LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-05-2006, 03:16 AM   #1
KaraK
LQ Newbie
 
Registered: Jan 2005
Location: UK
Distribution: Mint
Posts: 15

Rep: Reputation: 0
Qmail + SMTP Auth. being bypassed


Hi all,

Am running several Debian Sarge servers with qmail + smtp auth. However I am seeing large amounts of spam mail passing through the servers that appears to be coming via SMTP. So far the only characteristic I've found in common with the mails is that they all use a spoofed FROM: address using one of the IP addresses for that server.

So far the angles I've covered are that its not using the server's address as a spoofed IP (have blocked this at the F/W), it's not being injected locally (as far as I can tell), i think the idea that the there is a compromised mail account and thats being used to send via the auth is unlikely since its affecting ALL our servers including our storemail server which has no mail accounts. Really starting to run out of ideas on how this is getting into the MTA!

I've included a header of one such mail below (have edited our server ip out)

regards,

Andrew

Received: (qmail 27535 invoked by uid 1008); 5 Jul 2006 05:33:30 -0000
Received: from 202.8.87.185 by bfb001 (envelope-from <a214g326pp@[server ip here]>, uid 1002) with qmail-scanner-1.25st
(clamdscan: 0.84/1539. spamassassin: 3.0.3. perlscan: 1.25st.
Clear:RC:0(202.8.87.185):SA:1(6.8/5.0):.
Processed in 4.327631 secs); 05 Jul 2006 05:33:30 -0000
X-Spam-Status: Yes, hits=6.8 required=5.0
X-Spam-Level: ++++++
X-Qmail-Scanner-Mail-From: a214g326pp@[server ip here] via bfb001
X-Qmail-Scanner: 1.25st (Clear:RC:0(202.8.87.185):SA:1(6.8/5.0):. Processed in 4.327631 secs Process 27505)
Received: from ppp-202.8.87.185.revip.proen.co.th (HELO ameillpu-7jat6i) (webmaster@202.8.87.185)
by bfb001.[server domain here] with SMTP; 5 Jul 2006 05:33:26 -0000
From: "mojxks" <A214G326pp@[server ip here]>
Subject: SPAM *** =?GB2312?B?usNfzsRfubJfyc0=?=
To: xudidan@yeah.net
Content-Type: TEXT/HTML
Date: Wed, 5 Jul 2006 13:33:50 +0800
X-Mailer: Microsoft Outlook, Build 10.0.2616
X-Qmail-Scanner-1.25st: added fake MIME-Version header
MIME-Version: 1.0
X-Qmail-Scanner-Message-ID: <115207760789427505@bfb001>

Last edited by KaraK; 07-05-2006 at 03:20 AM.
 
Old 07-05-2006, 07:39 AM   #2
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Quote:
it's not being injected locally (as far as I can tell)
Do you see these mails pass inbound in your F/W then?
It's maybe a pain (depends on your F/W and its logging system) but it could be interesting to be sure that they really are not being injected locally, from a compromised machine for example.
Worst pessimistic scenario first
 
Old 07-05-2006, 07:47 AM   #3
KaraK
LQ Newbie
 
Registered: Jan 2005
Location: UK
Distribution: Mint
Posts: 15

Original Poster
Rep: Reputation: 0
yeah.. had the f/w log all the inbound SMTP and they showed up in there so they are definitely coming from outside. Doesnt rule out the servers themselves being compromised though (although there have been no other indications to date).

I've currently got an Ethereal capture running so I'm hoping that will provide some more information.
 
Old 07-06-2006, 03:19 AM   #4
KaraK
LQ Newbie
 
Registered: Jan 2005
Location: UK
Distribution: Mint
Posts: 15

Original Poster
Rep: Reputation: 0
some further info...

following analysis of the Ethereal dump I've discovered that the SMTP Auth isnt working correctly - it authenticates regardless of what username/password you give it!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Adding SMTP AUTH to qmail Apollo77 Linux - Software 2 11-29-2004 04:59 PM
qmail smtp auth maxut Linux - Software 1 03-04-2004 08:24 AM
SMTP Auth with qmail?! Psykoral Linux - Software 1 12-17-2003 03:33 PM
qmail smtp-auth anyone? bueller? wayloud *BSD 3 02-01-2003 05:08 AM
qmail smtp-auth help wayloud General 0 01-31-2003 02:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration