LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-30-2004, 01:44 PM   #1
Fle><
Member
 
Registered: Dec 2003
Location: Vienna | Austria
Distribution: Gentoo
Posts: 52

Rep: Reputation: 15
daily mail "Security-Report"


Hello,

I was used to check roots mail with the command 'mail'. I got everyday a kind of status report of the system: Who logged in via ssh, errors from vsftpd, what was cron doing,...
Suddenly I receive no mails any longer.
Any ideas why?

regards
 
Old 12-30-2004, 11:04 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Did you have logwatch installed? It provides a daily summary of important log messages which is then mailed to root. If that was the messages you were seeing, check /etc/cron.daily/ and make sure that a logwatch is in the directory. It should be a link, so do ls -al and make sure that the file it is linked to exists as well (usually is /etc/log.d/scripts/logwatch.pl). Then try sending a message with logwatch by running "logwatch".

Also, take a look and make sure that syslog is running and that log messages are appearing in the system logs. If you don't see anything current, test it by doing: "logger test" and check system log to confirm logging of "test" message occurred.
 
Old 12-31-2004, 06:09 AM   #3
Fle><
Member
 
Registered: Dec 2003
Location: Vienna | Austria
Distribution: Gentoo
Posts: 52

Original Poster
Rep: Reputation: 15
yeah, it is logwatch (i remember). i checked out, what you have said, and everything seems to be okay. But I get no mail, if I run logwatch - now I know my problem =). If I run 'logwatch --print', I can see the whole report on stdout.
 
Old 12-31-2004, 09:39 AM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
So if you run logwatch without any options, it doesn't mail root any messages? Does your local mail system work (try sending mail to root) or is it only a logwatch problem?
 
Old 12-31-2004, 10:54 AM   #5
Fle><
Member
 
Registered: Dec 2003
Location: Vienna | Austria
Distribution: Gentoo
Posts: 52

Original Poster
Rep: Reputation: 15
it's a mail problem. i can send mails without errors, but i don't receive mails: 'No mail for root'. I tried to send mails with another user -> same problem.
does anybody know, how I can fix this?

Last edited by Fle><; 01-01-2005 at 04:31 PM.
 
Old 01-04-2005, 11:37 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Any error messages in /var/log/maillog?
 
Old 01-05-2005, 11:30 AM   #7
Fle><
Member
 
Registered: Dec 2003
Location: Vienna | Austria
Distribution: Gentoo
Posts: 52

Original Poster
Rep: Reputation: 15
there are a lot...
they are all like this one:
Code:
Dec 26 04:19:44 projekte4 sm-msp-queue[17406]: 
iBQ524nA017175: to=root, ctladdr=root (0/0), delay=00:17:40, 
xdelay=00:03:09, mailer=relay, pri=120042, relay=[127.0.0.1] [127.0.0.1], 
dsn=4.0.0, stat=Deferred: Connection timed out with [127.0.0.1]
if i am right, i'd say, the mailerdaemon is not running. am i right? I've looked for a daemon - i've found sendmail. But I'm not sure, if it is also responsible for receiving mails.
 
Old 01-05-2005, 09:15 PM   #8
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
That error message usually means that sendmail is down/off or your firewall is blocking connections over the loopback interface. However, sendmail should be up if you can send a message. Check with netstat -pant (should see sendmail listening and accepting connections on localhost port 25). Check to make sure that sendmail is running with: ps aux | grep sendmail. Also try restarting the sendmail daemon (service sendmail restart).
 
Old 01-06-2005, 09:16 AM   #9
Fle><
Member
 
Registered: Dec 2003
Location: Vienna | Austria
Distribution: Gentoo
Posts: 52

Original Poster
Rep: Reputation: 15
thanks for your help - now I've found my mistake. In my 'delusion of security' I've scanned my box for opened ports. After that I was closing all ports I thought I do not need to be opened. Because of I had no mailserver installed (I thought ), I closed port 25 - smtp using iptables. Now I've opened it again, but only for the localhost.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"Your monitor didn't report its X- and Y-Size" in Suse 9.1 rollo Linux - Laptop and Netbook 9 10-18-2005 01:21 PM
mysql install error says "please submit bug report" learnfast Linux - Newbie 1 04-30-2005 09:26 AM
repquota (and edquota) report incorrect "used" blocks/inodes.. marcolof Linux - General 0 02-18-2005 09:26 AM
"Report to Moderator" question Mega Man X LQ Suggestions & Feedback 7 08-13-2004 11:20 AM
"mail" and "mailx" lost. yapp Slackware 2 10-27-2003 11:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration