Re: [suse-security] Sendmail 8.12.3-75 exploit
What makes you think you have a problem? The logs show nothing out of the ordinary. If you mean the NULL sender addresses <>, these can be perfectly legal (for instance for bounce messages). Based on the log entries you posted, it's hard to tell.
ok... this is a portion of my today's log. As you can see, before a line with "from=<>" there are one before whith a tentative of a non-existent user. the pattern is to strong... for be just only bounced messages: smtp:/var/log # cat mail Jun 26 15:10:07 smtp sendmail[18532]: ruleset=check_relay, arg1=omr-m01.mx.aol.com, arg2=64.12.138.1, relay= omr-m01.mx.aol.com [64.12.138.1], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:11:46 smtp sendmail[18633]: ruleset=check_relay, arg1=mc7-s15.law1.hotmail.com, arg2=65.54.251.155 , relay=mc7-s15.law1.hotmail.com [65.54.251.155] (may be forged), reject=553 5.3.0 see http://www.blars.org/ errors/block.html Jun 26 15:11:46 smtp sendmail[18686]: ruleset=check_relay, arg1=n14.grp.scd.yahoo.com, arg2=66.218.66.69, re lay=n14.grp.scd.yahoo.com [66.218.66.69], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:11:57 smtp sendmail[18687]: h5QEBvrm018687: from=<Maria.Lurdes.Castro.Sousa@ccr-c.pt>, size=209172 , class=0, nrcpts=1, msgid=<5.1.0.14.2.20030626150540.00ab1440@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, rela y=[192.168.5.51] Jun 26 15:11:57 smtp amavis[18689]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:11:58 smtp amavis[18689]: do_exit:832 - ending execution with 0 Jun 26 15:11:58 smtp sendmail[18687]: h5QEBvrm018687: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:12:01 smtp sendmail[18695]: h5QEBvrm018687: to=<mjfig@ci.uc.pt>, delay=00:00:04, xdelay=00:00:03, mailer=esmtp, pri=120395, relay=smtp.ci.uc.pt. [193.136.200.62], dsn=2.0.0, stat=Sent (Ok: queued as 85EE815 754D) Jun 26 15:12:19 smtp sendmail[18777]: h5QECIrl018777: from=<>, size=5175, class=0, nrcpts=1, msgid=<0HH300E5 FDLLOZ@mstore2.iol.pt>, proto=ESMTP, daemon=MSA, relay=customer-240-190.lsb.net.KPNQwest.pt [193.126.240.190 ] Jun 26 15:12:20 smtp amavis[18779]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:12:20 smtp amavis[18779]: do_exit:832 - ending execution with 0 Jun 26 15:12:20 smtp sendmail[18777]: h5QECIrl018777: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:12:20 smtp sendmail[18784]: h5QECIrl018777: to=<pmanso@ccr-c.pt>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=35458, dsn=2.0.0, stat=Sent Jun 26 15:13:16 smtp sendmail[19574]: h5QECnrl019574: from=<JLapa@abrantina.pt>, size=2092, class=0, nrcpts= 1, msgid=<D9A3DA42D838C648BC33047111EB29E104B6A0@marte>, proto=ESMTP, daemon=MSA, relay=mail2.abrantina.pt [ 62.48.167.162] (may be forged) Jun 26 15:13:17 smtp amavis[24339]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:13:17 smtp amavis[24339]: do_exit:832 - ending execution with 0 Jun 26 15:13:17 smtp sendmail[19574]: h5QECnrl019574: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:13:17 smtp sendmail[24453]: h5QECnrl019574: to=<marta@ccr-c.pt>, delay=00:00:09, xdelay=00:00:00, mailer=local, pri=32371, dsn=2.0.0, stat=Sent Jun 26 15:13:19 smtp popper[24588]: Stats: pmelo 0 0 0 0 192.168.100.14 192.168.100.14 [pop_updt.c:296] Jun 26 15:13:23 smtp sendmail[24455]: h5QEDKrl024455: from=<c.browne@vam.ac.uk>, size=919, class=0, nrcpts=1 , msgid=<sefb0c39.054@vammail.vam.ac.uk>, proto=SMTP, daemon=MSA, relay=vammail.vam.ac.uk [193.62.208.129] Jun 26 15:13:24 smtp amavis[25141]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:13:24 smtp amavis[25141]: do_exit:832 - ending execution with 0 Jun 26 15:13:24 smtp sendmail[24455]: h5QEDKrl024455: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:14:06 smtp sendmail[30280]: h5QEE4rl030280: <dpdrc@ccr-c.pt>... User unknown Jun 26 15:14:06 smtp sendmail[30280]: h5QEE4rl030280: from=<assuncao@srsguarda.min-saude.pt>, size=55458, cl ass=0, nrcpts=0, bodytype=8BITMIME, proto=ESMTP, daemon=MSA, relay=host-17.min-saude.pt [194.65.151.17] Jun 26 15:14:25 smtp sendmail[18469]: h5QE8krl018469: collect: premature EOM: Connection reset by [159.213.1 00.253] Jun 26 15:14:26 smtp sendmail[18469]: h5QE8krl018469: SYSERR(root): collect: I/O error on connection from [1 59.213.100.253], from=<a.mazzoni@consiglio.regione.toscana.it> Jun 26 15:14:26 smtp sendmail[18469]: h5QE8krl018469: from=<a.mazzoni@consiglio.regione.toscana.it>, size=56 720, class=0, nrcpts=1, proto=ESMTP, daemon=MSA, relay=[159.213.100.253] Jun 26 15:15:08 smtp sendmail[32428]: h5QEF5rl032428: <g_davenportbs@ccr-c.pt>... User unknown Jun 26 15:15:08 smtp sendmail[32428]: h5QEF5rl032428: from=<>, size=2575, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=ausxndrpc101.aus.amer.dell.com [143.166.216.70] (may be forged) Jun 26 15:15:31 smtp sendmail[32538]: h5QEFPrl032538: from=<macorreia43@hotmail.com>, size=129459, class=0, nrcpts=1, msgid=<Law15-F196PYzDabigP000070aa@hotmail.com>, proto=ESMTP, daemon=MSA, relay=law15-f19.law15.ho tmail.com [64.4.23.19] Jun 26 15:15:31 smtp amavis[32542]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:15:32 smtp amavis[32542]: do_exit:832 - ending execution with 0 Jun 26 15:15:32 smtp sendmail[32538]: h5QEFPrl032538: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:15:32 smtp sendmail[32549]: h5QEFPrl032538: to=vf1022, delay=00:00:04, xdelay=00:00:00, mailer=loc al, pri=159743, dsn=2.0.0, stat=Sent Jun 26 15:15:40 smtp sendmail[32551]: h5QEFdrl032551: <latkinsiu@ccr-c.pt>... User unknown Jun 26 15:15:40 smtp sendmail[32551]: h5QEFdrl032551: from=<>, size=4108, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=mailout11.sul.t-online.com [194.25.134.85] JJun 26 15:16:08 smtp sendmail[32557]: ruleset=check_relay, arg1=llca097.servidoresdns.net, arg2=217.76.128.7 5, relay=llca097.servidoresdns.net [217.76.128.75], reject=553 5.3.0 see http://www.blars.org/errors/block.h tml Jun 26 15:16:18 smtp sendmail[32559]: h5QEGGrl032559: <s.puckett_fw@ccr-c.pt>... User unknown Jun 26 15:16:18 smtp sendmail[32559]: h5QEGGrl032559: from=<>, size=3139, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=[207.99.126.139] Jun 26 15:16:23 smtp sendmail[32561]: h5QEGNrm032561: from=<luis.filipe@ccr-c.pt>, size=1253, class=0, nrcpt s=1, msgid=<5.1.0.14.2.20030626150909.00aef980@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=[192.168.4.63] Jun 26 15:16:23 smtp amavis[32563]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:16:23 smtp amavis[32563]: do_exit:832 - ending execution with 0 Jun 26 15:16:23 smtp sendmail[32561]: h5QEGNrm032561: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:16:24 smtp sendmail[32567]: h5QEGNrm032561: to=<sopertec-centro@sopertec.pt>, delay=00:00:01, xdel ay=00:00:00, mailer=esmtp, pri=120517, relay=smtp.net.vodafone.pt. [212.18.160.142], dsn=2.0.0, stat=Sent (O k.) Jun 26 15:16:44 smtp sendmail[32571]: h5QEGarm032571: <arlinepaigerf@ccr-c.pt>... User unknown Jun 26 15:17:02 smtp sendmail[32574]: h5QEGrrl032574: <glennar.bonner_tg@ccr-c.pt>... User unknown Jun 26 15:17:02 smtp sendmail[32574]: h5QEGrrl032574: from=<>, size=1789, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=gatekeeper.datatel.com [205.231.22.252] Jun 26 15:17:03 smtp sendmail[32575]: h5QEGurl032575: <cliftongilliamor@ccr-c.pt>... User unknown Jun 26 15:17:04 smtp sendmail[32575]: h5QEGurl032575: from=<>, size=4278, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=m1.dnx.net [65.192.199.14] JJun 26 15:17:22 smtp sendmail[32581]: h5QEHMrm032581: from=<luis.filipe@ccr-c.pt>, size=4072, class=0, nrcpt s=1, msgid=<5.1.0.14.2.20030626151028.00aeb440@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=[192.168.4.63] Jun 26 15:17:22 smtp sendmail[32571]: h5QEGarm032571: from=<Symantec_AntiVirus_for_SMTP_Gateways@tmac.com>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MSA, relay=symantec.tmac.com [192.206.250.65] Jun 26 15:17:22 smtp amavis[32584]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:17:22 smtp amavis[32584]: do_exit:832 - ending execution with 0 Jun 26 15:17:23 smtp sendmail[32581]: h5QEHMrm032581: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:17:24 smtp sendmail[32583]: ruleset=check_relay, arg1=n13.grp.scd.yahoo.com, arg2=66.218.66.68, re lay=n13.grp.scd.yahoo.com [66.218.66.68], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:17:25 smtp sendmail[32588]: h5QEHMrm032581: to=<feucomm@yahoogrupos.com.br>, delay=00:00:03, xdela y=00:00:02, mailer=esmtp, pri=120480, relay=mta2.grp.scd.yahoo.com. [66.218.66.217], dsn=2.0.0, stat=Sent (o k 1056636705 qp 55280) Jun 26 15:17:30 smtp sendmail[32589]: ruleset=check_relay, arg1=n34.grp.scd.yahoo.com, arg2=66.218.66.102, r elay=n34.grp.scd.yahoo.com [66.218.66.102], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:18:48 smtp sendmail[32600]: h5QEIkrl032600: <randalljimenez_tz@ccr-c.pt>... User unknown Jun 26 15:18:48 smtp sendmail[32600]: h5QEIkrl032600: from=<>, size=4384, class=0, nrcpts=0, proto=ESMTP, da emon=MSA, relay=rsunx.crn.cogs.susx.ac.uk [139.184.48.12] JJun 26 15:19:43 smtp sendmail[32633]: starting daemon (8.12.3): SMTP+queueing@00:30:00 Jun 26 15:19:43 smtp sendmail-client[32637]: starting daemon (8.12.3): queueing@00:30:00 Jun 26 15:19:45 smtp sendmail[32661]: starting daemon (8.12.3): SMTP+queueing@00:30:00 Jun 26 15:19:45 smtp sendmail-client[32665]: starting daemon (8.12.3): queueing@00:30:00 Jun 26 15:20:06 smtp sendmail[32669]: h5QEJsq7032669: smtp.ccr-c.pt [10.1.3.3] did not issue MAIL/EXPN/VRFY/ ETRN during connection to MSA Jun 26 15:20:40 smtp sendmail[32682]: ruleset=check_relay, arg1=n36.grp.scd.yahoo.com, arg2=66.218.66.104, r elay=n36.grp.scd.yahoo.com [66.218.66.104], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:20:41 smtp sendmail[32683]: ruleset=check_relay, arg1=[194.65.115.18], arg2=194.65.115.18, relay=[ 194.65.115.18], reject=553 5.3.0 Rejected by SPAM filter - see http://relays.osirusoft.com/ Jun 26 15:21:41 smtp sendmail[32700]: h5QELaq7032700: from=<psilva@metromondego.pt>, size=2982, class=0, nrc pts=3, msgid=<GLEBKPIJICCAPCFKLOHEMEIKDFAA.psilva@metromondego.pt>, bodytype=8BITMIME, proto=ESMTP, daemon=M SA, relay=server1.interacesso.pt [212.13.36.243] Jun 26 15:21:42 smtp amavis[32702]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:21:42 smtp amavis[32702]: do_exit:832 - ending execution with 0 Jun 26 15:21:42 smtp sendmail[32700]: h5QELaq7032700: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:21:42 smtp sendmail[32705]: h5QELaq7032700: to=lf1010, delay=00:00:01, xdelay=00:00:00, mailer=loc al, pri=93229, dsn=2.0.0, stat=Sent Jun 26 15:21:42 smtp sendmail[32705]: h5QELaq7032700: to=ms1011, delay=00:00:01, xdelay=00:00:00, mailer=loc al, pri=93229, dsn=2.0.0, stat=Sent Jun 26 15:21:42 smtp sendmail[32705]: h5QELaq7032700: to=rp1018, delay=00:00:01, xdelay=00:00:00, mailer=loc al, pri=93229, dsn=2.0.0, stat=Sent Jun 26 15:21:44 smtp popper[32709]: (v4.0.3) Unable to get canonical name of client 192.168.2.73: Unknown ho st (1) [pop_init.c:1054] Jun 26 15:21:57 smtp sendmail[32711]: h5QELvq8032711: from=<Margarida.Franca@ccr-c.pt>, size=1033, class=0, nrcpts=1, msgid=<5.1.0.14.2.20030626151405.00a78850@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=[192.168. 2.56] Jun 26 15:21:58 smtp amavis[32713]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:21:58 smtp amavis[32713]: do_exit:832 - ending execution with 0 Jun 26 15:21:58 smtp sendmail[32711]: h5QELvq8032711: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:22:00 smtp sendmail[32717]: h5QELvq8032711: to=<clarasantos@hotmail.com>, delay=00:00:03, xdelay=0 0:00:02, mailer=esmtp, pri=120391, relay=mx1.hotmail.com. [65.54.166.99], dsn=2.0.0, stat=Sent ( <5.1.0.14.2 .20030626151405.00a78850@mail.ccr-c.pt> Queued mail for delivery) Jun 26 15:24:52 smtp sendmail[32737]: h5QEOpq8032737: from=<Ana.Pires@ccr-c.pt>, size=1332, class=0, nrcpts= 1, msgid=<5.1.0.14.2.20030626151735.00a92920@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=[192.168.2.73] Jun 26 15:24:52 smtp amavis[32739]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:24:52 smtp amavis[32739]: do_exit:832 - ending execution with 0 Jun 26 15:24:52 smtp sendmail[32737]: h5QEOpq8032737: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:24:55 smtp sendmail[32743]: h5QEOpq8032737: to=<clara.pires@verizon.net>, delay=00:00:03, xdelay=0 0:00:03, mailer=esmtp, pri=120430, relay=relay.verizon.net. [206.46.170.12], dsn=2.0.0, stat=Sent (Message r eceived: 20030626141914.MKQM29366.mta008.verizon.net@smtp.ccr-c.pt) Jun 26 15:25:40 smtp sendmail[32748]: h5QEPPq7032748: from=<cantunes@inescc.pt>, size=93093, class=0, nrcpts =1, msgid=<3EFAFE9F.5010500@inescc.pt>, proto=ESMTP, daemon=MSA, relay=pombo.inescc.pt [193.137.103.1] Jun 26 15:25:41 smtp amavis[32751]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:25:41 smtp amavis[32751]: do_exit:832 - ending execution with 0 Jun 26 15:25:41 smtp sendmail[32748]: h5QEPPq7032748: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:25:41 smtp sendmail[32755]: h5QEPPq7032748: to=as0023, delay=00:00:14, xdelay=00:00:00, mailer=loc al, pri=123356, dsn=2.0.0, stat=Sent Jun 26 15:25:53 smtp popper[32757]: (v4.0.3) Unable to get canonical name of client 192.168.5.55: Unknown ho st (1) [pop_init.c:1054] Jun 26 15:26:12 smtp sendmail[32759]: ruleset=check_relay, arg1=server.equal.mts.gov.pt, arg2=195.22.29.42, relay=server.equal.mts.gov.pt [195.22.29.42], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:26:30 smtp popper[32760]: (v4.0.3) Unable to get canonical name of client 192.168.2.96: Unknown ho st (1) [pop_init.c:1054] Jun 26 15:26:55 smtp sendmail[32761]: ruleset=check_relay, arg1=omr-m11.mx.aol.com, arg2=64.12.138.23, relay =omr-m11.mx.aol.com [64.12.138.23], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:27:12 smtp popper[32763]: (v4.0.3) Unable to get canonical name of client 192.168.13.3: Unknown ho st (1) [pop_init.c:1054] Jun 26 15:27:41 smtp sendmail[32765]: h5QERYq7032765: