LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-14-2003, 12:41 PM   #1
andy18
Member
 
Registered: Oct 2002
Location: Malaysia
Posts: 106

Rep: Reputation: 15
detecting spam


Hello ,

I suspect our server has been exploit by spammers.I believe the spammer has place a script on the server and executed it ... How do I detect out the spammer as the header of the subject, To and From always change....

I have tried executed the find command but was not able to get anything ..

I am using Linux 7.3 with Exim as the mail server...is there any spamguard that can be installed on the server to scan ?

thanks,
 
Old 12-14-2003, 05:32 PM   #2
J_Szucs
Senior Member
 
Registered: Nov 2001
Location: Budapest, Hungary
Distribution: SuSE 6.4-11.3, Dsl linux, FreeBSD 4.3-6.2, Mandrake 8.2, Redhat, UHU, Debian Etch
Posts: 1,126

Rep: Reputation: 58
Are you sure it is a spammer script on your machine? Do not you happen to have an open mail relay instead? It would be more likely.

Last edited by J_Szucs; 12-14-2003 at 05:36 PM.
 
Old 12-15-2003, 09:53 PM   #3
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
If you suspect that someone has placed scripts/programs/data on your server and is able to execute them, then you should take that server offline until it can be cleaned and fixed.
 
Old 12-15-2003, 10:49 PM   #4
mac_phil
Member
 
Registered: Sep 2003
Distribution: Mandrake 10.0
Posts: 200

Rep: Reputation: 30
That's very unlikely in my opinion. Spam comes from open relays, not scripts.
 
Old 12-15-2003, 10:59 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
It's not very unlikely. There's a guest column on SecurityFocus from last week detailing how a spammer used an automated script to breakin to a Red Hat box and use it as a spam zombie. The exploit was very advanced. You can find the article linked (currently the last item on the page) in the "links" section of my site http://www.amaunetsgothique.com/chort/email-sec/

As for what to do about it, run tcpdump ... should be something like this:
# tcpdump -nXttt dst port 25

See what you come up with. If you have a graphical interface (i.e. X) on your machine, then you can use Ethereal to sniff the traffic. When you see a tcp stream going to port 25 on some foreign IP, you can right click on any of the packets and do "decode tcp stream". That will show you the entire transaction, including the helo, mail from, and the body of the message.

Also, check in the links section of my site, near the top there is a link to MAPS TSI anti-relay. It has instructions for making sure your MTA (Exim) is not an open relay). My site has many tips on fighting spam (about 50% of the "threats" section has been filled out so far). If you're looking to do it for free, then you're going to want to look into SpamAssassin and setting up some RBL look-ups.
 
Old 12-16-2003, 11:06 AM   #6
andy18
Member
 
Registered: Oct 2002
Location: Malaysia
Posts: 106

Original Poster
Rep: Reputation: 15
hello,

i tried with ur website but was not able to get the link...
 
Old 12-16-2003, 11:35 AM   #7
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Could you tell us what led you to believe that your system is being used to send spam. While it may not seem like such a big deal, you could potentially be mailing millions of unsolicited emails per day, so those of us who have to wade through a river of spam in our inboxes have a vested interest in seeing it stopped.

Please provide any relevent log entries from (/var/log/mesages, /var/log/maillog, etc) so we have a better idea of how to proceed. If you think that it's a script, then give us a list of running processes that seem out of the ordinary to you (especially anything that is consuming lots of resources (use the top command)). Right now you haven't really told us why you think it's a unauthorized script that was run by a cracker as opposed to just having a miss-configured mailserver that allows open relaying.
 
Old 12-16-2003, 11:38 AM   #8
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally posted by andy18
hello,

i tried with ur website but was not able to get the link...
Sorry about that, what error are you getting? I'm showing outside traffic hitting it so I do not believe it's a firewall problem and I haven't changed DNS in weeks. Could you be a bit more specific, please?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
detecting my IP jonaskoelker Linux - Networking 5 01-16-2005 06:45 AM
procmail and spam -- do not send out of office auto replay to spam draix Linux - Software 0 12-30-2004 08:35 AM
detecting '\t' haobaba1 Programming 5 02-22-2004 11:01 AM
What other anti-spam for Linux that can be used, other than Spam assassin? johnportiz Linux - Software 6 01-27-2004 03:17 AM
Spam talmor Linux - Security 6 04-02-2002 03:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration