Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
04-12-2007, 09:44 AM
|
#1
|
Member
Registered: Jun 2003
Posts: 55
Rep:
|
ahhh my sendmail is sending spam?!?!
I am currently running Sendmail 8.13.7 on FC5 and totally blacklisted. I did a Netstat -a and got the following:
tcp 0 0 10.2.8.40:smtp ovalgenius.com:10047 TIME_WAIT
tcp 0 0 localhost.localdomain:smtp localhost.localdomain:42930 TIME_WAIT
tcp 0 0 10.2.8.40:smtp mx1.gc-bmg.com:51384 TIME_WAIT
Where do I start to fix this issue? All help is appreciated!
|
|
|
04-12-2007, 09:46 AM
|
#2
|
Member
Registered: Jun 2003
Posts: 55
Original Poster
Rep:
|
and more
tcp 0 0 10.2.8.40:smtp ipsec10.superactiveme:65209 SYN_RECV
tcp 0 0 10.2.8.40:smtp mx1.fuji-says.com:37985 TIME_WAIT
tcp 0 0 10.2.8.40:smtp mail4.cargill.com:35396 TIME_WAIT
|
|
|
04-12-2007, 10:42 AM
|
#3
|
Member
Registered: Jun 2003
Posts: 55
Original Poster
Rep:
|
a little bit more info. My sendmail server forwards email to a internal exchange server. Do you think it would work if I changed the outgoing smtp port on my sendmail to a different port number? or would this also affect my incoming?
|
|
|
04-12-2007, 08:38 PM
|
#4
|
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Rep:
|
Do you have anything in the mail logs in /var/log/ ? Also post the output of "ps aux" run as root.
|
|
|
04-13-2007, 05:06 PM
|
#5
|
Member
Registered: Mar 2007
Posts: 119
Rep:
|
You have an open relay.
google for the solution.
You might want to consider changing to qmail or postfix, sendmail is notoriously hard to configure.
I think the guy who wrote it is paraphrased as saying, 'if he knew how hard it would have been to write it initially and how much time in maintenance he would need to spend he would never would have written it.'
Once you have stopped the open relay you can work on de-black listing yourself.
|
|
|
04-14-2007, 02:49 PM
|
#6
|
Member
Registered: Apr 2006
Location: Cape Town, South Africa
Distribution: Gentoo 2006.1(2.6.17-gentoo-r7)
Posts: 222
Rep:
|
yes, you need to configure Sendmail correctly. Configure it so that it wont relay for all domains :P (though this might/will differ from your Sendmail needs)
|
|
|
04-14-2007, 07:52 PM
|
#7
|
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Rep:
|
With the minimal info provided, I don't think anyone can say that the system is acting as an open relay and definitively rule out a compromise. Please post the relevant log data and netstat output so that we can rule that out and move on to investigating why it's relaying.
|
|
|
All times are GMT -5. The time now is 12:43 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|