One of the users of my mail server reported to me this strange case of spamming, apparently coming from his own address, to somewhere else. He noticed it because the message bounced back at him, since the recipient seems not to be valid.
Here is a copy of the headers of the "spam mail". I'll discuss about it right after.
Note: myuser@rafal-team.net is obviously a false address I replaced, instead of the real one.
Note 2: I also replaced the spam's subject on purpose
Code: Select all
Received: from bos-mail-rmail8.bos.lycos.com (rmail8.lycosmail.lycos.com [209.202.208.28])
by spf7-13.us4.outblaze.com (Postfix) with SMTP id 93F923A33C
for <fluorescentspear@mailcity.com>; Sun, 9 Jul 2006 23:01:54 +0000 (GMT)
Received: from rmail.lycosmail.lycos.com ([83.198.250.124]) by hermes of bos-mail-rmail8.bos.lycos.com (127.0.0.1) with SMTP id a6970Dr1q139164120 for <fluorescentspear@mailcity.com>; Sun, 09 Jul 2006 19:00:13 -0400 (EDT)
Received: from mail.rafal-team.net
by --- (8.13.1/8.13.1) with ESMTP id ASQpQXpzcdMdZ
for <fluorescentspear@mailcity.com>; Jan, 9 Jul 2006 22:58:22 -0300
Received: from [98.25.92.196]
by mail.rafal-team.net with ESMTP (8.13.1/8.13.1) id RE6oaxpyeeYw0
for <fluorescentspear@mailcity.com>; Jan, 9 Jul 2006 22:57:08 -0300
Reply-To: "myuser@rafal-team.net" <myuser@rafal-team.net>
From: "myuser@rafal-team.net" <myuser@rafal-team.net>
Date: Jan, 9 Jul 2006 22:46:37 -0300
Message-ID: fPpFlHxYLoX8E.oukmsu2ciXOdt@rafal-team.net
To: fluorescentspear@mailcity.com
Content-type: text/html;
Charset=Windows-1251
Subject: *insert spammy subject here*
MIME-Version: 1.0
X-Hanmail-Peer-IP: 83.198.250.124
X-Hanmail-Class: X
X-Hanmail-Env-From: myuser@rafal-team.net
X-Hanmail-Checksum: 506-T6ps4o7FoqPsTeiGQXKuh/jxrTY=My server uses qmail and vpopmail for SMTP-Auth, which allows my users to relay mail once they authentificate.
What I have searched for so far:
- Testing if the server is on open-relay: Nope, it isn't.
- Is my user infected by some kind of spamming trojan? Tested, and not infected
- I have not found any mention to a mail to deliver to mailcity.com in qmail logs (I searched in qmail-send logs)
Thanks in advance for your help...

