how do i stop this smtp access
Hi, My mail log is giving me these type of messages below. Looks like some guy or group of peole is using my smtp server as a relay machine. Fortunately my smtp rules are forbidding it, i think. But how do i stop all these messages in the mail log? The from is not frommy domain and looks like they can access my smtp and send email... I am using suse 7.3 and it is outdated and still working on my new 9.2 box, but i am curious what happened and how to resolve the problem. thanks henry ], reject=550 5.7.1 <s27610@yahoo.com.tw>... Relaying denied Mar 31 09:12:22 main sendmail[20762]: j2VFCEA20762: from=<tekdxtpbzdl@inbox.lv>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=219-81-229-104.static.tfn.net.tw [219.81.229.104] Mar 31 09:12:22 main sendmail[20765]: j2VFCIA20765: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:25 main sendmail[20767]: j2VFCNA20767: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:25 main sendmail[20766]: j2VFCIA20766: ruleset=check_rcpt, arg1=<cpui@kkcity.com.tw>, relay=219-81-238-110.static.tfn.net.tw [219.81.238.110], reject=550 5.7.1 <cpui@kkcity.com.tw>... Relaying denied Mar 31 09:12:25 main sendmail[20766]: j2VFCIA20766: from=<cftjj@ukr.net>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=219-81-238-110.static.tfn.net.tw [219.81.238.110] Mar 31 09:12:28 main sendmail[20767]: j2VFCNA20767: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:28 main sendmail[19729]: j2UNB0127150: to=<to76264@pchome.com.tw>, delay=16:01:28, xdelay=00:00:31, mailer=esmtp, pri=2677160, relay=mx.pchome.com.tw. [211.20.188.150], dsn=4.0.0, stat=Deferred: 440 Error: Wrong recipients Mar 31 09:12:31 main sendmail[20769]: j2VFCTA20769: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:32 main sendmail[20769]: j2VFCTA20769: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:35 main sendmail[20770]: j2VFCXA20770: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:36 main sendmail[20770]: j2VFCXA20770: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:39 main sendmail[20772]: j2VFCbA20772: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:39 main sendmail[19729]: j2UNB0127150: to=<to7252837@pchome.com.tw>, delay=16:01:39, xdelay=00:00:42, mailer=esmtp, pri=2677160, relay=mx.pchome.com.tw. [211.20.188.150], dsn=4.0.0, stat=Deferred: 440 Error: Wrong recipients Mar 31 09:12:40 main sendmail[20772]: j2VFCbA20772: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:43 main sendmail[20774]: j2VFCfA20774: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:44 main sendmail[20774]: j2VFCfA20774: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:46 main sendmail[20777]: j2VFCjA20777: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied Mar 31 09:12:46 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<beebe@ms62.hinet.net>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <beebe@ms62.hinet.net>... Relaying denied Mar 31 09:12:47 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<hk654321@ms11.hinet.net>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <hk654321@ms11.hinet.net>... Relaying denied Mar 31 09:12:47 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<biancamoriarty@hotmail.com>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <biancamoriarty@hotmail.com>... Relaying denied Mar 31 09:12:47 main sendmail[20777]: j2VFCjA20777: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:48 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<cocokyo9@yahoo.com.tw>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <cocokyo9@yahoo.com.tw>... Relaying denied Mar 31 09:12:48 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<girl_fan1009@yahoo.com.tw>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <girl_fan1009@yahoo.com.tw>... Relaying denied Mar 31 09:12:49 main sendmail[20776]: j2VFCjA20776: ruleset=check_rcpt, arg1=<19720319@yahoo.com.tw>, relay=219-81-231-102.static.tfn.net.tw [219.81.231.102], reject=550 5.7.1 <19720319@yahoo.com.tw>... Relaying denied Mar 31 09:12:49 main sendmail[20778]: j2VFCmA20778: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied
From: "Henry Tang" <henry@yucreation.com>
Hi,
My mail log is giving me these type of messages below. Looks like some guy or group of peole is using my smtp server as a relay machine. Fortunately my smtp rules are forbidding it, i think. But how do i stop all these messages in the mail log? The from is not frommy domain and looks like they can access my smtp and send email... I am using suse 7.3 and it is outdated and still working on my new 9.2 box, but i am curious what happened and how to resolve the problem.
thanks henry
], reject=550 5.7.1 <s27610@yahoo.com.tw>... Relaying denied Mar 31 09:12:22 main sendmail[20762]: j2VFCEA20762: from=<tekdxtpbzdl@inbox.lv>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=219-81-229-104.static.tfn.net.tw [219.81.229.104] Mar 31 09:12:22 main sendmail[20765]: j2VFCIA20765: from=<tttt@msa.hinet.net>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39] Mar 31 09:12:25 main sendmail[20767]: j2VFCNA20767: ruleset=check_rcpt, arg1=<a0000000@ms39.hinet.net>, relay=61-31-138-39.dynamic.tfn.net.tw [61.31.138.39], reject=550 5.7.1 <a0000000@ms39.hinet.net>... Relaying denied
This is just the log of your server doing exactly the right thing. Unless the logs are filling up your disc or these messages are hindering you from seeing others, there is no problem Cheers, Paul.
* Henry Tang <henry@yucreation.com> [03-31-05 10:22]:
My mail log is giving me these type of messages below. Looks like some guy or group of peole is using my smtp server as a relay machine.
trying to *use* and *failing*, which is appropriate.
Fortunately my smtp rules are forbidding it, i think. But how do i stop all these messages in the mail log?
edit the mail log or power down your router. ps: three or four examples would be plenty. -- Patrick Shanahan Registered Linux User #207535 http://wahoo.no-ip.org @ http://counter.li.org HOG # US1244711 Photo Album: http://wahoo.no-ip.org/gallery
The Thursday 2005-03-31 at 09:20 -0600, Henry Tang wrote:
My mail log is giving me these type of messages below. Looks like some guy or group of peole is using my smtp server as a relay machine. Fortunately my smtp rules are forbidding it, i think. But how do i stop all these messages in the mail log? The from is not frommy domain and looks like they can access my smtp and send email... I am using suse 7.3 and it is outdated and still working on my new 9.2 box, but i am curious what happened and how to resolve the problem.
It looks ok to me, as others said. Also, if you want, it is possible to compile postfix for use on 7.3. I did, using the sources from suse 9.1. -- Cheers, Carlos Robinson
Thanks people. I feel better now :)/ I just bougt a dual p3 866mzh dell for my new server.. i"ll be happy, and next time i'll do two -three examples. thanks for the info henry Carlos E. R. wrote:
The Thursday 2005-03-31 at 09:20 -0600, Henry Tang wrote:
My mail log is giving me these type of messages below. Looks like some guy or group of peole is using my smtp server as a relay machine. Fortunately my smtp rules are forbidding it, i think. But how do i stop all these messages in the mail log? The from is not frommy domain and looks like they can access my smtp and send email... I am using suse 7.3 and it is outdated and still working on my new 9.2 box, but i am curious what happened and how to resolve the problem.
It looks ok to me, as others said. Also, if you want, it is possible to compile postfix for use on 7.3. I did, using the sources from suse 9.1.
Fri, 01 Apr 2005, by henry@yucreation.com:
Thanks people. I feel better now :)/ I just bougt a dual p3 866mzh dell for my new server.. i"ll be happy, and next time i'll do two -three examples.
Why don't you use the access file to deny access from these hosts, or even better, firewall rules? Theo -- Theo v. Werkhoven Registered Linux user# 99872 http://counter.li.org ICBM 52 13 26N , 4 29 47E. + ICQ: 277217131 SUSE 9.2 + Jabber: muadib@jabber.xs4all.nl Kernel 2.6.8 + See headers for PGP/GPG info.
Because i have poeple that i know that uses the hosts.. the ip is inconsistent and host is as well but alot of *.tw... It all happened after a trip from taiwan. Must be a lot of hackers there. I only used a friend's computer there and changed some sendmail rules to allow me to email.. I reverted back the change and fixed the problem, but now people from *.tw kept on trying to use my email server... I don't think my friend's comp is hacked. . he has an antivirus.. unless they are recording keystroke or soemthing.. I changed all my password just to be safe because on the previous problem that i had was someone logged into my server and try to send out a message with shadow file and system info and files. Scary. henry Theo v. Werkhoven wrote:
Fri, 01 Apr 2005, by henry@yucreation.com:
Thanks people. I feel better now :)/ I just bougt a dual p3 866mzh dell for my new server.. i"ll be happy, and next time i'll do two -three examples.
Why don't you use the access file to deny access from these hosts, or even better, firewall rules?
Theo
participants (5)
-
Carlos E. R.
-
Henry Tang
-
Patrick Shanahan
-
Paul Gardiner
-
Theo v. Werkhoven