[Exim] common pattern in spam involving exim 4.34

Top Page
Delete this message
Reply to this message
Author: Giuliano Gavazzi
Date:  
To: exim-users
Subject: [Exim] common pattern in spam involving exim 4.34
Is this a coincidence (both were spam)?

Received: from [69.93.240.154] (helo=server150.teknonservers.com)
    by mailhost.humph.com with esmtp (TLSv1:DES-CBC3-SHA:168)
    (Exim 4.34)
    id I0AVBF-0007G8-OS
    for   @humph.com; Sun, 04 Jul 2004 00:45:16 +0100
Received: from nobody by server150.teknonservers.com with local (Exim 4.34)
    id 1BguBu-000729-RO
    for   @humph.com; Sat, 03 Jul 2004 18:45:06 -0500



Received: from [67.18.88.244] (helo=venus.select-servers.com)
    by mailhost.humph.com with esmtp (TLSv1:DES-CBC3-SHA:168)
    (Exim 4.34)
    id I09X0O-0006QS-1M
    for   @humph.com; Sat, 03 Jul 2004 12:24:24 +0100
Received: from nobody by venus.select-servers.com with local (Exim
4.34; FreeBSD)
    id 1BgidS-000AEC-OM
    for   @humph.com; Sat, 03 Jul 2004 06:24:46 -0500


it could be:

1) exim is very popular

2) there is a exploit in version 4.34

3) just a coincidence...


Giuliano