LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-25-2003, 02:08 AM   #1
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
Is this indicative of an open relay?


I'm running qmail, with the qmailqueue and logrelay patches. I noticed the following in the log files this evening

From smtpd logs...
Code:
2003-06-24 23:41:05.127333500 tcpserver: status: 1/20
2003-06-24 23:41:05.127540500 tcpserver: pid 2065 from 218.233.19.200
2003-06-24 23:41:05.177742500 tcpserver: ok 2065 mydomain.net:10.10.201.4:25 :218.233.19.200::4523
2003-06-24 23:41:07.732345500 tcpserver: end 2065 status 0
2003-06-24 23:41:07.732350500 tcpserver: status: 0/20
and from the qmail logs...
Code:
2003-06-24 23:41:07.535523500 new msg 34789
2003-06-24 23:41:07.535530500 info msg 34789: bytes 727 from <edu_web@returnmails.com> qp 2072 uid 1005
2003-06-24 23:41:07.556375500 starting delivery 283: msg 34789 to remote edu_test@hanmail.net
2003-06-24 23:41:07.556382500 status: local 0/10 remote 1/20
2003-06-24 23:41:25.865891500 delivery 283: success: 211.43.197.77_accepted_message./Remote_host_said:_250_2.0.0_h5P6f4tt011912_Message_accepted_for_delivery/
2003-06-24 23:41:25.865901500 status: local 0/10 remote 0/20
2003-06-24 23:41:25.865904500 end msg 34789
To me this looks like I've just been hopped on. I've tried a couple of different online open relay tests and both came out okay, but I can't figure out why this message seems to have been sent successfully.
 
Old 06-25-2003, 07:52 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
A trace on the three addresses supplied shows they're in APNIC and IIRC all within the .kr TLD. Korean netblock owners are not that renowned for their good network management practices, innit?

but I can't figure out why this message seems to have been sent successfully.
Well, what anti-spam measures/reinforcements do you have in place in /var/qmail/control and/or tcp wrappers? Please FUP/Post the restrictions you set Qmail up with to the appropriate forum: Linux-networking.
 
Old 06-27-2003, 03:31 PM   #3
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Arctic
Distribution: Fedora, Debian, OpenSuSE and Android
Posts: 1,820

Rep: Reputation: 46
I would suggest having your mail server tested for open relay by the ordb.org site. It will tell you for sure if you have a problem..
 
Old 06-27-2003, 03:34 PM   #4
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Original Poster
Rep: Reputation: 45
Yep. did that recently and all seemed fine. The problems ocurred after a qmail-scanner install and was traced back to a missing "127." in my smtp rules. Must have looked at that file 20 times before someone else pointed out the mistake (thanks jer!).
 
Old 10-07-2004, 03:25 PM   #5
lsimon4180
Member
 
Registered: Oct 2004
Location: Chicago, IL
Distribution: Fedora Core 2
Posts: 101

Rep: Reputation: 15
hey mcleodnine,

I am having the same issue as you, what file did you have to make the change too and what did you actually change?

Thanks

Lenny
 
Old 10-07-2004, 08:09 PM   #6
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Original Poster
Rep: Reputation: 45
Most qmail how-to's put something like this in their /etc/tcp.smtp
Code:
127.:allow,RELAYCLIENT=""
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I not use open relay? Red Squirrel Linux - Networking 2 08-20-2005 11:31 PM
open relay problem, help please chadi Linux - Newbie 4 11-10-2004 12:17 AM
Open relay gubak Linux - Networking 1 08-25-2004 01:02 PM
How can I tell if my sendmail is an open relay.. Bjorkli Linux - Networking 1 05-28-2004 03:35 AM
open relay slack66 Linux - Security 1 09-28-2003 08:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration