[CentOS] pop3 attack

Wed Dec 10 17:40:50 UTC 2008
Ned Slider <ned at unixmail.co.uk>

Bill Campbell wrote:
> On Wed, Dec 10, 2008, James Pifer wrote:
>> My issues have gotten worse. Apparently over the last few days my ip
>> address has gotten blacklisted. No idea why. Even though I have a
>> commercial class cable modem service, my ip is residential because it
>> comes to my house. But I've been running my mail server for several
>> years and never had an issue. 
> 
> Your IP address, 70.62.90.185, is listed on zen.spamhaus.org, and
> you can probably go to their web site to see why it's listed.
> 

It's listed on zen.spamhaus.org because it's in pbl.spamhaus.org which 
is a policy blocklist:

http://www.spamhaus.org/pbl/query/PBL238253

Time Warner Cable/Road Runner's policy is not to permit outbound email 
for this IP address range.

There is no indication your server has been compromised or abused, just 
that Time Warner Cable/Road Runner have decided you shouldn't be running 
a mail server on that IP address range.

Sspamhaus.org is a hugely popular list so this is going to be a big 
problem for you.