Received 32,000 and counting Spam Email from postino1.discountasp.net - Please Help

Discussion in 'Email' started by Ex-designz, May 15, 2011.

Thread Status:
Threads that have been inactive for 5 years or longer are closed to further replies. Please start a new thread.
  1. Hi Support,

    Spam Email Coming from One of the website hosted by Discountasp.net. Can someone please find out why I kept getting the email. I disabled the send email script from my website and still getting email.

    I received another 2,000 email and counting every few minutes.Looks like one of the site hosted on the server got exploit.

    From [email protected] Sun May 15 23:17:22 2011
    X-Apparently-To: [email protected] via 98.138.90.190; Sun, 15 May 2011 16:17:42 -0700
    Return-Path: <[email protected]>
    X-YahooFilteredBulk: 216.32.60.20
    Received-SPF: neutral (mta1249.mail.mud.yahoo.com: domain of [email protected] is neutral about designating 216.32.60.20 as permitted sender)
    X-YMailISG: zBieBo8cZAoZnvxiRknuQvtSe3YYdiH.X.2JWU7A0KkSzs2r
    WvNIjVKguAJAAprKd0syBPZ.p844nnUuSoAdebpJ1IXPEpZZqsE3Wu8ZYJTa
    ujke5HYaxqIMAbDZUM144H2gyrzs.abtQhojR1FEHU9JEKglerN6kfejUPJN
    4PwlZyGoIyCxcjmX0YRRa2TejuSs33Np6AVcu.ymF2pzIzJgi1xu2cX4D3fK
    mMpNrizZsRLtubO1gg4uzv7yVmeOEoDKa0BrKSYjY4r9PcNwo.Ad5U4NZHgb
    2Py52C4tG4PZJLRGmUQhineM5TJNtjpmKLGxZCEVBOpVR5aynRnYCPC.iu3n
    tCUhgO27VCm4aTOBFdmgek8ElaSMje3qBp3xoqIwphFYeJEeuARyNlg5Gni8
    aGwAhfNZUdYcatbaKJLdS_t4WJ_Th2_f3AAFhyIrEyTYhpEAcHfLf12tz6GA
    dU3B8wBTCsR3Df_VD4q4iGDu0c.EL18OkcIYi6rGtLgjSEu4I9SENLNY4Mca
    .hE5bCw5LrC_7ECPBNriIaP0y7ogEprFrE1pJOSBz8uOuJM2.0n7dEjKx6s4
    M9icrN8_gzaTaxfLRSGEiO1zP.hFLHwYFJ05WdOEs7Or1o_OiuBz2F99opt0
    j0mFElJ_Up5s8oGBjKAVJUT9cyR5I5b9UDaDwudG_psZINkDHNGmFym.VzS0
    G1LUkZ0AEVn9Mc08rWjKkBPP6AY_qhK9SXuxjH6WxbUpsMx419nsuIg1eNA5
    cz8rD8AgFp4zNMkR8wKpaKo4iRFxuqapUCOdUsemVGziZZx7D6ljliziSFFx
    HLZ06nwj93bd_tCGb_O1x9uE.mzFcAli4XsXnyiPsZ8tTjAtuosHRhO.R8N5
    H0LPjDLHrnUJDOmV9aI4hHeJbDHv3fVRxwZPtLnLLxdxkb7atMEf6Sb4pijH
    ZCMQuIX7xg22wisnjhYUyGkbt1gvqMKvt9Rznv0E9NqhEccu7emlIafhdg8B
    9d164SVL6CC_h2iaqN638gwJJFfH.SRLXwD8a4Jipc1U.1jIqGEZxx0VeKmv
    cwfkA9sEIWhlSFStHnechfO3zXMnewvdjVyYUq0GqNm_MYV3Pw136AwO9JD1
    XQoSUldIIqlD2pAvDa.Z8hOoDXXf
    X-Originating-IP: [216.32.60.20]
    Authentication-Results: mta1249.mail.mud.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=neutral (no sig)
    Received: from 127.0.0.1 (EHLO postino1.discountasp.net) (216.32.60.20)
    by mta1249.mail.mud.yahoo.com with SMTP; Sun, 15 May 2011 16:17:42 -0700
    Received: from web120.dotnetplayground.com [192.168.100.90] by postino1.discountasp.net with SMTP;
    Sun, 15 May 2011 16:17:22 -0700
    Received: from web120 ([127.0.0.1]) by web120.discountasp.net with Microsoft SMTPSVC(6.0.3790.4675);
    Sun, 15 May 2011 16:17:22 -0700
    thread-index: AcwTVj5PrO2uWza/SjukmDEC+FsWkw==
    Thread-Topic: John has emailed you an article
    From: <[email protected]>
    To: <[email protected]>
    Subject: John has emailed you an article
    Date: Sun, 15 May 2011 16:17:22 -0700
    Message-ID: <[email protected]>
    MIME-Version: 1.0
    Content-Type: text/plain;
    charset="iso-8859-1"
    Content-Transfer-Encoding: 7bit
    X-Mailer: Microsoft CDO for Windows 2000
    Content-Class: urn:content-classes:message
    Importance: normal
    Priority: normal
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4721
    Return-Path: [email protected]
    X-OriginalArrivalTime: 15 May 2011 23:17:22.0058 (UTC) FILETIME=[3E5206A0:01CC1356]
    Content-Length: 1302

    Regards,
    Dexter
     
  2. It seems like dotnetplayground still live and sending me thousands of spam email. The message-ID says (0BA5A88B8C5F47FFB886ED52EF568090@dotnetplayground .com)

    I just configured my Yahoo mail filtered and add the returned email to the spam filter. So far work but, this is not good.

    Dexter
     
  3. Bruce

    Bruce DiscountASP.NET Staff

    it looks like one of our customer's web application is compromised and hacker put some mass mailing script there. our admins are aware of this problem and are working on it.
     
Thread Status:
Threads that have been inactive for 5 years or longer are closed to further replies. Please start a new thread.

Share This Page