The reason that I started using linux was to avoid MS NT's cost
and still have multi cpu access for rendering but someone has been
banging
on my box pretty hard and done some damage (or so it seems). I have done
what all I understand to do to keep them out and it has not helped. I've
run cops and satin and pourd over /etc and dissabled sendmail. It's
not helped and that is all I know how to do. I've contacted my ISP (who
handed me off to /dev/null) and AOL (who has not responded, !surpise!).
There is nothing on this machine that could be worth anything to anyone
and it does not have secure links to any other boxes. I don't mind the
target practice, but it has gone a little beyond that now (/bin and
/sbin
have been thrashed).
So what I am asking is can any of you help me plug these holes (or where
to start looking, or what do I need to wrap how to get a fix on the
source).
I've included the only traces I have been able to capture -- maybe
they mean something to you. All it tells me is that they don't know
this site is running Linux and they are trumping netcom's smtp and
at least using AOL as an ID.
!**What ever advice you may have will be welcomed. I just do pictures**!
####################################################################
From /var/adm/messages:
Oct 7 07:51:22 localhost pppd[2979]: remote IP address 163.179.240.2
Oct 7 07:52:28 localhost sendmail[2986]: HAA02986:
relay=emout15.mx.aol.com [198.81.11.41]
Oct 7 07:54:01 localhost sendmail[2986]: HAA02986:
mailer=smtp, relay=orioles.dyn.ml.org. [205.186.165.43], stat=Deferred:
Connection refused by orioles.dyn.ml.org.
Oct 7 07:56:15 localhost sendmail[2989]: HAA02986:
mailer=smtp, relay=orioles.dyn.ml.org. [205.186.165.43], stat=Deferred:
Connection refused by orioles.dyn.ml.org.
Oct 7 08:11:19 localhost sendmail[2996]: HAA02986:
mailer=smtp, relay=orioles.dyn.ml.org. [205.186.165.40], stat=Local
configuration error
Oct 7 08:11:19 localhost sendmail[2996]: HAA02986: IAA02996: postmaster
notify: Local configuration error
Oct 7 08:11:33 localhost sendmail[2996]: IAA02996:
relay=c.mx.aol.com. [198.81.19.179], stat=Sent (IAA28144 Message
accepted for delivery)
Oct 7 08:11:33 localhost sendmail[2996]: IAA02996: to=postmaster,
delay=00:00:14, xdelay=00:00:00, mailer=local, stat=Sent
#########################################################
Also from /var/adm/messages but with the disabled local sendmail:
Oct 14 08:55:07 localhost sendmail[1310]: IAA01310: from=root, size=131,
Oct 14 08:55:07 localhost sendmail[1310]: IAA01310: to=root,
ctladdr=root (0/0), delay=00:00:01, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 08:55:07 localhost sendmail[1310]: IAA01310: IAB01310: postmaster
notify: unknown mailer error 1
Oct 14 08:55:07 localhost sendmail[1310]: IAB01310: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 08:55:07 localhost sendmail[1310]: IAB01310: IAC01310: return to
sender: unknown mailer error 1
Oct 14 08:55:07 localhost sendmail[1310]: IAC01310: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:00:06 localhost sendmail[1320]: JAA01320: from=root, size=131,
Oct 14 09:00:06 localhost sendmail[1320]: JAA01320: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:00:06 localhost sendmail[1320]: JAA01320: JAB01320: postmaster
notify: unknown mailer error 1
Oct 14 09:00:06 localhost sendmail[1320]: JAB01320: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:00:06 localhost sendmail[1320]: JAB01320: JAC01320: return to
sender: unknown mailer error 1
Oct 14 09:00:06 localhost sendmail[1320]: JAC01320: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:05:06 localhost sendmail[1332]: JAA01332: from=root, size=131,
Oct 14 09:05:06 localhost sendmail[1332]: JAA01332: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:05:06 localhost sendmail[1332]: JAA01332: JAB01332: postmaster
notify: unknown mailer error 1
Oct 14 09:05:06 localhost sendmail[1332]: JAB01332: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:05:06 localhost sendmail[1332]: JAB01332: JAC01332: return to
sender: unknown mailer error 1
Oct 14 09:05:06 localhost sendmail[1332]: JAC01332: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:10:06 localhost sendmail[1352]: JAA01352: from=root, size=131,
Oct 14 09:10:06 localhost sendmail[1352]: JAA01352: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:10:06 localhost sendmail[1352]: JAA01352: JAB01352: postmaster
notify: unknown mailer error 1
Oct 14 09:10:06 localhost sendmail[1352]: JAB01352: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:10:06 localhost sendmail[1352]: JAB01352: JAC01352: return to
sender: unknown mailer error 1
Oct 14 09:10:06 localhost sendmail[1352]: JAC01352: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:15:06 localhost sendmail[1371]: JAA01371: from=root, size=131,
Oct 14 09:15:06 localhost sendmail[1371]: JAA01371: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:15:06 localhost sendmail[1371]: JAA01371: JAB01371: postmaster
notify: unknown mailer error 1
Oct 14 09:15:06 localhost sendmail[1371]: JAB01371: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:15:06 localhost sendmail[1371]: JAB01371: JAC01371: return to
sender: unknown mailer error 1
Oct 14 09:15:06 localhost sendmail[1371]: JAC01371: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:20:06 localhost sendmail[1395]: JAA01395: from=root, size=131,
Oct 14 09:20:06 localhost sendmail[1395]: JAA01395: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:20:06 localhost sendmail[1395]: JAA01395: JAB01395: postmaster
notify: unknown mailer error 1
Oct 14 09:20:06 localhost sendmail[1395]: JAB01395: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:20:06 localhost sendmail[1395]: JAB01395: JAC01395: return to
sender: unknown mailer error 1
Oct 14 09:20:06 localhost sendmail[1395]: JAC01395: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
Oct 14 09:25:06 localhost sendmail[1418]: JAA01418: from=root, size=131,
Oct 14 09:25:06 localhost sendmail[1418]: JAA01418: to=root,
ctladdr=root (0/0), delay=00:00:00, xdelay=00:00:00, mailer=local,
stat=unknown mailer error 1
Oct 14 09:25:06 localhost sendmail[1418]: JAA01418: JAB01418: postmaster
notify: unknown mailer error 1
Oct 14 09:25:06 localhost sendmail[1418]: JAB01418: to=root,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=unknown mailer error
1
Oct 14 09:25:06 localhost sendmail[1418]: JAB01418: JAC01418: return to
sender: unknown mailer error 1
Oct 14 09:25:06 localhost sendmail[1418]: JAC01418: to=postmaster,
delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent
#########################################################
from /tmp/cron.root.13925
To: root
Subject: cron: /usr/lib/atrun 1> /dev/null 2> /dev/null