Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game. |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
06-02-2004, 08:57 AM
|
#1
|
|
LQ Newbie
Registered: Aug 2003
Location: Brooklyn
Distribution: RH 9
Posts: 3
Rep:
|
Spam in /var/spool/mail/root
Greetings,
My first post so please forgive me is something is wrong with it. While I don't consider myself a NOOB, I must admit that I'm not a seasoned Linux pro either. I have several services up and running including Samba, Squid, VSFTP, SOCKS5 etc. - all on Redhat 9 with updates and no signs of trouble.
However, I recently made some major changes to my /etc/hosts file in which I denied access to my LAN for certain workstations. I received a message immediately after restarting my network stating that I had mail in /var/spool/mail/root. Examining the file I noticed that it was approximately 20mb in size and contained several hundred Spam e-mails.
I ran ethereal several times and haven't noticed anything particularly suspicious and I do not have this unit set up as a mail server of any kind. The only e-mail I use is 'excite' which is web based and only on certain workstations. SpamAssassin is running; as I was planning to set up a mail server in the future.
Any information relating to this matter is very greatly appreciated. I usually browse these groups when I have troubles and very many helpful people have resolved them, but alas I am perplexed.
Thanks.

|
|
|
|
06-02-2004, 09:16 PM
|
#2
|
|
Member
Registered: Dec 2003
Location: South Australia (ex-Devon, UK)
Distribution: SuSE, Slackware, Fedora, Debian, Knoppix
Posts: 141
Rep:
|
To whom were the mails addressed? To users that don't exist?
I'm guessing that your system is configured so that unknown addresses go to postmaster and that you have postmaster aliased to root.
Have a look in your aliases file (probably /etc/aliases or /etc/mail/aliases) - you may find a clue as to what is happening.
|
|
|
|
06-04-2004, 12:47 PM
|
#3
|
|
LQ Newbie
Registered: Aug 2003
Location: Brooklyn
Distribution: RH 9
Posts: 3
Original Poster
Rep:
|
Greetings all;
kbcnetau, thank you very much for the reply and the information was right on target. I guess I am confused as to how I'm getting e-mail sent to the computer in the first place. Are they just taking an IP address and filling it with various names hoping to reach one or two users? I hope not because that sounds completely ludicrous to me.
Is there a way I can completely stop any mail from reaching any user anywhere on my Linux box? The only access I would even prefer to have to /var/spool/mail/ is by root and only to check for errors. Maybe not even for that. I figure that I don't need any type of e-mail services at all, as all the e-mail accounts here are web based requiring only http proxy services.
It wouldn't seem safe to me that junk mailers can simply send hundreds of spam e-mails to my IP address, if that is what they are doing, and instead of being blocked somehow they are merely redirected. I've been looking for a way to stop all e-mail services in my unit, but I can find nothing.
Thanks again for any and all help.

|
|
|
|
06-05-2004, 01:48 AM
|
#4
|
|
Member
Registered: Dec 2003
Location: South Australia (ex-Devon, UK)
Distribution: SuSE, Slackware, Fedora, Debian, Knoppix
Posts: 141
Rep:
|
Having looked at rejects on my own mail server logs, what the spammers are doing is taking a domain (rather than an IP address) and are putting just about every concievable name in front of the @ in hope of hitting a legitimate account. If the MTA on your machine is not set to reject non-existent users, postmaster and thus root ends up getting all the junk.
If you don't need your mail server to handle incoming traffic and your Web mail is coming through on the normal http port (80), you could just block the smtp port (25) on your firewall. This should also cut down your incoming bandwidth...
|
|
|
|
06-11-2004, 02:35 PM
|
#5
|
|
LQ Newbie
Registered: Aug 2003
Location: Brooklyn
Distribution: RH 9
Posts: 3
Original Poster
Rep:
|
Greetings,
Thank you again for the information. I know this follow-up is extremely late, but I wanted to let anyone know who may search this thread that kbcnetau's method worked. I now only have errors reported to local users in my mail folders and no spam at all.
Very much appreciated.
|
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 08:18 AM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|