LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-30-2012, 05:33 AM   #1
zhjim
Senior Member
 
Registered: Oct 2004
Distribution: Debian Squeeze x86_64
Posts: 1,748
Blog Entries: 11

Rep: Reputation: 233Reputation: 233Reputation: 233
Exim DKIM DNS exploit Any evidence in logs? or else where


Hi folks,

I just updated my server to close the exim dkim exploit. Five days due since it's been out officaly.

I checked my logs to see if I could find any evidence of a break in but could not see any. Just the "normal" people trying to relay through. Also last log does not shown any awkward things. No changes in services or iptables rules. The only thing "new" is this
Code:
2012-10-21 18:41:57 [14112] SMTP protocol synchronization error (next input sent too soon: pipelining was advertised): rejected "DATA" H=(admin-silo5yeiy) [163.177.112.103]:3748 I=[xx.169.xx.xx]:25 next input="RSET\r\nMAIL FROM:<mrwc@my_domain.tld>\r\nRCPT TO:<xingkong868@126.com>\r\nDATA\r\n"
as well as some people trying to AUTH with the service also AUTH is not advertised. This ones are new.

Next to the question does anyone know of log lines to watch out for that indicate an exploit (succesfull or not) is that within the link above they state that one is not vunerable if one has the warn control = dkim_disable_verify. As far as I know warn is the action taken by exim if the contidtion control = dkim_disable_verify holds true. So I have accept control = dkim_disable_verify. Which is not the same but does it help?

As my mail is not serving any offical stuff and no mail address is known to outside I put my risk beeing a target down. But wearing a bullet proof vest always looks hilerious if one gets head shoot .

All this is on a virtual server now running debian 6.0.6. Should be 6.0.5 before that.
So anyone got anything on this?
 
Old 10-31-2012, 07:30 AM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
163.177.112.103 is China and they have been running amok lately with scripted crap.

Exim link you provided says:
"You are not vulnerable if you built Exim with DISABLE_DKIM or if you
put this at the start of an ACL plumbed into acl_smtp_connect or
acl_smtp_rcpt:

warn control = dkim_disable_verify"

Did you do that?
 
Old 11-06-2012, 01:19 AM   #3
zhjim
Senior Member
 
Registered: Oct 2004
Distribution: Debian Squeeze x86_64
Posts: 1,748

Original Poster
Blog Entries: 11

Rep: Reputation: 233Reputation: 233Reputation: 233
Thanks for the reply.

I have DKIM enabled. But I do not have

Code:
warn control = dkim_disable_verify
but I have

Code:
accept control = dkim_disable_verify
which comes with the standard configuration. I just wonder if accept does do any good. As far as I know warn accepts as well as also printing a log line...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Exim smarthost with DKIM Tornado_Shanks Linux - Server 1 05-13-2010 05:14 AM
LXer: Set Up DKIM For Multiple Domains On Postfix With dkim-milter 2.8.x (CentOS 5.3) LXer Syndicated Linux News 0 09-07-2009 06:20 PM
LXer: Set Up DKIM On Postfix With dkim-milter (CentOS 5.2) LXer Syndicated Linux News 0 04-06-2009 12:30 PM
random crashes, no evidence in any system logs H_TeXMeX_H Linux - Hardware 4 11-05-2007 03:22 AM
Exim Busy / Analysing logs etc MPK Linux - Software 1 02-06-2005 12:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration