LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (http://www.linuxquestions.org/questions/linux-security-4/)
-   -   Mail Server problem (http://www.linuxquestions.org/questions/linux-security-4/mail-server-problem-4175462017/)

saran_redhat 05-15-2013 12:27 AM

Mail Server problem
 
HI Friends,

In my linux mail server,

V8
T1368547362
K1368591840
N335
P30753480
I0/96/99516442
MDeferred: Connection timed out with hmail.com.
Fws
$_[61.19.190.13]
$rESMTP
$srssda.org
${daemon_flags}
${if_addr}70.32.89.121
S<no-reply@rssda.org>
MDeferred: Connection timed out with hmail.com.
rRFC822; kewldilip@hmail.com
RPFD:<kewldilip@hmail.com>
MDeferred: Connection refused by punkass.com.
rRFC822; kewlchika@punkass.com
RPFD:<kewlchika@punkass.com>
H?P?Return-Path: <~Ag>
H??X-Virus-Scanned: amavisd-new at ragecom.com
H??Received: from rssda.org ([61.19.190.13])
(authenticated bits=0)
by vps1.ragecom.com (8.13.8/8.13.8) with ESMTP id r4EFltko023636;
Tue, 14 May 2013 09:02:42 -0700
H??Reply-To: no-reply@rssda.org
H??From: "WellsFargo" <no-reply@rssda.org>
H??Subject: 1 new message
H??Date: 14 May 2013 23:02:36 +0700
H??Message-ID: <20130514230236.C6FDFE7615DFDEF4@rssda.org>
H??MIME-Version: 1.0
H??Content-Type: text/html;
charset="iso-8859-1"
H??Content-Transfer-Encoding: quoted-printable

in the mqueue directory. lot mails stored in the mqueue directory. Give some help.

Thanks

TB0ne 05-15-2013 10:50 AM

Quote:

Originally Posted by saran_redhat (Post 4951401)
HI Friends,
In my linux mail server,

Again, as you've been asked in several of your other threads, you need to provide DETAILS: "linux mail server" tells us nothing...what version/distro of Linux, using which mail server engine, and in what kind of configuration? Firewalls? ANY details?
Quote:

MDeferred: Connection timed out with hmail.com.
...and if you tried to look this error up, you'd have seen that either the domain can't be resolved, or it's not set up to accept email from you as a relay.
Quote:

MDeferred: Connection refused by punkass.com.
Again, that domain is REFUSING to allow you to send mail to it. So, contact the mail admin at that site and ask them to let you in. However....
Quote:

H??Reply-To: no-reply@rssda.org
H??From: "WellsFargo" <no-reply@rssda.org>
..these two lines don't make me want to help you at all. You're masking your REPLY-TO address, you're saying the Email is coming from WELLS FARGO BANK in the US. and the rssda.org site is in Nigeria (home of the 419 scam).
Quote:

in the mqueue directory. lot mails stored in the mqueue directory. Give some help.
Thanks
Delete the mails, or fix the errors.

Tinkster 05-15-2013 04:01 PM

If you can explain why someone in Chennai poses as Wells Fargo bank using an organisation
in Nigeria as the mail-address (Che?) we'll assist you.



If this mail didn't originate from your server you're running an open relay, and need
URGENT help. What mail system are you running? Post its config.


Moved to security.

saran_redhat 05-16-2013 12:22 AM

Mail server problem
 
Quote:

Originally Posted by Tinkster (Post 4951977)
If you can explain why someone in Chennai poses as Wells Fargo bank using an organisation
in Nigeria as the mail-address (Che?) we'll assist you.



If this mail didn't originate from your server you're running an open relay, and need
URGENT help. What mail system are you running? Post its config.


Moved to security.

Thanks for your reply.

I am using centos 5.2

Mail configured settings:
Sendmail is configured for outgoing and qmail is configured for incomming. I don't know how they configured.

Thanks

TB0ne 05-16-2013 10:08 AM

Quote:

Originally Posted by saran_redhat (Post 4952168)
Thanks for your reply.
I am using centos 5.2

Mail configured settings:
Sendmail is configured for outgoing and qmail is configured for incomming. I don't know how they configured.

A couple of things:
  1. You say that sendmail is configured for outging and qmail is configured for incoming (?)...then say you don't know how they are configured??? Didn't you just TELL US how they're configured?
  2. You STILL are not addressing the concerns brought up about Wells Fargo Bank, Nigeria, etc. NO ONE HERE is going to help a spammer/phisher/scammer.

unSpawn 05-26-2013 10:24 AM

Quote:

Originally Posted by TB0ne (Post 4952455)
You STILL are not addressing the concerns brought up about Wells Fargo Bank, Nigeria, etc. NO ONE HERE is going to help a spammer/phisher/scammer.

Easy, easy... It could be his server is sending spam due to vulnerabilities and he just doesn't recognize that, right?

@saran_redhat: please respond and tell us you've audited the complete server (accounts, running processes, software versions, anomalous files) and any other server that sends email through this server of yours.

TB0ne 05-26-2013 12:17 PM

Quote:

Originally Posted by unSpawn (Post 4959208)
Easy, easy... It could be his server is sending spam due to vulnerabilities and he just doesn't recognize that, right?

Indeed, that could be the situation, or the OP could be working at a hosting company. But the OP has not answered the question in a few threads, despite being asked several times.

unSpawn 05-26-2013 12:38 PM

Quote:

Originally Posted by TB0ne (Post 4959275)
Indeed, that could be the situation, or the OP could be working at a hosting company.

Or a combination of the two?..


Quote:

Originally Posted by TB0ne (Post 4959275)
But the OP has not answered the question in a few threads, despite being asked several times.

I've mailed him an invitation to return to this thread and clarify things.


All times are GMT -5. The time now is 11:07 PM.