Re: SYS ADMINS Comments about APEWS Need Help
  Home FAQ Contact Sign in
news.admin.netabuse.blocklisting only
 
Advanced search
POPULAR GROUPS

more...

 Up
Re: SYS ADMINS Comments about APEWS Need Help         

Group: news.admin.netabuse.blocklisting · Group Profile
Author: 1urk3r
Date: Aug 23, 2007 23:04

On Aug 23, 7:34 am, "Tom Schiller" wrote:
> Can someone help me out here. ive been working with my ISP trying to figure
> out what he or I need to do
> to fix my current problem. APEWS has me blacklisted (dont really care
> BUTT!!!!) other people are
> rejecting mail from our server for proabably the same reason. it appears
> that my ISP has some problems
> with there Network. what can I tell them in order to fix it. or is there
> network ok and I have to changed something
> on my server.
>
> here is his comments. pls let me know what I should be telling the.. HELLLLP
> ! :(
>
> This is the response from my CO LO HOST
>
> can i tell them anything that says hey fix this?
>
> Your IP has always had reverse DNS set up on it. Before our changes
> yesterday, 64.39.161.58 resolved towww.schiller.ca, andwww.schiller.ca
> resolved to 64.39.161.58. That's reverse DNS. It didn't match the host
> name your mail server was using to identify itself, which could cause some
> problems when e-mailing out, so that's what we changed yeterday.
> After our changes yesterday, 64.39.161.58 resolves to vplanet.ca, and
> vplanet.ca resolves to 64.39.161.58.
>
> The IP address they're looking up, 64.39.160.0, is not your IP. It's merely
> the first IP (i.e. network address) in that block of 8000+ that they've
> listed. It's not a live host, and it's not internet accessible.
>
> Furthermore, reverse DNS isn't often put in place for the network address of
> a block (.0), nor the broadcast address (.255). So I'm not entirely certain
> why they're using 64.39.160.0 for their check.
>
> If we look at the IP for their own mail server (mail.apews.org), we see that
> it's 72.2.24.120. This IP belongs to a much larger block owned by Big
> Pipe - 72.2.0.0/16. If we mimic the same check on that IP block that they
> appear to be doing on ours (looking for a reverse DNS entry on the network
> address - 72.2.0.0), we see that it fails. i.e. there is no reverse DNS
> entry for 72.2.0.0. So by that logic, they should be listing their own IP,
> which they're not.
>
> That makes me think that they might be listing the block for other reasons.
> The more I read about this Apews entity, however, the more I'm inclined to
> believe they're not very legit....
>
> http://member.dnsstuff.com/forums/showthread.php?p=14730960http://member.dnsstuff...
>

there's no question about "legit" - it isn't.
if you're having deliverability issues, you can
remove "apews" from your list of possible suspects.

golden.net is certainly not on the standard list of "bad"
networks. leaving aside "apews" as just foolishness,
only uceprotect lists golden.net "in bulk," and
uceprotect's penetration is only slightly greater than
that of "apews." if you're really seeing lots of
rejections, neither "apews" nor uceprotect are
the cause.

the longevity of the lone spamhaus' listing, which has
the earmarks of a trojanned machine, is troubling, though.
an attentive network would have noticed the listing, fixed
the problem, and asked for delisting. there are other
mild problems.

64.39.166.109 listed in bl.spamcop.net (127.0.0.2)

...for instance. and i notice one cbl listing.
but all in all, not much seems to be wrong at
golden.net. i'm sure they have their share of
Storm-infested boxes, but that's as rare as
the common cold these days.

you say "other people" are rejecting your mail, but you
don't give any examples. usually there's at least a little
information in the rejection message. why not post
one here?

adam

--

--
Comments posted to news.admin.net-abuse.blocklisting
are solely the responsibility of their author. Please
read the news.admin.net-abuse.blocklisting FAQ at
http://www.blocklisting.com/faq.html before posting.
no comments
diggit! del.icio.us! reddit!

RELATED THREADS
SubjectArticles qty Group
Re: cvs commit: src/sys/sys mbuf.h src/sys/net if_ethersubr.cmailing.freebsd.cvscurrent ·