LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2005, 08:19 AM   #1
xlr8films
LQ Newbie
 
Registered: Mar 2005
Posts: 4

Rep: Reputation: 0
Unhappy Sendmail is wide open


Hi guys and gals,

I am using FC3 with KDE and Evolution as my mail client. Every day, root will receive an email about system status and so forth. In this mail, among other things, I am seeing my sendmail being used even tho I dont use anything except yahoo for my email. So im guessing that someone is using me to relay mail, right?

I turned off the sendmail service already. Is there some way that i can find what was sent through my box or make sendmail more secure?

Thanks in advance.

Xlr8films
 
Old 05-13-2005, 08:59 AM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Re: Sendmail is wide open

Quote:
Originally posted by xlr8films
Is there some way that i can find what was sent through my box or make sendmail more secure?
Code:
# rpm -e sendmail
 
Old 05-13-2005, 10:41 AM   #3
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
Securing sendmail would require some research but if you are not using sendmail for anything its better just to keep it disabled.
 
Old 05-20-2005, 09:22 PM   #4
xlr8films
LQ Newbie
 
Registered: Mar 2005
Posts: 4

Original Poster
Rep: Reputation: 0
Thanks.

Any way I can see whast was sent thru it?
 
Old 05-21-2005, 10:28 PM   #5
javaroast
Member
 
Registered: Apr 2005
Posts: 131

Rep: Reputation: 19
Sendmail

Current sendmail versions will not relay email in their default configuration. Tto see what is being sent through all you have to do is read those system status messages sent to the root email account. These messages are what sendmail is sending. Your system is using sendmail to send those messages. To make a long story short there is likely nothing abnormal going on here, just system services reporting to the root account as they are supposed to.

You can always block port 25 incoming connecting to the local system using iptables to ensure that there are no connections to your local sendmail server.
 
Old 05-21-2005, 11:12 PM   #6
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
/var/log/maillog anyone?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
wide open samba without domain login? FiveFlat Linux - Networking 1 05-19-2005 10:20 AM
Wide Open Server... Pipewrench General 1 10-09-2004 05:30 PM
wide-open samba share hoover93 Linux - Software 3 09-15-2004 01:41 PM
Sendmail: cannot open mail:25 kaffeen Linux - Networking 1 01-17-2004 10:49 AM
sendmail 8.9 open relay subhasis_ray Linux - Software 1 05-27-2003 06:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration