<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs? in Archive</title>
    <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38375#M18126</link>
    <description>&lt;P&gt;OK, after BT fiixed this account on the btconnect.com SMTP relays it looks as though the spam has stopped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found that you can still authenticate using Base64 encoding via telnet, so it is still possible to relay. But I dont think the spammers are using that technique.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either way there are mutliple security holes on the mail.btconnect.com mail servers, as a result of the move to Office365.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently someone from the mail team is contacting me later so I can show them how I can spam through their servers.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2012 12:21:50 GMT</pubDate>
    <dc:creator>bobdonkey</dc:creator>
    <dc:date>2012-04-24T12:21:50Z</dc:date>
    <item>
      <title>Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38183#M18119</link>
      <description>&lt;P&gt;I am posting this here as support have so far been absolutely no use in resolving my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My client has an account on btconnect.com which is receiving hundreds of non delivery reports. I can see in the email header that they are authenticating using the account. But changing the password for the account makes no difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I setup the account in Outlook and tried other passwords.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guess what? The old password was a simple word, but still works to authenticate. But even worse, anything added at the end of the password also works. So, say the old password was hello. Even though I changed that ages ago on btconnect.com, I can still send email using that account. But I can use hello1, hello99 hello1234812304 and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Top notch security BT. And thanks for ignoring this issue for several weeks.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Apr 2012 17:27:51 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38183#M18119</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-21T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38195#M18120</link>
      <description>&lt;P&gt;Wow! First time I heard this so far. Can anyone else confirm this?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Apr 2012 18:42:36 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38195#M18120</guid>
      <dc:creator>kuerten</dc:creator>
      <dc:date>2012-04-21T18:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38275#M18121</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two separate problems here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. The password? No idea.&amp;nbsp; Could be a server error, or something else.&amp;nbsp; Try the Helpdesk again, and see if they can escalate it.&amp;nbsp; They're more email platforms anyway, so it may be a moot point in the end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The Non-Delivery Reports?&amp;nbsp; Email spoofing, which I posted up about the other day elsewhere.&amp;nbsp; If your own system is clean of malware then someone else who has your email address and a virus, or someone who has harvested your address online, is sending email as if it were you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clean your system, and let everyone that you know has your email address know that they may have a malware infection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's about the best you can do to be honest.&amp;nbsp; Email spoofing is a horrible thing and difficult to track the source of.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dave A&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2012 07:24:00 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38275#M18121</guid>
      <dc:creator>OldWolf</dc:creator>
      <dc:date>2012-04-23T07:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38281#M18122</link>
      <description>&lt;P&gt;Yes someone is sending as my client, I can see in the email headers from various IPs in china. It is not from our machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it is the password issue that is the problem - you update on btconnect.com and it hasnt removed the old password, and worse than that, a variety of passwords work so it would be easy to guess as yo uhave more chances.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2012 08:25:48 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38281#M18122</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-23T08:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38291#M18123</link>
      <description>&lt;P&gt;Trying to contact the security team is virtually impossible. I have called them several times, they always promise to call be back and never do. BT support said to just email them, they never respond. One guy said that there are only 8 guys on the team and they get thousands of emails per day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just waiting on hold for 10 mins and then was cut off, so now waiting again. The joke is that the on hold message says to email the abuse email address, but if you do that they never respond.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is shocking customer service, I would not recommend BT to any of my business customers, they're attitude to security is a joke.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2012 10:12:51 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38291#M18123</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-23T10:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38295#M18124</link>
      <description>&lt;P&gt;Well they finally fixed this. It was as I suspected to do with the Office365 migration. Since the migration obviously there are different servers to use, but the old account on btconnect.com somehow got out of sync and unsecure and was allowing all sorts of passwords. Took me an hour on the phone to explain and then they fixed it, now I can only send through mail.btconnect.com using the correct password and none others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So they do indeed have a security issue.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2012 11:09:36 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38295#M18124</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-23T11:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38339#M18125</link>
