LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 06-05-2012, 11:22 AM   #1
grob115
Member
 
Registered: Oct 2005
Posts: 528

Rep: Reputation: 32
Postfix - Name or service not known


Hi, am seeing this type of messages logged in my /var/log/maillog. Any idea what it means?
Code:
Jun  x xx:xx:xx www postfix/smtpd[10317]: connect from unknown[171.229.54.253]
Jun  x xx:xx:xx www postfix/smtpd[10317]: lost connection after CONNECT from unknown[171.229.54.253]
Jun  x xx:xx:xx www postfix/smtpd[10317]: disconnect from unknown[171.229.54.253]
Jun  x xx:xx:xx www postfix/smtpd[23135]: warning: 201.155.77.34: hostname dsl-201-155-77-34-sta.prod-empresarial.com.mx verification failed: Name or service not known
Jun  x xx:xx:xx www postfix/smtpd[23135]: connect from unknown[201.155.77.34]
Jun  x xx:xx:xx www postfix/smtpd[23135]: disconnect from unknown[201.155.77.34]

Last edited by grob115; 06-05-2012 at 11:24 AM.
 
Old 06-05-2012, 12:52 PM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Ubuntu 10.10, Slackware 64-current
Posts: 2,124

Rep: Reputation: 776Reputation: 776Reputation: 776Reputation: 776Reputation: 776Reputation: 776Reputation: 776
As part of the anti-spam package, Postfix can perform sender address verification, through declarations like " reject_unknown_sender_domain". What you are seeing in your logs is spam-activity, most likely from a compromised PC that is acting as a spam zombie, such as the conficker worm which is famous for sending out this crap.

The first example shows in your logs, a conenction from 171.229.54.253 In your logs, it shows a connection was made and then dropped possibly because your system didn't respond in the (vulnerable ?) manner it was looking for. If we do a lookup on this address, we see that it is an unnamed host in a range belonging to the Viettel Corporation in Vietnam.

In the case of the second one, we see that a connection was made from 201.155.77.34. A reverse lookup shows this to be a DSL connection from sta. Googling this name shows that it is a blacklisted domain, possibly in Mexico, but trying to perform a lookup of this domain failed, which is an indication of a possible SPAM host.
 
1 members found this post helpful.
Old 06-06-2012, 10:14 AM   #3
grob115
Member
 
Registered: Oct 2005
Posts: 528

Original Poster
Rep: Reputation: 32
That's great. Thanks.
 
Old 06-11-2014, 12:54 AM   #4
javcove
LQ Newbie
 
Registered: Jun 2014
Posts: 1

Rep: Reputation: Disabled
SASL LOGIN authentication failed: authentication failure

Hello Iīm having faiil2ban blocking some of my email users. I only found this on Postfix logs but not sure why this errors. Please help me. I donīt know what is happening.

Jun 4 09:18:34 sat4 postfix/smtpd[32687]: warning: 189.191.145.179: hostname dsl-189-191-145-171-dyn.prod-infinitum.com.mx verification failed: Name or service not known
Jun 4 09:18:34 sat4 postfix/smtpd[32687]: connect from unknown[189.191.145.179]
Jun 4 09:18:34 sat4 postfix/smtpd[32687]: warning: unknown[189.191.145.179]: SASL LOGIN authentication failed: authentication failure
Jun 4 09:18:34 sat4 postfix/smtpd[32687]: lost connection after AUTH from unknown[189.191.145.179]
Jun 4 09:18:34 sat4 postfix/smtpd[32687]: disconnect from unknown[189.191.145.179]
Jun 4 09:18:37 sat4 postfix/smtpd[20808]: warning: 189.191.145.179: hostname dsl-189-191-145-179-dyn.prod-infinitum.com.mx verification failed: Name or service not known

Thanks!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix service went down and cannot be restarted when adding with virtual domain map jonizen Linux - Server 0 10-01-2011 05:20 AM
[SOLVED] how to setting Mailscanner using postfix service alphatest Red Hat 1 09-01-2010 05:48 AM
Really Confusing Postfix Name Service Error arfal Linux - Server 3 05-09-2010 08:35 PM
Service postfix restart fail/domain name config cmwalter Linux - Server 2 03-05-2010 03:16 PM
Postfix error service not found: biff/udp soulwatcher1974 Red Hat 2 02-26-2005 12:50 AM


All times are GMT -5. The time now is 03:28 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration