LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-27-2005, 09:50 AM   #1
rizhun
Member
 
Registered: Jun 2005
Location: England
Distribution: Ubuntu, SLES, AIX
Posts: 268

Rep: Reputation: 47
Am I being Hacked ?


Hello,

I'm having problems with sendmail... Here is an extract from 'logwatch':
Quote:

--------------------- sendmail Begin ------------------------



Bytes Transferred: 12050
Messages Sent: 2
Total recipients: 2

Warning!!!:
Connections Rejected due to high load average 106 Time(s)
Max. Load Avg reached: 24

**Unmatched Entries**
have been rejecting connections on daemon MTA for 25+03:38:26: 1 Time(s)
have been rejecting connections on daemon MTA for 25+18:39:41: 1 Time(s)
have been rejecting connections on daemon MTA for 25+06:38:41: 1 Time(s)
have been rejecting connections on daemon MTA for 25+09:38:56: 1 Time(s)
have been rejecting connections on daemon MTA for 25+15:39:26: 1 Time(s)
have been rejecting connections on daemon MTA for 25+00:38:22: 1 Time(s)
have been rejecting connections on daemon MTA for 25+21:39:56: 1 Time(s)
have been rejecting connections on daemon MTA for 25+12:39:11: 1 Time(s)

---------------------- sendmail End -------------------------
Quote:
[rizhun][/home/rizhun]$ps -ef | grep -i sendmail
root 27397 1 0 15:52 ? 00:00:00 sendmail: rejecting connections on daemon MTA: load average: 23
smmsp 27405 1 0 15:52 ? 00:00:00 sendmail: Queue runner@01:00:00 for /var/spool/clientmqueue
rizhun 27848 27821 0 16:07 pts/5 00:00:00 grep -i sendmail
The only email my server should be sending is a few script out-puts.

Im nervous that I'm being hacked, but I need my email back.
Can anybody help me out with this problem?

Thanks in advance.
 
Old 08-27-2005, 10:32 AM   #2
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 271Reputation: 271Reputation: 271
Not hacked but perhaps a spammer is trying to use your sendmail server as a means to send out spam.. make sure you don't have an open relay and find the IP or source of what is making so many connections by blocking them. And if you only use this to send out email, block port 25 from outside connections.
 
Old 08-27-2005, 10:53 AM   #3
rizhun
Member
 
Registered: Jun 2005
Location: England
Distribution: Ubuntu, SLES, AIX
Posts: 268

Original Poster
Rep: Reputation: 47
An open relay?
Is that a setting in sendmail.cf or a network-related setting?
 
Old 08-28-2005, 12:54 PM   #4
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 271Reputation: 271Reputation: 271
Quote:
Originally posted by rizhun
An open relay?
Is that a setting in sendmail.cf or a network-related setting?
It's a configuration file with sendmail to only allow the hosts you want permission to send email using your email server.
 
Old 09-07-2005, 08:08 AM   #5
antus
LQ Newbie
 
Registered: Oct 2003
Posts: 13

Rep: Reputation: 0
It sounds like your box is over loaded.

"Warning!!!:
Connections Rejected due to high load average 106 Time(s)"

Run top and take a look at your load average. 1 is 100%. It should be probably less than 0.1. If its over 1 then you need to see why. Perhaps your box is not up to the task, or perhaps something in partucular is sucking all the power. Either way running top should shed some light. Its unlikely that you are an open relay unless you have done something stupid to your mail configuration. By default you wont be.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Have I been hacked? Please help linuxboy69 Linux - Security 11 09-07-2005 07:20 AM
Hacked? mikeshn Linux - Security 2 03-12-2004 01:57 PM
Help! Have I been hacked? Tenover Linux - Security 1 11-19-2003 03:24 PM
Did we just get hacked? vous Linux - Security 4 11-17-2003 08:11 AM
am i being hacked? tearinox Linux - Security 5 11-13-2003 06:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration