webzed
08/03/2008, 10h29
Bonjour,
Pour les besoins de mon site en plus de mon hébergement mutualisé d'OVH, j'utilise un VDS chez Nexlink.
Depuis hier je reçois un spam d'hameçonnage bancaire sur une e-mail de mon VDS et je me demande si ce n'est pas mon VDS qui envoie le spam.
Voici le header du spam :
Return-Path: <mailing.id758-8491CBF@citi.com>
Delivered-To: 1-xxxxxxx@mon_domaine.com
Received: (qmail 5889 invoked from network); 8 Mar 2008 03:06:06 +0100
Received: from unknown (HELO 80.86.202.114) (58.122.221.113)
by v085.nexlink.ch with SMTP; 8 Mar 2008 03:06:06 +0100
Received: from lawrence.ebaystatic.com (unknown [18.224.152.72])
by second-ns.com with SMTP id G34XA0HS91
for <xxxxxxx@mon_domaine.com>; Fri, 07 Mar 2008 18:06:12 -0800
Received: from drill.aol.com (unknown [78.67.7.158])
by DEC.com with SMTP id TAQQ1ZLKLE
for <xxxxxxx@mon_domaine.com>; Sat, 08 Mar 2008 06:04:12 +0400
From: "Citi" <mailing.id758-8491CBF@citi.com>
To: "Echange" <xxxxxxx@mon_domaine.com>
Subject: *****SPAM***** CitiBusiness customer service: new enhanced online security measures. -Fri, 07 Mar 2008 18:06:12 -0800
X-Authenticated: #06281605
User-Agent: Internet Mail Service (5.5.2650.21)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--FJ1hat3888o8gCO"
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on v085.nexlink.ch
X-Spam-Level: ******
X-Spam-Status: Yes, hits=6.2 required=3.0 tests=DATE_MISSING,FAKE_HELO_AOL,
HTML_20_30,HTML_FONTCOLOR_UNSAFE,HTML_MESSAGE,HTML _TAG_BALANCE_HTML,
MIME_HTML_ONLY,MIME_HTML_ONLY_MULTI,PRIORITY_NO_NA ME,
RCVD_NUMERIC_HELO autolearn=no version=2.63
X-Spam-Report:
* 1.0 DATE_MISSING Missing Date: header
* 0.3 RCVD_NUMERIC_HELO Received: contains a numeric HELO
* 0.0 HTML_MESSAGE BODY: HTML included in message
* 0.1 HTML_FONTCOLOR_UNSAFE BODY: HTML font color not in safe 6x6x6 palette
* 0.5 HTML_20_30 BODY: Message is 20% to 30% HTML
* 0.4 HTML_TAG_BALANCE_HTML BODY: HTML has unbalanced "html" tags
* 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
* 1.9 FAKE_HELO_AOL Host HELO did not match rDNS: aol.com
* 0.8 PRIORITY_NO_NAME Message has priority setting, but no X-Mailer
* 1.1 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
Si un spécialiste pouvez me dire qui envoie le spam (serveur) le 80.86.202.114 ou le 58.122.221.113.
Pour les besoins de mon site en plus de mon hébergement mutualisé d'OVH, j'utilise un VDS chez Nexlink.
Depuis hier je reçois un spam d'hameçonnage bancaire sur une e-mail de mon VDS et je me demande si ce n'est pas mon VDS qui envoie le spam.
Voici le header du spam :
Return-Path: <mailing.id758-8491CBF@citi.com>
Delivered-To: 1-xxxxxxx@mon_domaine.com
Received: (qmail 5889 invoked from network); 8 Mar 2008 03:06:06 +0100
Received: from unknown (HELO 80.86.202.114) (58.122.221.113)
by v085.nexlink.ch with SMTP; 8 Mar 2008 03:06:06 +0100
Received: from lawrence.ebaystatic.com (unknown [18.224.152.72])
by second-ns.com with SMTP id G34XA0HS91
for <xxxxxxx@mon_domaine.com>; Fri, 07 Mar 2008 18:06:12 -0800
Received: from drill.aol.com (unknown [78.67.7.158])
by DEC.com with SMTP id TAQQ1ZLKLE
for <xxxxxxx@mon_domaine.com>; Sat, 08 Mar 2008 06:04:12 +0400
From: "Citi" <mailing.id758-8491CBF@citi.com>
To: "Echange" <xxxxxxx@mon_domaine.com>
Subject: *****SPAM***** CitiBusiness customer service: new enhanced online security measures. -Fri, 07 Mar 2008 18:06:12 -0800
X-Authenticated: #06281605
User-Agent: Internet Mail Service (5.5.2650.21)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--FJ1hat3888o8gCO"
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on v085.nexlink.ch
X-Spam-Level: ******
X-Spam-Status: Yes, hits=6.2 required=3.0 tests=DATE_MISSING,FAKE_HELO_AOL,
HTML_20_30,HTML_FONTCOLOR_UNSAFE,HTML_MESSAGE,HTML _TAG_BALANCE_HTML,
MIME_HTML_ONLY,MIME_HTML_ONLY_MULTI,PRIORITY_NO_NA ME,
RCVD_NUMERIC_HELO autolearn=no version=2.63
X-Spam-Report:
* 1.0 DATE_MISSING Missing Date: header
* 0.3 RCVD_NUMERIC_HELO Received: contains a numeric HELO
* 0.0 HTML_MESSAGE BODY: HTML included in message
* 0.1 HTML_FONTCOLOR_UNSAFE BODY: HTML font color not in safe 6x6x6 palette
* 0.5 HTML_20_30 BODY: Message is 20% to 30% HTML
* 0.4 HTML_TAG_BALANCE_HTML BODY: HTML has unbalanced "html" tags
* 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
* 1.9 FAKE_HELO_AOL Host HELO did not match rDNS: aol.com
* 0.8 PRIORITY_NO_NAME Message has priority setting, but no X-Mailer
* 1.1 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
Si un spécialiste pouvez me dire qui envoie le spam (serveur) le 80.86.202.114 ou le 58.122.221.113.