LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 02-16-2007, 11:52 AM   #1
bmeckle
Member
 
Registered: Jun 2004
Posts: 60

Rep: Reputation: 15
Unhappy problem forwarding mail


Hello,

I have a linux system running arpwatch. I noticed that when it was setup somebody had sendmail running so arpwatch would forward messages to them. I don't like having sendmail run so I stopped it and put the email addresses into the /root/.forward file. I have not recieved an email since.

my .forward file looks like this
ima@idiot.com,
imstilla@idiot.com

I can send mail to myself from this system using mailx.
cat somefile | mailx ima@idiot.com

Did I do something wrong?
Any help is greatly appreciated.
Thanks in advance.
 
Old 02-17-2007, 05:53 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I don't like having sendmail run
What's your beef with running Sendmail?


so I stopped it and (..) I have not recieved an email since.
In /etc/(mail/)aliases adding a line "root: recipient" will make all email to root go to user account "recipient" which should be an unprivileged human user account.

[edit]
I'll add Alternate .forward files as reference, but be sure to notice the note.
[/edit]

Last edited by unSpawn; 02-17-2007 at 05:58 AM.
 
Old 02-19-2007, 02:59 PM   #3
bmeckle
Member
 
Registered: Jun 2004
Posts: 60

Original Poster
Rep: Reputation: 15
My beef with sendmail is that it leaves a security hole. If I don't have to have it running I would rather shut it off. It looks like the version of arpwatch that we are running requires sendmail. I am currently looking into weather or not there is a version of arpwatch that does not require sendmail.

Thanks for your help.
 
Old 02-19-2007, 06:32 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
My beef with sendmail is that it leaves a security hole.
Does that mean you:
- suffered a breach of security in the past 2 years due to Sendmail on boxen you own or administer, or
- believed campfire hearsay when Ye Aulde Dragons told you Ancient Tales of 'Net Folklore five years ago, or
- are in a host/network situation where binding to localhost ports, user and network access restrictions, SELinux etc, etc won't be able to harden it enough for you?


It looks like the version of arpwatch that we are running requires sendmail.
Code:
]# rpm -q arpwatch
arpwatch-2.1a13-9.FC3     # * Mind you, not that I run FC3...

]# rpm -qR arpwatch
/bin/sh  
/sbin/chkconfig  
/sbin/service  
config(arpwatch)
libc.so.6
libresolv.so.2
No deps here I can see.
 
Old 02-20-2007, 07:40 AM   #5
bmeckle
Member
 
Registered: Jun 2004
Posts: 60

Original Poster
Rep: Reputation: 15
We had a breach about 5 years ago before I became a sysadmin, but that system was completely unpatched and the intruder came in through a back door to another network. But the good thing about it was it brought security to the for ground in our company.

Also one of our arpwatch systems is sitting, for the moment, in our DMZ so I hardly consider it a secure network. And we noticed at least one advertising it's self out as a mail server, causing problems with mail.

All that and best practices.
Thanks for your help and thanks for setting me straight.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Procmail: forwarding mail to remote mail account Cadmium Linux - Software 2 01-14-2010 01:05 PM
Mail Forwarding in postfix/maildrop/redhat (like yahoo mail forwarding) topcat Linux - Software 1 08-31-2007 12:10 PM
mail forwarding problem. crackerB Linux - Software 1 09-19-2006 04:50 AM
postfix forwarding mail problem smurfix Linux - Software 2 11-08-2004 08:57 PM
mail forwarding problem with sendmail JelloMaster Linux - Software 18 08-14-2003 09:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 08:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration