LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-18-2002, 01:16 PM   #1
john_biggs
LQ Newbie
 
Registered: Mar 2002
Posts: 3

Rep: Reputation: 0
HELP! Someone is bombarding my SMTP port



:smash:
Hello, all,

This is driving me crazy. We have someone trying to send SMTP traffic over our postfix. It's all being rejected, but I can't shut him out entirely via the firewall. He's sending the requests in about 100 email bursts and it's clogging our pipes but good.

Has anyone seen this? Any suggestions?

I'd like to go huntin', but I can't find his IP in any of my logs. Am I missing something?

JB

john@bigwidelogic.com
 
Old 03-18-2002, 01:46 PM   #2
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Rep: Reputation: 32
Exclamation first:

what are you doing with your server?
is it a webserver? are you hosting some websites?
if not:

why don`t you just get a new ip form your isp by reconnecting to the internet?

if so:

what does your firewall - log tell you?
when i get some scans or connects on my firewall i can always see the ip of the other guy!

who did you give the ip of your server? perhaps someone with is allowed to connect to your server has a windows (sh**) pc client and is is bad configured......

so what ?
 
Old 03-19-2002, 07:31 AM   #3
KayJay
Member
 
Registered: Mar 2002
Location: dev/null
Distribution: redhat, mandrake
Posts: 218

Rep: Reputation: 30
if this sob is packeting u with the same IP(static), write some chains to your firewall where u deny all traffic from IP xxx.xx.xx.xxx to the SMTP port
 
Old 03-19-2002, 08:48 AM   #4
john_biggs
LQ Newbie
 
Registered: Mar 2002
Posts: 3

Original Poster
Rep: Reputation: 0
I believe I got the bugger.
Thanks for all the help, all.

JB
 
Old 03-19-2002, 01:35 PM   #5
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Rep: Reputation: 32
Wink congratulations

so what was it and how did you solve the problem?
 
Old 03-19-2002, 01:41 PM   #6
john_biggs
LQ Newbie
 
Registered: Mar 2002
Posts: 3

Original Poster
Rep: Reputation: 0
I found his ip in one of the messages he was attempting to send and locked him out. It was really strange. I'm going to try to do a full post-mortem later.
 
Old 03-19-2002, 02:08 PM   #7
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Rep: Reputation: 32
ok thanx

it would be kind if you would find the time to write how you manage to kick the stranger out of you system.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
comcast smtp port 25 johnyy Linux - Networking 3 01-01-2005 11:19 PM
smtp server can't get port 25 Charles Daniel Linux - Security 1 10-26-2004 07:27 AM
smtp port changes Bruce Hill Linux - General 1 10-17-2004 05:37 PM
SMTP Port changing mosherben Linux - Software 4 07-25-2004 11:16 AM
Port 25 not open for SMTP Jim Miller Linux - Networking 6 11-18-2001 12:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration