Quote:
Originally posted by Capt_Caveman
Take a look at your mail logs and see if you can find any information on the user sending mail. Also post a few examples from the log if possible.
|
Thk u, Capt_Caveman
I have attached my server maillog some log which is I have think it NOD CORRECT.
*******************
Jul 3 07:43:58 pweb-srv2 sendmail[20654]: /etc/mail/submit.cf: WARNING: dangerous write permissions
Jul 3 07:43:58 pweb-srv2 sendmail[20654]: j62MhwGW020654: from=nobody, size=1869, class=0, nrcpts=1, msgid=<200507022243.j62MhwGW020654@pwe
b-srv2.other-server-domain>, relay=nobody@localhost
Jul 3 07:43:58 pweb-srv2 sm-mta[20656]: j62MhwhH020656: from=<nobody@my-server-domain>, size=2104, class=0, nrcpts=1, msgid=<200507022
243.j62MhwGW020654@my-server-domain>, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1]
Jul 3 07:43:58 pweb-srv2 sendmail[20654]: j62MhwGW020654: to=member@other-server-domain, ctladdr=nobody (99/99), delay=00:00:00, xdelay=00:00:00, m
ailer=relay, pri=30128, relay=localhost.localdomain. [127.0.0.1], dsn=2.0.0, stat=Sent (j62MhwhH020656 Message accepted for delivery)
Jul 3 07:43:58 pweb-srv2 sendmail[20659]: /etc/mail/submit.cf: WARNING: dangerous write permissions
Jul 3 07:43:58 pweb-srv2 sendmail[20659]: j62MhwtR020659: from=nobody, size=1894, class=0, nrcpts=1, msgid=<200507022243.j62MhwtR020659@pwe
b-srv2.other-server-domain>, relay=nobody@localhost
Jul 3 07:43:58 pweb-srv2 sm-mta[20661]: j62MhwhH020661: from=<nobody@my-server-domain>, size=2129, class=0, nrcpts=1, msgid=<200507022
243.j62MhwtR020659@my-server-domain>, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1]
Jul 3 07:43:58 pweb-srv2 sendmail[20659]: j62MhwtR020659: to=rin_2125@yahoo.co.jp, ctladdr=nobody (99/99), delay=00:00:00, xdelay=00:00:00,
mailer=relay, pri=30130, relay=localhost.localdomain. [127.0.0.1], dsn=2.0.0, stat=Sent (j62MhwhH020661 Message accepted for delivery)
Jul 3 07:43:59 pweb-srv2 sm-mta[20663]: j62MhwhH020661: to=<rin_2125@yahoo.co.jp>, ctladdr=<nobody@my-server-domain> (99/99), delay=00
:00:01, xdelay=00:00:01, mailer=esmtp, pri=30365, relay=mta08.mail.yahoo.co.jp. [202.93.87.210], dsn=2.0.0, stat=Sent (ok dirdel)
Jul 3 07:44:15 pweb-srv2 sm-mta[20658]: j62MhwhH020656: to=<member@other-server-domain>, ctladdr=<nobody@my-server-domain> (99/99), delay=00:0
0:17, xdelay=00:00:17, mailer=esmtp, pri=30363, relay=other-dns-name. [xxx.zzz.
www.qqq], dsn=2.0.0, stat=Sent (ok 1120337504 qp 15957)
Jul 3 07:54:12 pweb-srv2 sendmail[20675]: /etc/mail/submit.cf: WARNING: dangerous write permissions
Jul 3 07:54:12 pweb-srv2 sendmail[20675]: j62MsCdf020675: from=nobody, size=2506, class=0, nrcpts=1, msgid=<200507022254.j62MsCdf020675@pwe
*******************