LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-17-2007, 07:43 AM   #1
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Rep: Reputation: 15
Unhappy ISP mail server help.


I work for a small ISP in NY

I have a mail server running RHEL 4 with postfix + squirrelmail over the past few weeks someone has been sending 100K+ emails through my server and im not sure how to stop them. Could anyone recommend how I could tighting my security on the mail server? sorry if this is vague I can provide more details if needed.
 
Old 08-17-2007, 08:52 AM   #2
ArcLinux
Member
 
Registered: Apr 2005
Location: Fargo, ND
Distribution: Slackware, CentOS
Posts: 87

Rep: Reputation: 20
First of all, is the user a client or a generic user on the net?
Is the user using your smtp server or their own and your just noticing the traffic on 25?
 
Old 08-17-2007, 09:01 AM   #3
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Original Poster
Rep: Reputation: 15
generic user I think.

if it helps here is some of my mail log, im in no way a linux guru know enough to get by.

Quote:
ug 17 09:53:00 mail postfix/smtp[21226]: CA46A5600C7: to=<neptune1619@aol.com>, relay=none, delay=67663, status=deferred (connect to mailin-01.mx.aol.com[64.12.137.249]: server refused to talk to me: 554 (RLY:B1) http://postmaster.info.aol.com/errors/554rlyb1.html )
Aug 17 09:53:01 mail postfix/qmgr[4383]: 2171D5637D6: removed
Aug 17 09:53:01 mail postfix/smtp[24412]: connect to mailin-03.mx.aol.com[64.12.138.120]: server refused to talk to me: 554 (RLY:B1) http://postmaster.info.aol.com/errors/554rlyb1.html (port 25)
Aug 17 09:53:01 mail postfix/smtp[18826]: connect to mailin-01.mx.aol.com[64.12.137.184]: server refused to talk to me: 554 (RLY:B1) http://postmaster.info.aol.com/errors/554rlyb1.html (port 25)
Aug 17 09:53:01 mail postfix/smtp[20645]: connect to mailin-02.mx.aol.com[205.188.157.25]: Connection timed out (port 25)
Aug 17 09:53:01 mail postfix/smtp[21907]: connect to mailin-04.mx.aol.com[205.188.159.216]: server refused to talk to me: 554 (RLY:B1) http://postmaster.info.aol.com/errors/554rlyb1.html (port 25)
Aug 17 09:53:01 mail postfix/smtp[17790]: connect to mailin-01.mx.aol.com[64.12.137.184]: server refused to talk to me: 554 (RLY:B1) http://postmaster.info.aol.com/errors/554rlyb1.html (port 25)



I can sit here and watch thousands of those go by and the emails it sends to go in alphabetical order as they are sent.
 
Old 08-17-2007, 09:19 AM   #4
ArcLinux
Member
 
Registered: Apr 2005
Location: Fargo, ND
Distribution: Slackware, CentOS
Posts: 87

Rep: Reputation: 20
http://www.postfix.org/rate.html
Take a look at that page and search for concurrency.

If that does not work for you, you may have to implement a commercial or personal queue system that you can limit messages sent per IP addr per day.

You can also slow down the response rate of postfix.

all else fails, MAC bind the user and block all email.
 
Old 08-17-2007, 09:51 AM   #5
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Original Poster
Rep: Reputation: 15
great thanks ill take a look.
 
Old 08-17-2007, 10:01 AM   #6
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Original Poster
Rep: Reputation: 15
do you or does anyone else know of anything out there to limit the amount of emails sent from an ip to a domain per day?


for example if joe@whatever.com sends a email to *@aol.com how can I limit joe to only 5 msg per hour to that domain?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Using sendmail to relay mail to ISP mail server Swift&Smart Linux - Software 26 11-09-2008 03:00 PM
MY ISP DNS SERVER IP ...is creating some problems for my mail server daaku_n01 Linux - Networking 2 01-23-2006 05:09 PM
ISP mail server solution evilchild Linux - Networking 2 07-15-2005 07:27 AM
Mail server and ISP robbfen Linux - Security 4 02-24-2004 08:58 PM
cannot ping ISP mail server.... cockblocker Linux - Networking 7 07-09-2003 12:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration