LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 09-19-2005, 12:38 PM   #1
jademan83
LQ Newbie
 
Registered: May 2005
Distribution: FreeBSD 4.9-5.3, Slackware 10
Posts: 25

Rep: Reputation: 15
Spam problems


I'm not sure if this is a problem I can fix or not, but it appears that someone is able to spam through some of the general email addresses on my FreeBSD server. I received an email from the webmaster@mydomain.com, saying basically that my account was going to be suspended, etc... No one else would be using this account, but I have noticed the problem with other general accounts such as sales@mydomain.com, support@mydomain.com, etc... The emails are all bogus and come with attachments that have supposedly been scanned by a bogus virus company. Any suggestions to track down the problem and/or fix it would be appreciated. I am running FreeBSD 4.9 with SpamAssassin for spam filtering.

Thanks
 
Old 09-19-2005, 05:59 PM   #2
cnjohnson
Member
 
Registered: Nov 2002
Location: Nashville
Distribution: FreeBSD, Linux, OS-X
Posts: 544

Rep: Reputation: 30
Which MTA are you using: sendmail, postfix, qmail? In short, you need to make sure that no one from inside your network is using your network to spam, but mor important, you need to see to it that no one can relay messages through your site. A google search will give way more information that you care to read on how to solve this situation.

Cheers--
Charles
 
Old 09-26-2005, 03:26 PM   #3
jademan83
LQ Newbie
 
Registered: May 2005
Distribution: FreeBSD 4.9-5.3, Slackware 10
Posts: 25

Original Poster
Rep: Reputation: 15
Problem continued

Sorry, I am running exim 4.X. I have inherited most of the configuration done on this server from the previous admin, so I am learning most of these things for the first time. In the config file for the exim, it has a line for the "hostlist relay_from_hosts" that contains the ip addresses of our customers, plus it also contains "*.def.com" and "def.com". Would these two entries cause the spoofing/relaying problem, that was mentioned before? The way I would understand it, is that those last two entries would allow anyone who says they are *@def.com to send mail through our server. Is this correct or am I barking up the wrong tree?


Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
procmail and spam -- do not send out of office auto replay to spam draix Linux - Software 0 12-30-2004 08:35 AM
postfix spam filtering problems pyu7 Linux - Software 0 09-17-2004 09:26 AM
What other anti-spam for Linux that can be used, other than Spam assassin? johnportiz Linux - Software 6 01-27-2004 03:17 AM
spam bluestorm Linux - Software 7 10-07-2003 05:39 AM
Spam? Nezar Linux - Security 1 06-20-2001 08:25 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 08:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration