LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-01-2002, 03:24 AM   #1
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Rep: Reputation: 30
Question Damn spammers!!!


They are messing up my sendmail. My mail gets looped because they somehow include email address
<>@mydomain.com and for some reason mail starts looping and fills up my var partition.

Any suggestions
i rejected mail to
<>@mydomain.com
but need to check if <> aren't some special charaters for access db
 
Old 06-01-2002, 03:50 AM   #2
MasterC
LQ Guru
 
Registered: Mar 2002
Location: Salt Lake City, UT - USA
Distribution: Gentoo ; LFS ; Kubuntu ; CentOS ; Raspbian
Posts: 12,613

Rep: Reputation: 69
Damn them all to hell!!! If you have less than 20 or so people, you could just setup their accounts exclusively.
 
Old 06-01-2002, 11:27 AM   #3
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Original Poster
Rep: Reputation: 30
no the problem is external abusers. they setup their spam so it appears to be from our local domain and use our sendmail to spam others, and we'll get blocked
 
Old 06-01-2002, 12:56 PM   #4
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Rep: Reputation: 15
Use qmail (www.qmail.org). It's much easier to configure than sendmail (worked with both) and you can easily specify who is allowed to do what - which is what it seems your problem is. You can mail me with any questions (koningshoed@freemail.absa.co.za).
 
Old 06-01-2002, 02:36 PM   #5
danrees
Member
 
Registered: Jul 2001
Posts: 114

Rep: Reputation: 15
Postfix is also quite simple but powerful at the same time, and tries to be compatible with sendmal.
 
Old 06-01-2002, 03:45 PM   #6
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Original Poster
Rep: Reputation: 30
I'm not sure, put so much time into sendmail, and set it up with kav. But I'll have to give it a try
 
Old 06-02-2002, 05:08 AM   #7
MartBrooks
Member
 
Registered: May 2002
Location: London
Distribution: Debian
Posts: 388

Rep: Reputation: 31
You could start using RBL databases to block these connections. I get exactly no spam whatsoever these days.

Regards
 
Old 06-02-2002, 09:52 AM   #8
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Original Poster
Rep: Reputation: 30
you mean blackhole?
but the blackhole won't help if spammers are messing up mail headers so the sendmail accepts is as trusted mail and start sending spam
 
Old 06-02-2002, 10:14 AM   #9
MartBrooks
Member
 
Registered: May 2002
Location: London
Distribution: Debian
Posts: 388

Rep: Reputation: 31
Of course it will, as the initial connection will be refused before any sending of mail is done. Here's yesterday's reject log from my mail server:

2002-06-01 07:43:06 recipients from fep02.superonline.com [212.252.122.41] refused
------------------------------------------------------------------------------
2002-06-01 10:19:25 recipients refused from 122.reverse237.fmcf.fr [217.112.237.122] (RBL relays.osirusoft.com)
------------------------------------------------------------------------------
2002-06-01 19:12:04 recipients from fep02.superonline.com [212.252.122.41] refused
------------------------------------------------------------------------------
2002-06-01 20:08:08 recipients refused from 01-086.067.popsite.net [64.24.72.86] (RBL relays.osirusoft.com)
------------------------------------------------------------------------------
2002-06-01 21:10:19 recipients from [66.237.120.201] refused (failed to find host name from IP address)
------------------------------------------------------------------------------
2002-06-01 23:48:25 recipients from [66.180.237.58] refused (failed to find host name from IP address)
------------------------------------------------------------------------------
2002-06-02 01:46:00 recipients refused from lsmail6.oin2.com [65.118.64.251] (RBL relays.osirusoft.com)
------------------------------------------------------------------------------
2002-06-02 05:48:41 recipients from [210.187.6.26] refused (failed to find host name from IP address)
------------------------------------------------------------------------------
clues:/var/log/exim# cat rejectlog
2002-06-02 13:25:59 refused relay (host) to <areyoublind@aol.com> from <firstcomm1@china.com> H=adsl-32-102-242.bhm.bellsouth.net (mail.china.com) [67.32.102.242]
------------------------------------------------------------------------------
2002-06-02 13:25:59 refused relay (host) to <cutco@inbox.lv> from <firstcomm1@china.com> H=adsl-32-102-242.bhm.bellsouth.net (mail.china.com) [67.32.102.242]
------------------------------------------------------------------------------

Regards
 
Old 06-02-2002, 01:54 PM   #10
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Rep: Reputation: 15
Or just set up a list of trusted ip's (obviously you know what the ip's of you lan is). Then set up rules for who's allowed to relay any mail, and the rest will only be allowed to "deliver" mail to your system.
 
Old 06-02-2002, 03:23 PM   #11
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Original Poster
Rep: Reputation: 30
I have customers on differnet isp's so can't just use a few ip's, but I think it's possible to fool sendmail just with headers in sendmail
 
Old 06-02-2002, 04:44 PM   #12
MartBrooks
Member
 
Registered: May 2002
Location: London
Distribution: Debian
Posts: 388

Rep: Reputation: 31
So solve the problem, not the symptons.
 
Old 06-03-2002, 02:46 PM   #13
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Rep: Reputation: 15
Ooh, that is bad. I don't know how hetzner does it (www.hetzner.co.za) but they require pop action before smtp, in that way, you have to read your mail before you can send any, this will confirm your ip to the server and then you can be sure that the user on that ip is in fact a user of your system (they managed to authenticate with pop). Hope you can find a package to do this (try telnetting into their smtp server - most packages advertize in the header line).
 
Old 06-04-2002, 05:20 AM   #14
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Original Poster
Rep: Reputation: 30
that's a good way of doing it, but how to explain customers why they they always get relaying denied if they forgot to check their mail
 
Old 06-04-2002, 03:00 PM   #15
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Rep: Reputation: 15
That is not my problem. Perhaps have another net-detect utility that tries to connect to the server every one minute to report the ip, if the program does not connect for 5 minutes drop that ip from the list of allowed relayers? Just use ipchains or something similar to sumarily block everyone you don't want - permitting your not anyone's mx entry .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
spammers problem hinetvenkat Linux - Security 0 06-07-2005 06:09 AM
Very mad with spammers zidane2010 General 13 05-26-2004 01:57 PM
Spammers should be dragged out and shot! Pcghost Linux - Software 3 05-07-2003 08:54 AM
Spammers... Artimus LQ Suggestions & Feedback 10 03-18-2003 04:24 PM
Damn it kwigibo Programming 1 04-02-2002 04:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration