LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-31-2004, 10:52 AM   #1
nbier
LQ Newbie
 
Registered: Aug 2004
Distribution: SuSE
Posts: 9

Rep: Reputation: 0
Angry Compromised: rebuilding questions (mail)


Howdy,

Discovered yesterday that a community server that I run had been compromised (still haven't id'ed the point of entry--been too busy rebuilding), and have spent the past day building a new machine. Machine's up and I've gotten web services restored. Now I'm moving on to restoring mail.

I'm running SuSE 9.0, using Postfix/Procmail/Cyrus for mail. I'm hoping to migrate old mail messages from the cracked HD, but I'm really not sure how to do it; google hasn't been paritcularly revealing on the subject, so I thought I'd check in here to see if anyone had any suggestions (or knew of websites that did).

I'm assuming that my process needs to be:

1) Recreate user accounts (so that when I turn mail back on, messages are not bounced). First on shell, then on Cyrus?

2) Configure Postfix.

3) Configure Procmail

4) Start mail services

5) Migrate old mail messages


So, two different questions, I guess: are these the right order of steps to take (and are there easy ways of recreating the user accounts on shell/cyrus)? How do I go about migrating the old mail messages?

Any other thoughts or suggestions on the process of rebuilding? I've been careful to ensure the new machine is fully updated and is as hardened as I am able to make it (of course, that was true of the old machine as well ).

thanks,
NB
 
Old 09-05-2004, 06:13 AM   #2
DrNeil
Member
 
Registered: Aug 2004
Location: Scotland
Distribution: Debian, Suse, Knoppix, Dyna:bolic, Mandrake [couple of years ago], Slackware [1993 or so]
Posts: 150

Rep: Reputation: 15
Re: Compromised: rebuilding questions (mail)

Quote:
Originally posted by nbier
(of course, that was true of the old machine as well ).
What did you have running, did you do, that was not sufficient?

Just so that I can build in a couple of extras.

Hope that's not too insensitive a question?

Firewall, ssh, xinetd IP limitations, limit root account, chkrootkit, logwatch, password rotation, IP Firewall filtering on trusted machines, virus spam filter.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mail server questions linuxnube Linux - Software 0 10-21-2003 11:20 AM
questions about a mail server DKY Linux - Newbie 35 08-01-2003 10:49 AM
e-mail questions PTBmilo Linux - Networking 2 01-11-2003 08:57 PM
2 different questions about mail messages finger51 Linux - Newbie 1 09-27-2002 11:59 AM
Questions regarding /etc/mail/access markng Linux - Security 6 08-19-2002 09:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration