LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 12-02-2003, 12:07 PM   #1
nazzymac
LQ Newbie
 
Registered: Oct 2003
Location: Jamaica
Posts: 27

Rep: Reputation: 15
Sendmail DOS ?


Greetings,

i just wondered if anyone can help me out with a possible incident / DOS.
for the past 10 hours or so i have been getting sendmail log entries like.
....
Mar 27 06:30:19 hostname sendmail[690]: NOQUEUE:
host*-*-*-*.in-addr.btopenworld.com [*.*.*.*] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA
Mar 27 06:31:29 hostname sendmail[752]: NOQUEUE:
host*-*-*-*.in-addr.btopenworld.com [*.*.*.*] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA
Mar 27 06:32:39 hostname sendmail[792]: NOQUEUE:
host*-*-*-*.in-addr.btopenworld.com [*.*.*.*] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA
Mar 27 06:33:49 hostname sendmail[834]: NOQUEUE:
host*-*-*-*.in-addr.btopenworld.com [*.*.*.*] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA
Mar 27 06:34:59 hostname sendmail[896]: NOQUEUE:
host*-*-*-*.in-addr.btopenworld.com [*.*.*.*] did not issue
MAIL/EXPN/VRFY/ETRN during connection to MTA
.... continuous ......

they are happening every 1 min and 10 seconds roughly and as i said been
going on for about 10-12 hours.
 
Old 12-02-2003, 02:19 PM   #2
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Real Washington
Distribution: Debian, Android
Posts: 1,819

Rep: Reputation: 46
I would run a whois on btopenworld.com and if you don't have legitimate need to talk to them block connections to/from their ip address. It may not be malicious but they obviously have a problem with their server.
 
Old 12-02-2003, 02:41 PM   #3
nazzymac
LQ Newbie
 
Registered: Oct 2003
Location: Jamaica
Posts: 27

Original Poster
Rep: Reputation: 15
now its more than one

a "ps -ax" shows

28667 ? S 0:00 sendmail: server n20.grp.scd.yahoo.com [66.218.66.76] cmd read
28710 ? S 0:00 sendmail: server [196.1.142.222] child wait
28717 ? S 0:00 sendmail: server [219.95.161.138] cmd read
28837 ? S 0:00 sendmail: startup with 24-193-160-236.nyc.rr.com
28839 ? S 0:00 sendmail: startup with scorpion.postdirect.com
28840 ? S 0:00 sendmail: server [203.190.128.135] child wait
28843 ? S 0:01 sendmail: ./hB2HxB528686: from queue
28848 ? S 0:00 sendmail: startup with ti211310a080-2221.bb.online.no
28856 ? S 0:00 sendmail: startup with [211.212.14.76]


and it goes over 255 connections
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sendmail ignores my sendmail smarthost entry Paul_assheton Linux - General 1 03-17-2009 08:55 AM
FC4 and Sendmail - Cannot create sendmail.pem Balderayne Linux - Security 2 11-09-2005 03:55 PM
Dos Emulator without Dos dtheorem Linux - Software 1 10-14-2003 02:18 PM
Dos Emulator without Dos dtheorem Linux - Software 1 10-14-2003 01:52 PM
Sendmail - RunAsUser=sendmail:mail/What files to i have to change ForumKid Linux - Security 45 01-18-2002 12:47 PM


All times are GMT -5. The time now is 04:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration