供远程登陆用)
        8. 培训开始日期:
        待定. 介于12 至17日间.
        9.结业考核(培训结束时会安排一个测验)

        四.有其他问题的朋友可以继续发EMAIL与我联系,我会尽快答复更多精彩文章及讨论,请光临枫下论坛 rolia.net
        • Need your response
          Hi all,

          Till now I have sent you about 5 emails. But not all of you have received it. I attached the message I sent out before at the end of the email.

          It seems that Chinese version hotmail and email with domain .cn doesn't work very well. It may caused by chi gov internet firewall.

          If you have such email, please let me know, you'd better change it. Since there still 2 month to the sensitive date.

          Always some people are than others. From my statistics, there are 12 people login and changed their password in the Linux server. If you do received my email, do two things please:

          1. Check the content of this email, if you received email contain the same content. And, send an email to me, just let me know you have receive all my email i sent to you before. This is to confirm that your email works.
          2. Login to the linux server and change ur password.

          Since this is public forum, I prefer to get in touch with you then send u the message I sent before(if u didn't received any).
          • Well I haven't receive some people's response. Most case, their email doesn't work recently. Here I give the list of the name and email(without the email domain). Hope you can see it if you write to me before:
            Well I haven't receive some people's response. Most case, their email doesn't work recently. Here I give the list of the name and email(without the email domain). Hope you can see it if you write to me before:



            Zhengdong zhu zdzzd2005@
            hui bo.hui@
            Ren dajiaxiao@
            Lai dancy1800@
            Chen chinmason@
            Li cnbullet@
            Wang wjjerry2003@
            Xu jessicaxu007@
            YuFeng wendy wendyjiang2003@
            Hu Ken kenhuban@
            Jiang sapr3ts@
            Gao Gaodu@
            Shi philipshi@
            lei robin_lei2002@
            Wang macsymxinwang@
            tony dldingjun@
            Shi Zhen shizn72@
            Huang cfrtopjoy@
            Cai caiyuanqi@
            Li mis_lee@
            wang zhongw2003@
    • i use qmail as well, recommand you install a mail virus filter gateway, like mailsecurity of gfi.
    • 其实这是很简单的事。你的机器没有病毒,
      只不过Inernet上某些中毒的机器用你的domain作为sender的domain到处传播病毒,而相当一部分recipient不存在,所以你就收到退信了。为什么你的domain被选中呢?其实这是随机的。对于写病毒的人来说,只要这些退信不退回给他们自己就行,因此在选sender的email地址时,他们会随机选一个,可以从中毒机器的address book里选,也可以自己随便产生一个。可能刚好中毒机器的address book里有你的email地址,所以你就撞大运了。
      • 恩,有道理,看来也没有其他的办法,只能力求自保了。