      <description>&lt;P&gt;OK I spoke too soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They did manage to change the password and I can no longer send using the old password using Outlook. But...I can login as the user using telnet and the password in Base64, and the old password works and not the new one! This is messed up. I can also use the old password with any character after it. Why Outlook doesnt work I don't know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;time for another call to the abuse team...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2012 15:08:32 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38339#M18125</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-23T15:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38375#M18126</link>
      <description>&lt;P&gt;OK, after BT fiixed this account on the btconnect.com SMTP relays it looks as though the spam has stopped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found that you can still authenticate using Base64 encoding via telnet, so it is still possible to relay. But I dont think the spammers are using that technique.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either way there are mutliple security holes on the mail.btconnect.com mail servers, as a result of the move to Office365.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently someone from the mail team is contacting me later so I can show them how I can spam through their servers.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2012 12:21:50 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38375#M18126</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-24T12:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38429#M18127</link>
      <description>&lt;P&gt;Firstly, I'm surprised that you were using mail.btconnect.com to send E-Mail despite using mail relay. Office 365 platform aside, I would have expected smtp.btconnect.com in use with authentication here. With regard to the mail.btconnect.com mailserver, it doesn't usually require authentication as it usually authenticates via the DSL line; if the line is with BT, it leaves it at that. If users are able to authenticate with it and it accepts it, that may indeed be something BT would be interested in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly, are you running a mailserver from site using the BT Mailservers? If so, I'd imagine that you're using a static IP. Had you setup reverse DNS? If not, other spam filters may realise that E-Mail flagged as coming from mailserver@mydomain.com was actually coming from 123456.ukcore.bt.net, or something along those lines.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2012 22:11:50 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38429#M18127</guid>
      <dc:creator>DanSmith87</dc:creator>
      <dc:date>2012-04-24T22:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38485#M18128</link>
      <description>&lt;P&gt;I am not using mail.btconnect.com, that is irrelevant. The spammers are using that to relay mail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not running a mailserver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The spam has actually start again due this security issue, BT security team have promised several times to call me and never have, they don't care.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can login to BT mail servers and send mail on behalf of a user without knowing their password, and I am not on the BT network. This is a serious issue.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2012 19:52:13 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38485#M18128</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-25T19:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38491#M18129</link>
      <description>&lt;P&gt;Bob; if you truely believe you have exhausted the routine BT support routes and feel you need to get the attention at the highest level in BT then message me and I'll give you the email address of BT top level management and the Executive Level Support Team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two other options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are on "Linkedin" then you can find BT Managers on there whom you can contact/lobby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or get in touch with the Guardian (newspaper) Technical Reporting Team and talk to them! LOL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: take a look at this link: found it whilst looking for BT Data Protection Officer. Whilst it's BT Compliance at least it gives personal email&amp;nbsp; addresses:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.btplc.com/Thegroup/RegulatoryandPublicaffairs/Regulatorycompliancepolicy/Regulatorycompliancepolicy.htm" target="_blank"&gt;http://www.btplc.com/Thegroup/RegulatoryandPublicaffairs/Regulatorycompliancepolicy/Regulatorycompliancepolicy.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bob!&amp;nbsp;&amp;nbsp;&amp;nbsp; fill this form in and shake 'em up!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://globalservices.bt.com/Feedback.do?method=VIEW&amp;amp;recordId=Managed_Security_Services_solutions_uk_en-gb&amp;amp;recordName=Managed%20Security%20Services&amp;amp;primDimName=solutions&amp;amp;Context=Solutions&amp;amp;webRefNum=30026" target="_blank"&gt;http://globalservices.bt.com/Feedback.do?method=VIEW&amp;amp;recordId=Managed_Security_Services_solutions_uk_en-gb&amp;amp;recordName=Managed%20Security%20Services&amp;amp;primDimName=solutions&amp;amp;Context=Solutions&amp;amp;webRefNum=30026&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 08:01:45 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38491#M18129</guid>
      <dc:creator>Seraphsailor</dc:creator>
      <dc:date>2012-04-26T08:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38505#M18130</link>
      <description>&lt;P&gt;Actually I am thinking of submitting mail.btconnect.com to some SMTP blacklists, that should get them to fix it pretty quickly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll also give details to the register or someone if this doesnt get sorted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 09:15:10 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38505#M18130</guid>
      <dc:creator>bobdonkey</dc:creator>
      <dc:date>2012-04-26T09:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Serious security flaw in mail.btconnect.com mail relay. Are you receving multiple NDRs?</title>
      <link>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38615#M18131</link>
      <description>&lt;P&gt;SMTP blacksit like spamhaus would autmatically block an SMTP server. They will also assess if it really needs to be blocked. At this point, I don't think they will be able to do that since all the mail traffic from their end would come up clean.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2012 15:13:18 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Serious-security-flaw-in-mail-btconnect-com-mail-relay-Are-you/m-p/38615#M18131</guid>
      <dc:creator>gugaguga</dc:creator>
      <dc:date>2012-04-29T15:13:18Z</dc:date>
    </item>
  </channel>
</rss>