from=<a.m.campos@iol.pt>, size=400929, class=0, nrcpts =1, msgid=<786833783e3d.783e3d786833@iol.pt>, bodytype=8BITMIME, proto=ESMTP, daemon=MSA, relay=customer-240 -190.lsb.net.KPNQwest.pt [193.126.240.190] Jun 26 15:27:42 smtp amavis[32767]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:27:42 smtp amavis[32767]: do_exit:832 - ending execution with 0 Jun 26 15:27:42 smtp sendmail[32765]: h5QERYq7032765: Milter add: header: X-Virus-Scanned: by amavis-milter (http://amavis.org/) Jun 26 15:27:42 smtp sendmail[303]: h5QERYq7032765: to=ms0032, delay=00:00:05, xdelay=00:00:00, mailer=local , pri=431227, dsn=2.0.0, stat=Sent Jun 26 15:27:54 smtp sendmail[305]: h5QERoq7000305: <emile_wilkerson_rh@ccr-c.pt>... User unknown Jun 26 15:27:54 smtp sendmail[305]: h5QERoq7000305: from=<>, size=4299, class=0, nrcpts=0, proto=ESMTP, daem on=MSA, relay=smtpny4.vnuusa.com [63.251.31.41] Jun 26 15:27:54 smtp sendmail[308]: h5QERsq8000308: from=<fcsacadu@ccr-c.pt>, size=2119, class=0, nrcpts=1, msgid=<5.1.0.14.2.20030626151254.009e21b0@mail.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=[192.168.7.7] Jun 26 15:27:55 smtp amavis[310]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:27:55 smtp amavis[310]: do_exit:832 - ending execution with 0 Jun 26 15:27:55 smtp sendmail[308]: h5QERsq8000308: Milter add: header: X-Virus-Scanned: by amavis-milter (h ttp://amavis.org/) Jun 26 15:27:56 smtp sendmail[315]: h5QERsq8000308: to=<pedro.cardoso@iambiente.pt>, ctladdr=<fcsacadu@ccr-c .pt> (604/100), delay=00:00:02, xdelay=00:00:01, mailer=esmtp, pri=120428, relay=urano.dga.min-amb.pt. [194. 79.68.1], dsn=2.0.0, stat=Sent (Ok.) Jun 26 15:28:41 smtp sendmail[321]: ruleset=check_relay, arg1=tybclbsmtpa01.listbuilder.com, arg2=204.71.191 .27, relay=tybclbsmtpa01.listbuilder.com [204.71.191.27], reject=553 5.3.0 Rejected by SPAM filter - see htt p://relays.osirusoft.com/ Jun 26 15:28:49 smtp sendmail[322]: ruleset=check_relay, arg1=calvin.oninet, arg2=195.245.128.9, relay=calvi n.oninet [195.245.128.9] (may be forged), reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:28:54 smtp sendmail[324]: h5QESpq7000324: from=<av_sic_pmsantos@lojadocidadao.pt>, size=1323, clas s=0, nrcpts=1, msgid=<670AA5A72F435D408DD680988615EE520607EF@LCPO-EXCH01.lc.pt>, proto=ESMTP, daemon=MSA, re lay=[193.126.127.66] Jun 26 15:28:54 smtp amavis[327]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:28:54 smtp amavis[327]: do_exit:832 - ending execution with 0 Jun 26 15:28:54 smtp sendmail[324]: h5QESpq7000324: Milter add: header: X-Virus-Scanned: by amavis-milter (h ttp://amavis.org/) Jun 26 15:28:54 smtp sendmail[330]: h5QESpq7000324: to=<lberna@ccr-c.pt>, delay=00:00:01, xdelay=00:00:00, m ailer=local, pri=31569, dsn=2.0.0, stat=Sent Jun 26 15:28:58 smtp sendmail[332]: ruleset=check_relay, arg1=mc10-s20.bay6.hotmail.com, arg2=65.54.165.94, relay=mc10-s20.bay6.hotmail.com [65.54.165.94], reject=553 5.3.0 see http://www.blars.org/errors/block.html Jun 26 15:32:26 smtp sendmail[375]: h5QEWNq7000375: <mike.n.mcNamara_ne@ccr-c.pt>... User unknown Jun 26 15:32:26 smtp sendmail[375]: h5QEWNq7000375: from=<>, size=3007, class=0, nrcpts=0, proto=ESMTP, daem on=MSA, relay=mx5.mx.voyager.net [216.93.66.84] Jun 26 15:32:27 smtp popper[377]: (v4.0.3) Unable to get canonical name of client 192.168.100.13: Unknown ho st (1) [pop_init.c:1054] Jun 26 15:32:27 smtp popper[377]: Stats: vribeiro 0 0 0 0 192.168.100.13 192.168.100.13 [pop_updt.c:296] Jun 26 15:32:30 smtp popper[378]: (v4.0.3) Unable to get canonical name of client 192.168.2.96: Unknown host (1) [pop_init.c:1054] Jun 26 15:32:32 smtp popper[378]: Stats: al1012 0 0 0 0 192.168.2.96 192.168.2.96 [pop_updt.c:296] Jun 26 15:32:39 smtp sendmail[338]: h5QET8q7000338: [194.65.114.179] did not issue MAIL/EXPN/VRFY/ETRN durin g connection to MSA Jun 26 15:32:53 smtp sendmail[380]: h5QEWrq7000380: from=<>, size=3239, class=0, nrcpts=1, msgid=<2003062614 27.h5QERCaJ001138@www.ccr-c.pt>, proto=ESMTP, daemon=MSA, relay=www [10.1.3.2] Jun 26 15:32:53 smtp amavis[382]: starting. amavis 0.3.12pre5 Mon Mar 25 21:10:14 UTC 2002 Jun 26 15:32:53 smtp amavis[382]: do_exit:832 - ending execution with 0 Jun 26 15:32:53 smtp sendmail[380]: h5QEWrq7000380: Milter add: header: X-Virus-Scanned: by amavis-milter (h ttp://amavis.org/) Jun 26 15:32:53 smtp sendmail[387]: h5QEWrq7000380: to=<pmelo@ccr-c.pt>, delay=00:00:00, xdelay=00:00:00, ma iler=local, pri=33477, dsn=2.0.0, stat=Sent Jun 26 15:32:57 smtp sendmail[379]: h5QEWsq7000379: <juliann.haas_yw@ccr-c.pt>... User unknown Jun 26 15:32:57 smtp sendmail[379]: h5QEWsq7000379: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon= MSA, relay=216.163.91.2.cypresscom.net [216.163.91.2] (may be forged) Jun 26 15:33:09 smtp sendmail[390]: h5QEX5q7000390: <rosariomdenniswo@ccr-c.pt>... User unknown Jun 26 15:33:09 smtp sendmail[390]: h5QEX5q7000390: from=<>, size=2642, class=0, nrcpts=0, proto=ESMTP, daem on=MSA, relay=ex3beimcoims02.cec.eu.int [158.169.131.58] Paulo Jorge de Melo Gabinete de Informática e Estatística Comissão de Coordenação da Região Centro _________________________________________________________________________________________________ "What? You search? You would multiply yourself by ten, by a hundred? You seek followers? Seek zeros! "- Nietzsche
On Thursday 26 June 2003 18:32, Paulo Melo wrote:
this is a portion of my today's log. As you can see, before a line with "from=<>" there are one before whith a tentative of a non-existent user. the pattern is to strong... for be just only bounced messages:
This looks suspiciously like virus activity, possibly BugBear or something like that. Here is the scenario: These kinds of viruses replicate by sending themselves to as many e-mail addresses they can find on the PC they are running on. In the process they fake the return address (to prevent others from warning of an infection) by picking random user names from e-mail addresses they find, combining them with random domain names from other e-mail addresses. In most cases, this combination will not be a valid address. What you're seeing now, is mail servers bouncing messages because a virus scanner detected a virus in e-mails where the virus SMTP engine took your domain name in the faked return addresses. Unless you can stop the virus from sending e-mails, there is basically nothing you can do. Note that the mails are not neccessarily sent via you mail server! Since you appear to receive quite a number of bounces, at least verify that not one or more of your users is infected by such a virus. In that case a relatively high number of messages will have your domain name in the faked return address as you local users will probably have many others within your domain in their address books. One way to prevent these viruses from propagating, is by only relaying mail from known users. Best regards, Arjen -- 51 N 25' 05.1" - 05 E 29' 14.1" Key fingerprint - 66 4E 03 2C 9D B5 CB 9B 7A FE 7E C1 EE 88 BC 57
participants (2)
-
Arjen de Korte
-
Paulo Melo