Solved

Is this a kind of phishing? How to disable it?

Posted on 2011-02-21
10
1,373 Views
Last Modified: 2013-11-08
This is using MailScanner 5.x in CentOS. Recently, a user comes to me and inform me she received the following notification mails, with following error:

MailScanner has detected a possible fraud attempt from "sg.jobstreet.com" claiming to be JobStreet.com

This could be due to link tracking. Can I disable it? Please help!
0
Comment
Question by:Balack
  • 3
  • 2
  • 2
  • +1
10 Comments
 
LVL 7

Expert Comment

by:wct296
ID: 34949017
Technically what is happening is that mailscanner is doing either a reverse PTR record lookup or a simple name server lookup on the IP from where the email came from..

Are you the owner of the domain jobstreet or are you just receiving alerts from it and want them to stop?
0
 
LVL 7

Expert Comment

by:wct296
ID: 34949027
I guess to give a bit of background...

when mailscanner receives and email from blah@jobstreet.com - it seems to be coming from 203.142.21.51 (sg.jobstreet.com) which is the actual server sending emails. Mailscanner wants to make sure that the email seems legit, so it does a either an MX or PTR records check on that domain, jobstreet.com... the MX record reports that jobstreet.com's mail server is 202.157.139.90 - which is obviously quite different.

If its doing a PTR records lookup, its saying that jobstreet responsible mail server is netops.jobstreet.com - which according to my testing, doesnt resolve at all..

So in short - its a misconfiguration of the jobstreet DNS/servers.. If you do not control it you cannot do anything about it. You do not want to relax your mailscanner settings if you can avoid it, mailscanner is working as it should
0
 

Author Comment

by:Balack
ID: 34952408
So, that means this could be a reverse DNS records lookup? Can this function be disable in MailScanner? Only for jobstreet? or all?
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 62

Expert Comment

by:gheist
ID: 34969763
Mailscanner works too late
Mail is already in your hands, you accepted it, so sending NDR would only multiply grief of spam.

You need to perform DNS lookups while in SMTP session.
What is your MTA?
0
 
LVL 19

Expert Comment

by:billmercer
ID: 34984582
This doesn't look like a phishing attempt, it looks like a company with multiple domains that has decided to send mail from an alternate server. Both servers belong to the same company, so it's not some sort of impersonation attempt.

If you need to receive mail from this Jobstreet company for some reason, you could whitelist them. Other than that, there's nothing you need to do on your end.
0
 

Author Comment

by:Balack
ID: 34987775
Already whitelisted both of them, but still the same problem...
0
 
LVL 19

Accepted Solution

by:
billmercer earned 500 total points
ID: 34998218
If you look at the actual text of the incoming message, does it have a link in the message where the link text looks like a URL? If so, and the URL in the text doesn't match the actual URL of the link itself then this will trigger this warming. If this is the case, then the sender of the message is really who needs to fix this, as it will cause this problem in other places as well.

You might try adding the jobstreet domains to the phishing.safe.sites.conf file. That may resolve it for you. However You might also ask to have MailScanner add these domains to their master list.

See http://www.mailscanner.info/phishing.safe.sites.conf.master for more info



0
 

Author Closing Comment

by:Balack
ID: 35005762
good
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Phishing attempts can come in all forms, shapes and sizes. No matter how familiar you think you are with them, always remember to take extra precaution when opening an email with attachments or links.
The new Gmail Phishing Scam going around is surprising even the savviest of users with its sophisticated techniques.
This Micro Tutorial demonstrates  how Internet marketers work with competitive analysis data, and a common task in data preparation is creating separate column for domains. You will then extract from a list of URLs.
In this Experts Exchange video Micro Tutorial, I'm going to show how small business owners who use Google Apps can save money by setting up what is called a catch-all email address in their Gmail accounts. By using the catch-all feature, small busin…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question