LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 01-20-2002, 10:41 PM   #1
LionKing
Member
 
Registered: Jun 2001
Location: Allen, Texas, USA
Distribution: Redhat
Posts: 82

Rep: Reputation: 15
Hacking attempt from port 25?


Hi, I noticed my RH7.2 maillog logged something which caught my attention. I wonder if this indicate someone was trying to hacking from smtp port 25 ?

Jan 19 14:01:54 china sendmail[30184]: g0JK1q830184: ruleset=check_rcpt, arg1=<test@localmail.eknowledge-algx.com>, relay=67-89-161-12.customer.algx.net [67.89.161.12], reject=550 5.7.1 <test@localmail.eknowledge-algx.com>... Relaying denied
Jan 19 14:01:55 china sendmail[30184]: g0JK1q830184: lost input channel from 67-89-161-12.customer.algx.net [67.89.161.12] to MTA after rcpt
Jan 19 14:01:55 china sendmail[30184]: g0JK1q830184: from=<bss@fre.sg.co.nz>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=67-89-161-12.customer.algx.net [67.89.161.12]

Aslo, logwatch reported as bellow:

g0J9BO829095: SYSERR: putoutmsg (dup-200-67-221-161.prodigy.net.mx): error on output channel sending "220 china.rockstone.com ESMTP
Sendmail 8.11.6/8.11.6; Sat, 19 Jan 2002 03:11:24 -0600": Connection reset by dup-200-67-221-161.prodigy.net.mx
NOQUEUE: root@localhost did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
g0JK1q830184: ruleset=check_rcpt, arg1=<test@localmail.eknowledge-algx.com>, relay=67-89-161-12.customer.algx.net [67.89.161.12], re
ject=550 5.7.1 <test@localmail.eknowledge-algx.com>... Relaying denied
g0JK1q830184: lost input channel from 67-89-161-12.customer.algx.net [67.89.161.12] to MTA after rcpt

Any idea what was going on? thanks.
 
Old 01-21-2002, 12:51 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,599
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Sendmail mocks input,
effort to enter flow fail,
Winter lake still sleeps.

* Your mailer denies relaying. Good.
/* Format (5-7-5) is Haiku, but the season turn aint that great. */
 
Old 01-21-2002, 05:39 AM   #3
ForumKid
Member
 
Registered: Dec 2001
Posts: 195

Rep: Reputation: 30
How can i insure that relaying is off. Would it be in /etc/access?
I have a statement in /etc/access that allows relaying for local users so they can send mail.
Im a bit confused.
 
Old 01-21-2002, 11:36 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,599
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Newer sendmail versions (should) dump (almost) all files in /etc/mail, but correct, the file where *allowed relay domains* are listed in is /etc(/mail)/access. So, unless an address is listed in this file, it isn't granted relaying caps.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
OT? Hacking the D-Link DI-604 4-port router - not wireless BlackCat3416 Programming 3 07-20-2005 07:54 PM
Hacking attempt underway, what to do. Neruocomp Linux - Security 18 03-08-2005 01:37 PM
Hacking Exposed Wireless Hacking Chapter prompt Linux - Wireless Networking 0 05-08-2004 02:44 PM
hacking narendra_i Linux - Security 2 11-15-2003 02:53 AM
Hacking... TimDimman Linux - Newbie 5 02-12-2002 03:11 PM


All times are GMT -5. The time now is 09:42 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration