LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-05-2011, 06:03 AM   #1
alphatest
Member
 
Registered: Aug 2010
Location: KL
Distribution: Centos, ubuntu
Posts: 137

Rep: Reputation: 2
spam attack +spamassassin+amavis


hello,

anyone know to delete this message from annoye my mailserver.

i don't know why it's through my server.


Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intelforce@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intelligensia79@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_co_ly@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_miln_2005@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_top2004@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<interaissa@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intergo12@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<interiy@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<infochad@yahoo.com.ph>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/qmgr[11836]: 903AC49ACCF5: to=<int76@yahoo.com>, relay=none, delay=0, status=deferred (delivery temporarily suspended: host b.mx.mail.yahoo.com[74.6.136.65] refused to talk to me: 421 4.7.0 [TS01] Messages from 210.19.31.170 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<info@yahoo.fr>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<info_adelz@yahoo.fr>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
 
Old 01-05-2011, 08:14 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,633

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by alphatest View Post
hello,

anyone know to delete this message from annoye my mailserver.

i don't know why it's through my server.


Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intelforce@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intelligensia79@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_co_ly@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_miln_2005@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<inter_top2004@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<interaissa@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<intergo12@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<interiy@yahoo.com>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<infochad@yahoo.com.ph>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/qmgr[11836]: 903AC49ACCF5: to=<int76@yahoo.com>, relay=none, delay=0, status=deferred (delivery temporarily suspended: host b.mx.mail.yahoo.com[74.6.136.65] refused to talk to me: 421 4.7.0 [TS01] Messages from 210.19.31.170 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<info@yahoo.fr>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
Jan 5 19:57:07 mail postfix/smtp[6990]: ABA2049ACCC8: to=<info_adelz@yahoo.fr>, relay=127.0.0.1[127.0.0.1], delay=4, status=sent (250 2.6.0 Ok, id=07000-05, from MTA([127.0.0.1]:10025): 250 Ok: queued as 903AC49ACCF5)
You've been blacklisted as a spammer...from what you've posted, it seems like you may be. A whole bunch of user-names, close together, alphabetized, all at once??

If you're not, then contact Yahoo, and get removed from their blacklist.
 
Old 01-07-2011, 09:51 AM   #3
alphatest
Member
 
Registered: Aug 2010
Location: KL
Distribution: Centos, ubuntu
Posts: 137

Original Poster
Rep: Reputation: 2
the problem is my server already have all spam need(spamassassin, clamav, amavis-new, greylist) and i know i get blacklist but(already report to yahoo or other parties ....you see from my log that email are not from my server. it's generate by spammers.

that's why i ask how to block from them....already do it as suppose to be but spammers just got through.
 
Old 01-07-2011, 09:54 AM   #4
alphatest
Member
 
Registered: Aug 2010
Location: KL
Distribution: Centos, ubuntu
Posts: 137

Original Poster
Rep: Reputation: 2
see this.....it's also spam


Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<pabloescalera@millic.com.ar>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<palmadelrey@netizen.com.ar>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<ouhelli@newconsul.com>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<osvictor@osvictor.com>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<otero@otero-abogados.com.ar>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<pam@pachecoyasociados.com.ar>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<paklau@rogers.com>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<pabc@shaw.ca>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<outpost4liberty@skywayusa.net>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<pabloflorezabogado@speedy.com.ar>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
Jan 7 23:51:48 mail postfix/smtp[2146]: AA56349F6862: to=<p_tom005@tiscali.co.uk>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=02178-11, from MTA([127.0.0.1]:10025): 250 Ok: queued as 37EF349F687A)
 
Old 01-07-2011, 12:11 PM   #5
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,633

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by alphatest View Post
the problem is my server already have all spam need(spamassassin, clamav, amavis-new, greylist) and i know i get blacklist but(already report to yahoo or other parties ....you see from my log that email are not from my server. it's generate by spammers.
No, we see from your logs that the messages are COMING from your server, out to somewhere else. You don't have something set up right, or you've been compromised, and your server is churning out spam
Quote:
that's why i ask how to block from them....already do it as suppose to be but spammers just got through.
Don't know, since you don't post any of your configurations. If I were you, I'd start back at the beginning, and go through your installation VERY carefully, to see where something might have been missed.
 
Old 01-08-2011, 09:36 AM   #6
alphatest
Member
 
Registered: Aug 2010
Location: KL
Distribution: Centos, ubuntu
Posts: 137

Original Poster
Rep: Reputation: 2
please check my master.cf

any mistake ?



# ==========================================================================
# service type private unpriv chroot wakeup maxproc command + args
# (yes) (yes) (yes) (never) (100)
# ==========================================================================
smtp inet n - n - - smtpd
2525 inet n - n - - smtpd
#587 inet n - n - - smtpd
submission inet n - n - - smtpd
# -o smtpd_etrn_restrictions=reject
#smtps inet n - n - - smtpd
# -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes
#submission inet n - n - - smtpd
-o smtpd_etrn_restrictions=reject
-o smtpd_enforce_tls=yes -o smtpd_sasl_auth_enable=yes
#628 inet n - n - - qmqpd
pickup fifo n - n 60 1 pickup
cleanup unix n - n - 0 cleanup
qmgr fifo n - n 300 1 qmgr
#qmgr fifo n - n - 1 nqmgr
#tlsmgr fifo - - n - 1 tlsmgr
rewrite unix - - n - - trivial-rewrite
bounce unix - - n - 0 bounce
defer unix - - n - 0 bounce
trace unix - - n - 0 bounce
verify unix - - n - 1 verify
flush unix n - n 1000? 0 flush
proxymap unix - - n - - proxymap
smtp unix - - n - - smtp
relay unix - - n - - smtp
# -o smtp_helo_timeout=5 -o smtp_connect_timeout=5
showq unix n - n - - showq
error unix - - n - - error
local unix - n n - - local
virtual unix - n n - - virtual
lmtp unix - - n - - lmtp
anvil unix - - n - 1 anvil
#
# Interfaces to non-Postfix software. Be sure to examine the manual
# pages of the non-Postfix software to find out what options it wants.
#
# maildrop. See the Postfix MAILDROP_README file for details.
#
maildrop unix - n n - - pipe
flags=DRhu user=vmail argv=/usr/local/bin/maildrop -d ${recipient}
#
old-cyrus unix - n n - - pipe
flags=R user=cyrusimap argv=/cyrus/bin/deliver -e -m ${extension} ${user}
# Cyrus 2.1.5 (Amos Gouaux)
# Also specify in main.cf: cyrus_destination_recipient_limit=1
cyrus unix - n n - 10 pipe
user=cyrusimap argv=/usr/bin/cyrus/bin/deliver -e -r ${sender} -m ${extension} ${user}
uucp unix - n n - - pipe
flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient)
ifmail unix - n n - - pipe
flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
bsmtp unix - n n - - pipe
flags=Fq. user=foo argv=/usr/local/sbin/bsmtp -f $sender $nexthop $recipient
127.0.0.1:10025 inet n - y - - smtpd
-o content_filter=
-o local_recipient_maps=
-o relay_recipient_maps=
-o smtpd_restriction_classes=
-o smtpd_client_restrictions=
-o smtpd_helo_restrictions=
-o smtpd_sender_restrictions=
-o smtpd_recipient_restrictions=permit_mynetworks,reject
-o mynetworks=10.0.0.0/8
-o smtpd_enforce_tls=no
-o strict_rfc821_envelopes=yes
-o smtpd_error_sleep_time=0
-o smtpd_soft_error_limit=1001
-o smtpd_hard_error_limit=1000
-o receive_override_options=no_header_body_checks,no_unknown_recipient_checks
#127.0.0.1:10025 inet n - y - - smtpd
-o smtpd_bind_address=127.0.0.1
smtp-amavis unix - - y - 2 smtp
-o smtp_data_done_timeout=1200
-o smtp_send_xforward_command=yes
-o disable_dns_lookups=yes
-o max_use=20
127.0.0.1:10025 inet n - y - - smtpd
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to enable spamassassin in amavis Skaperen Linux - Server 5 12-30-2010 05:28 PM
postfix (spamassassin+clamav+ amavis) alphatest Linux - Software 2 12-21-2010 08:17 AM
How to restart spamassassin in an Amavis-environment ? Marc Thoelen Linux - Server 6 07-20-2007 08:46 AM
How to restart spamassassin in an Amavis-environment ? Marc Thoelen Linux - Enterprise 1 07-13-2007 04:21 AM
Postfix, dovecot, spamassassin SPAM to a spam folder breitscott Linux - Server 30 02-17-2007 02:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 02:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration