LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-14-2005, 11:26 AM   #1
Yomaoni
Member
 
Registered: Aug 2003
Location: Boise, idaho
Distribution: Red Hat, Fedora, Debian, BSD, CentOS, Ubuntu
Posts: 44

Rep: Reputation: 15
mail server question


Hi all,

I have a question. I've been just given the job of managing our mail server running RHE3 with Qmail and squarrelmail. Resently I've been recieving entries into my logs that look like this:


**Unmatched Entries**
xinetd[2154]: START: sgi_fam pid=9160 from=<no address>
xinetd[2154]: START: sgi_fam pid=10234 from=<no address>
xinetd[2154]: START: sgi_fam pid=11281 from=<no address>
xinetd[2154]: START: sgi_fam pid=12315 from=<no address>
xinetd[2154]: START: sgi_fam pid=13213 from=<no address>
xinetd[2154]: START: sgi_fam pid=14287 from=<no address>
xinetd[2154]: START: sgi_fam pid=15195 from=<no address>
xinetd[2154]: START: sgi_fam pid=16411 from=<no address>
xinetd[2154]: START: sgi_fam pid=17533 from=<no address>
xinetd[2154]: START: sgi_fam pid=18420 from=<no address>
xinetd[2154]: START: sgi_fam pid=18449 from=<no address>
xinetd[2154]: START: sgi_fam pid=18492 from=<no address>
xinetd[2154]: START: sgi_fam pid=18520 from=<no address>
xinetd[2154]: START: sgi_fam pid=18551 from=<no address>
xinetd[2154]: START: sgi_fam pid=18608 from=<no address>
xinetd[2154]: START: sgi_fam pid=19625 from=<no address>
xinetd[2154]: START: sgi_fam pid=20944 from=<no address>
xinetd[2154]: START: sgi_fam pid=22467 from=<no address>
xinetd[2154]: START: sgi_fam pid=23762 from=<no address>
xinetd[2154]: START: sgi_fam pid=24716 from=<no address>
xinetd[2154]: START: sgi_fam pid=25628 from=<no address>
xinetd[2154]: START: sgi_fam pid=27111 from=<no address>


I get several hundred in my logs everyday. Is this someone trying to hack my server or am I looking at something else. Thanks for the help.
 
Old 09-14-2005, 12:24 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
don't worry, it's not a security issue

i think you are looking at something else...

maybe you could disable your fam daemon (if you don't need it)??

http://oss.sgi.com/projects/fam/index.html


from what little i've googled it seems you could also try adding a "flags = NOLIBWRAP" option to your /etc/xinet.d/sgi_fam file:

https://bugzilla.redhat.com/bugzilla....cgi?id=119918

for more info about this: http://www.google.com/linux?&q=flags+nolibwrap

but i might be trippin', though... maybe the nolibwrap thing isn't what you want... either way, i'm sure there's a way to configure either xinetd or fam so as that your logs don't get cluttered... please post the solution if you find it so that others with the same issue can benefit from it...

just my ...


Last edited by win32sux; 09-14-2005 at 12:43 PM.
 
Old 09-14-2005, 02:05 PM   #3
Yomaoni
Member
 
Registered: Aug 2003
Location: Boise, idaho
Distribution: Red Hat, Fedora, Debian, BSD, CentOS, Ubuntu
Posts: 44

Original Poster
Rep: Reputation: 15
not sure if i do need it but I'm trying the "flags = NOLIBWRAP" and will see what happens in the morning when I get my logs. I will let you know.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mail Server question Mow Linux - Software 1 10-08-2003 02:58 PM
mail server question buttnutt Linux - Software 3 06-07-2002 01:34 PM
Mail server question! jmcrtp Linux - Networking 1 03-06-2002 05:27 PM
Mail Server Question Jase Linux - Networking 2 11-29-2001 04:12 PM
Mail Server Question Jase Linux - General 1 11-29-2001 01:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration