LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-18-2008, 03:33 AM   #1
i_nomad
Member
 
Registered: Mar 2008
Distribution: RedHatES4
Posts: 144

Rep: Reputation: 15
Possible mail server breach


I was checking the mail logs and observed an ip adddress successfully accessing a mailbox. There was no tls used by the user..just looked like a normal in the clear imap connection.

I contacted the end user to see if they were aware of using any other networks and they can assure thay have not. I have traced the IP address to a satellite provider who I have sent an email to..

The system is using postfix and cyrus. Relay has been locked down but I am concerned about the imap which can use imaps as well but I have left imap port open as well. I suppose I should block 143. I initially allowed this due to pda access which did not have tls functionality.

In this case what is the best thing to do?

Regards

Last edited by i_nomad; 09-18-2008 at 03:36 AM.
 
Old 09-18-2008, 05:18 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by i_nomad View Post
In this case what is the best thing to do?
Simple. Provide your users (and yourself) clarity.

You could start by auditing the machine for (unauth'ed) access (see the CERT Intruder Detection Checklist for a handy list of pointers), then verify the integrity of the machine. Post any findings if you want a second opinion.

Sure, some will say that that's over the top and way too much hassle for something that "clearly does not constitute a compromise". Unfortunately that's a lazy and short-sighted point of view. Running GNU/Linux is all about performance, protecting assets and providing services in a continuous, stable and secure way. You want to keep it that way. You want to ascertain you alone control the system and correct things where necessary.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to monitor web server, FTP server, Mail server and database server vodka33us Programming 1 06-16-2008 04:20 AM
How to connect linux mail server with the exchange mail server nanuseenu Linux - Newbie 4 03-04-2008 03:37 AM
can we configure a Linux server with mail server,file server and web server kumarx Linux - Newbie 5 09-09-2004 06:21 AM
security breach: send mail to unknown address? graffitici Linux - Security 4 01-29-2004 05:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration