qmail DoS?

qmail DoS?

Post by Erik Thij » Fri, 07 Jun 2002 17:42:39



Hi,

I see a lot of traffic going out from our qmail server to a remote SMTP
server.

Jun  6 09:32:45 <firewall> kernel: >> IN= OUT=eth1 SRC=<firewall-IP>
DST=<external mail server> LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=43106
PROTO=TCP SPT=44759 DPT=25 WINDOW=5840 RES=0x00 ACK URGP=0

There are more than 10 of these transmissions per second, for quite a long
time (actually still going on untill I blocked this traffic in the
firewall). This seems to be comming from my smtp server, and I'm a little
bit worried now.
Has anybody seen something like this before? Is it possible that my mail
server is compormised?

E.T.

 
 
 

qmail DoS?

Post by Jay Robertso » Fri, 07 Jun 2002 18:09:03


Sounds like someone is using your qmail to relay, suggest you check your
relay settings in /etc/hosts.allow file. It should read something like this:
tcp-env: 192.168.0.1, 192.168.0.2, 192.168.0.3, 192.168.0.4, 192.168.0.11,
127.0.0.1: setenv = RELAYCLIENT
Of course this is for kernel 2.2.14, may be different for later kernels...


Quote:> Hi,

> I see a lot of traffic going out from our qmail server to a remote SMTP
> server.

> Jun  6 09:32:45 <firewall> kernel: >> IN= OUT=eth1 SRC=<firewall-IP>
> DST=<external mail server> LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=43106
> PROTO=TCP SPT=44759 DPT=25 WINDOW=5840 RES=0x00 ACK URGP=0

> There are more than 10 of these transmissions per second, for quite a long
> time (actually still going on untill I blocked this traffic in the
> firewall). This seems to be comming from my smtp server, and I'm a little
> bit worried now.
> Has anybody seen something like this before? Is it possible that my mail
> server is compormised?

> E.T.


 
 
 

1. qmail and qmail+MRTG How-Tos

As a followup to my post of a week or two ago, I have re-formatted
Aaron Hill's qmail How-To and have put online my own brief How-To
for setting up qmail logging so that Inter7's qmailmrtg7 package
can generate graphs for MRTG.  These documents are available here:

http://logicsquad.net/freebsd/qmail-how-to.html

http://logicsquad.net/freebsd/qmail-mrtg-how-to.html

--
Paul.


2. Problema con winmodem per la versione 10.1

3. qmail help: how do i use qmail-pw2u????

4. auto logout

5. HELP: Connectivity between DOS/DOS and DOS/Linux

6. Java for AIX

7. accessing dos partitions with wd7000fasst scsi, isc unix 2.2, dos[345]

8. ksh vs bash: problem with pattern-list

9. Uninstall Linux: Deleted "non dos partition" with DOS fdisk -- Now what?!?

10. Samba w/ DOS box - what does DOS need?

11. Can I boot from DOS to use DOS Device Drivers?

12. Mini Linux coexists in DOS partition and boot from DOS

13. Q: Filenames turnicated DOS to LINUX to DOS?