Switch to full style
Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems
Post a reply

IP Blacklisted

May 03 06 3:46 am

Hello,

I found out this morning my IP address was blacklisted by Spamhaus.org. They report my IP being listed in CBL and XBL and njabl.org as an open proxy.

I have been getting a good number of virus/trojans picked up by the antivirus on the wingate machine. They have all been quarantined successfully. They are all Wingate files (or they have the wingate file extension at least).

I need advise on how to keep this from happening again.

We use pop mail. We do not use the Wingate mail server (pop or SMTP) services. We simply have MS Outlook configured to send and receive mail using the standard mail settings in Outlook.

Any help would really be appreciated.

Thanks

May 03 06 9:36 am

Hi

normally you can only be an open relay if you are accepting incoming mail and forwarding it. These blacklist sites typically employ a probing technique to see if they can get a mail relayed through you.

So, if you aren't running any SMTP server (it's disabled right?) it's hard to see how you could be an open relay.

Have you had your IP long? It could be a hangover from a previous owner of the IP if you acquired it recently.

Also, if you have something like an open SOCKS server or HTTP proxy that accepts CONNECT commands, then you could be used by spammers to send through - i.e. if they bounced off you.

You would see evidence of this in your proxy logs, normally WinGate won't bind to the external interface for services like this.

So, things to check.

1. Check the SMTP server is actually disabled
2. Check that there is no firewall hole open on port 25 for Incoming connections from the Internet
3. Check your HTTP proxy is not accepting connections on your external interface (if you were using it to pipe connections into your LAN, you may need to lock it down).
4. Check the SOCKS service to make sure it isn't available from outside your LAN.

You could do a quick port scan on your network by going to www.grc.com if you like, it will tell you if you have any of these ports open.

Once you have verified you are locked down, you can typically request a re-test from the blacklist site to get you off their list.

Regards

Adrien

May 04 06 2:47 am

Thanks for the good info! I went to the site and did a number of scans. Looks like I'm doing okay! Thanks again.
Post a reply