LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-12-2005, 02:22 PM   #1
msound
Member
 
Registered: Jun 2003
Location: SoCal
Distribution: CentOS
Posts: 465

Rep: Reputation: 30
Hit with a nasty DoS


I'm currently running a Postfix mail server on CentOS 4.1 This morning our server started launching a DoS attack on *.hinet.net and *.tw domain names.

I've taken the server offline. But I really can't figure out the cause of the problem. Right now I have our old sendmail server running in its place. The sendmail server has all of the same users, but it is not experiencing the problem.

I've checked the maillog and it does not list the source of the emails (I was hoping for an IP or username). All it says is that the messages are coming from the queue manager.

How would I go about configuring Postfix to prevent it from sending DoS attacks to these two domains?

Thanks.
 
Old 09-12-2005, 02:52 PM   #2
msound
Member
 
Registered: Jun 2003
Location: SoCal
Distribution: CentOS
Posts: 465

Original Poster
Rep: Reputation: 30
some more info:
The problem has got to be with the server itself. the server is no longer accessable from client machines and yet the problem is still there. Do you think reinstalling postfix would help? And if so, how could I go about beefing up security so this doesn't happen again?
 
Old 09-13-2005, 08:16 AM   #3
jtshaw
Senior Member
 
Registered: Nov 2000
Location: Seattle, WA USA
Distribution: Ubuntu @ Home, RHEL @ Work
Posts: 3,892
Blog Entries: 1

Rep: Reputation: 67
Moved: This thread is more suitable in Linux - Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 09-13-2005, 08:17 AM   #4
jtshaw
Senior Member
 
Registered: Nov 2000
Location: Seattle, WA USA
Distribution: Ubuntu @ Home, RHEL @ Work
Posts: 3,892
Blog Entries: 1

Rep: Reputation: 67
Do you allow your postfix server to relay mail from the outside world to other outside world addresses?
 
Old 09-14-2005, 11:10 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Also, what do you mean by a DoS attack? Do you mean some kind of mail flood or is it un-related to the mail service?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Nasty tsclient error NTolerance Linux - Software 4 04-04-2005 01:34 PM
nasty download problem ylts Linux - Software 2 03-06-2005 04:31 AM
WINE and some nasty errors to go with it... Twiggy794 Linux - Software 5 09-18-2003 05:39 PM
Nasty stuff carrja99 General 9 03-05-2003 03:19 PM
Is this someone naughty trying something nasty on my system? neo77777 Linux - Security 4 07-16-2002 11:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration