LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-12-2007, 09:44 AM   #1
mrlucio79
Member
 
Registered: Jun 2003
Posts: 55

Rep: Reputation: 15
Unhappy ahhh my sendmail is sending spam?!?!


I am currently running Sendmail 8.13.7 on FC5 and totally blacklisted. I did a Netstat -a and got the following:

tcp 0 0 10.2.8.40:smtp ovalgenius.com:10047 TIME_WAIT
tcp 0 0 localhost.localdomain:smtp localhost.localdomain:42930 TIME_WAIT
tcp 0 0 10.2.8.40:smtp mx1.gc-bmg.com:51384 TIME_WAIT


Where do I start to fix this issue? All help is appreciated!
 
Old 04-12-2007, 09:46 AM   #2
mrlucio79
Member
 
Registered: Jun 2003
Posts: 55

Original Poster
Rep: Reputation: 15
Unhappy

and more

tcp 0 0 10.2.8.40:smtp ipsec10.superactiveme:65209 SYN_RECV
tcp 0 0 10.2.8.40:smtp mx1.fuji-says.com:37985 TIME_WAIT
tcp 0 0 10.2.8.40:smtp mail4.cargill.com:35396 TIME_WAIT
 
Old 04-12-2007, 10:42 AM   #3
mrlucio79
Member
 
Registered: Jun 2003
Posts: 55

Original Poster
Rep: Reputation: 15
Question

a little bit more info. My sendmail server forwards email to a internal exchange server. Do you think it would work if I changed the outgoing smtp port on my sendmail to a different port number? or would this also affect my incoming?
 
Old 04-12-2007, 08:38 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Do you have anything in the mail logs in /var/log/ ? Also post the output of "ps aux" run as root.
 
Old 04-13-2007, 05:06 PM   #5
Zention
Member
 
Registered: Mar 2007
Posts: 119

Rep: Reputation: 16
You have an open relay.

google for the solution.

You might want to consider changing to qmail or postfix, sendmail is notoriously hard to configure.

I think the guy who wrote it is paraphrased as saying, 'if he knew how hard it would have been to write it initially and how much time in maintenance he would need to spend he would never would have written it.'

Once you have stopped the open relay you can work on de-black listing yourself.
 
Old 04-14-2007, 02:49 PM   #6
coolb
Member
 
Registered: Apr 2006
Location: Cape Town, South Africa
Distribution: Gentoo 2006.1(2.6.17-gentoo-r7)
Posts: 222

Rep: Reputation: 30
yes, you need to configure Sendmail correctly. Configure it so that it wont relay for all domains :P (though this might/will differ from your Sendmail needs)
 
Old 04-14-2007, 07:52 PM   #7
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
With the minimal info provided, I don't think anyone can say that the system is acting as an open relay and definitively rule out a compromise. Please post the relevant log data and netstat output so that we can rule that out and move on to investigating why it's relaying.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sendmail - Spam Abuse tgrist Linux - Security 4 08-22-2006 08:58 AM
spam and sendmail Ammad Linux - Networking 1 12-14-2005 09:55 AM
Spam and sendmail Jonpittam Linux - Software 2 09-30-2004 06:56 AM
EXIM - sending spam from PHP scrips GRisha Linux - Software 0 06-05-2004 11:07 AM
Sendmail Spam MrJoshua Linux - Software 1 08-14-2003 10:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration