LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-01-2005, 09:19 PM   #1
RHrulz
Member
 
Registered: Jul 2002
Location: Troy, KS
Distribution: Mandrake 10.1
Posts: 57

Rep: Reputation: 15
2 Questions : qmail-remote & OpenBSD Firewall


I run qmail on a Mandrake 10.1 box. I also have an OpenBSD firewall. Today when I came home I noticed unusual disk activity on the mail server. When I did ps aux it was full of qmail-remote processes.

qmailr 8826 0.0 0.0 2720 792 ? S 21:00 0:00 qmail-remote soza.com anonymous@mail.mydomain.com 4woman@soza.com
qmailr 8830 0.0 0.0 2720 792 ? S 21:00 0:00 qmail-remote exemplary.net anonymous@mail.mydomain.com bent@exemplary.net
qmailr 8839 0.0 0.0 2720 792 ? S 21:00 0:00 qmail-remote vm.tcnj.edu anonymous@mail.mydomain.com admiss@vm.tcnj.edu

I yanked the network cable and rebooted. I figured that someone was using my server to send spam. There are only about 4 in there now. Any idea what this is and how to track it down.

Also, any idea if there is anywhere I should look on the OpenBSD firewall to get some insight on a securtiy breach?

Thanks for any help
 
Old 08-02-2005, 12:09 AM   #2
wylie1001
Member
 
Registered: Jul 2002
Location: USA
Distribution: Slackware 10.2
Posts: 53

Rep: Reputation: 15
Hi,
See if you have a file called local-host-names and make sure your host only is in there. Mine is in my etc/mail directory, also look at relay-domains your host only in there and look at the others in that directory. I use sendmail and see people trying to spam me but they get denied. I use iptables as a firewall. I also shut down submission I believe it is port 587 I only have port 25 open, and all is running ok. Also do a netstat -nl and see what is listening and shut off all that you don't need open to the public. Hope this is a help.
Rick
 
Old 08-05-2005, 09:42 AM   #3
Donboy
Member
 
Registered: Aug 2003
Location: Little Rock, Arkansas
Distribution: RH, Fedora, Suse, AIX
Posts: 736

Rep: Reputation: 31
Try looking in the queue and see what they are. Maybe use "find" to look for any files under /var/qmail/queue. Don't try deleting these manually. You will ruin your mail server. Look but don't touch.

My suspicion is they are spam messages and you're trying to deliver bounce messages. For example, spammer sends you some junk to non-existent mailbox. Spam bounces, but they used a fake "from" address, so they are sitting in your queue with no hope of being delivered.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Some questions about PPPOE & PPP in OpenBSD 3.6 VertX *BSD 1 03-26-2005 06:45 AM
Firewall/Server setup & choosing questions adrenaline_NZ Linux - Networking 2 10-13-2004 04:19 PM
OpenBSD Firewall w/DMZ & HTTP jdh77 *BSD 1 05-09-2004 12:13 AM
iptables questions: NAT & firewall insanitee Linux - Networking 10 08-24-2003 06:32 AM
Questions (remote control & mount --bind) DenShinobi Linux - Newbie 2 02-05-2002 09:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration