...
List Mail User wrote:
P.S. I refused it, so I don't know what it was. I do know the domain registration is false; There is no city named "San Gwann" in the country of Malta.
Apparently not a "city" but a recognized "village"; I guess it's like living in unincorparated parts of LA. Note the company claims to be "GFI Software Ltd" and sell anti-spam, anit-virus and email products. Did anyone actually receive the email? Was it just directed at me? Another batch of attempts just occurred:
Apr 7 22:22:26 mailhub postfix/qmgr[14119]: D6A9C6A44: removed Apr 7 22:22:31 mailhub postfix/smtpd[24110]: connect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:32 mailhub postfix/smtpd[24110]: NOQUEUE: reject: RCPT from mailgate.gfi.com[80.85.99.13]: 450 <passthrough>: Helo command rejected: Host not found; from=discuss-bounces@lists.surbl.org to=track@plectere.com proto=ESMTP helo=<passthrough> Apr 7 22:22:33 mailhub postfix/smtpd[24110]: lost connection after RSET from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:33 mailhub postfix/smtpd[24110]: disconnect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:33 mailhub postfix/smtpd[24110]: connect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:34 mailhub postfix/smtpd[24110]: NOQUEUE: reject: RCPT from mailgate.gfi.com[80.85.99.13]: 450 <passthrough>: Helo command rejected: Host not found; from=discuss-bounces@lists.surbl.org to=track@plectere.com proto=ESMTP helo=<passthrough> Apr 7 22:22:34 mailhub postfix/smtpd[24110]: lost connection after RSET from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:34 mailhub postfix/smtpd[24110]: disconnect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:34 mailhub postfix/smtpd[24110]: connect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:35 mailhub postfix/smtpd[24110]: NOQUEUE: reject: RCPT from mailgate.gfi.com[80.85.99.13]: 450 <passthrough>: Helo command rejected: Host not found; from=discuss-bounces@lists.surbl.org to=track@plectere.com proto=ESMTP helo=<passthrough> Apr 7 22:22:36 mailhub postfix/smtpd[24110]: lost connection after RSET from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:36 mailhub postfix/smtpd[24110]: disconnect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:36 mailhub postfix/smtpd[24110]: connect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:37 mailhub postfix/smtpd[24110]: NOQUEUE: reject: RCPT from mailgate.gfi.com[80.85.99.13]: 450 <passthrough>: Helo command rejected: Host not found; from=discuss-bounces@lists.surbl.org to=track@plectere.com proto=ESMTP helo=<passthrough> Apr 7 22:22:37 mailhub postfix/smtpd[24110]: lost connection after RSET from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:37 mailhub postfix/smtpd[24110]: disconnect from mailgate.gfi.com[80.85.99.13]
If they are legitimate, I certainly wouldn't want to buy any anti-virus or anti-spam software from these people!
They are running an open relay:
% telnet mailgate.gfi.com 25 Trying 80.85.99.13... Connected to mailgate.gfi.com. Escape character is '^]'. 220 mailgate.gfi.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Fri, 8 Apr 2005 07:43:44 +0200 helo plectere.com 250 mailgate.gfi.com Hello [64.32.188.109] mail from: <> 250 2.1.0 <>....Sender OK rcpt to: test@plectere.com 250 2.1.5 test@plectere.com quit 221 2.0.0 mailgate.gfi.com Service closing transmission channel Connection closed by foreign host.
Paul Shupak track@plectere.com
On Thursday, April 7, 2005, 10:45:46 PM, List User wrote:
Note the company claims to be "GFI Software Ltd" and sell anti-spam, anit-virus and email products. Did anyone actually receive the email? Was it just directed at me? Another batch of attempts just occurred:
Apr 7 22:22:26 mailhub postfix/qmgr[14119]: D6A9C6A44: removed Apr 7 22:22:31 mailhub postfix/smtpd[24110]: connect from mailgate.gfi.com[80.85.99.13] Apr 7 22:22:32 mailhub postfix/smtpd[24110]: NOQUEUE: reject: RCPT from mailgate.gfi.com[80.85.99.13]: 450 <passthrough>: Helo command rejected: Host not found; from=discuss-bounces@lists.surbl.org to=track@plectere.com proto=ESMTP helo=<passthrough>
And why would a legitimate company send mail using a fake from address? I guess I'm extra annoyed because they're using one that belongs to us.
In my spare time, maybe' I'll write the fsckers:
GFI Software Ltd UK Unit 2, St Johns Mews St Johns Road Hampton Wick Kingston upon Thames Surrey KT1 4AN UK Tel +44 0870 770 5370 Fax +44 0870 770 5377 Email sales@gfi.co.uk Support support@gfi.com USA, Canada and Puerto Rico
GFI Software USA, Inc. 15300 Weston Parkway Suite 104 Cary, NC 27513 USA Tel +1 (888) 2 GFIFAX +1 (888) 243-4329 +1 (919) 379-3397 Fax +1 (919) 379-3402 Support +1 (919) 297-1350 Reseller support +1 (919) 297-1340 Email sales@gfiusa.com Support support@gfiusa.com Govt sales govsales@gfiusa.com
Jeff C. -- "If it appears in hams, then don't list it."
Hi!
If they are legitimate, I certainly wouldn't want to buy any anti-virus or anti-spam software from these people!
They are running an open relay:
% telnet mailgate.gfi.com 25 Trying 80.85.99.13... Connected to mailgate.gfi.com. Escape character is '^]'. 220 mailgate.gfi.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Fri, 8 Apr 2005 07:43:44 +0200 helo plectere.com 250 mailgate.gfi.com Hello [64.32.188.109] mail from: <> 250 2.1.0 <>....Sender OK rcpt to: test@plectere.com 250 2.1.5 test@plectere.com quit 221 2.0.0 mailgate.gfi.com Service closing transmission channel Connection closed by foreign host.
gfi.com, the same gfi.com thats selling mail security products? One word: Amazing.
550 5.7.1 Unable to relay for ...
Just checked, and it seems they closed it allready.
Bye, Raymond.