LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-08-2017, 01:13 AM   #1
sanjibgupta
Member
 
Registered: Apr 2003
Location: Kolkata
Posts: 215

Rep: Reputation: 30
stop SMTP


Hi
I have Linux RHEL5 running as as proxy server with no mailing daemon but i have receive mails from the service provider stating mails originating from my machine (xx.xx.xx.11)

Iptables also has
-A OUTPUT -p tcp --dport 25 -j REJECT

PLease help me how to stop any SMTP from this machine from any port.


{
"SMTP CONNECTION": "xx.xx.xx.11->89.#.#.70:25",
"HELO": "[xx.xx.xx.11]",
"MAIL FROM": "<xd###@###ot.de>",
"RCPT TO": "Array
(
[0] => <in###@###la.it>
)
",
"HEADERS": "Message-ID: <58###@###ot.de>
Date: Tue, 07 Mar 2017 20:24:08 +0400
From: <xd###@###ot.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:5.0) Gecko/20110624 Thunderbird/5.0
MIME-Version: 1.0
To: <in###@###la.it>
Subject: Vi offriamo la possibilita di guadagnare fino a 819 eur extra alla settimana.
Content-Type: multipart/alternative;
boundary="------------030404030604030205050105"
This is a multi-part message in MIME format.
--------------030404030604030205050105
Content-Type: text/plain; charset=CP-850; format=flowed
Content-Transfer-Encoding: quoted-printable

",
"MESSAGE BODY": "[hidden]"
}
 
Old 03-08-2017, 07:50 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,632

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by sanjibgupta View Post
Hi
I have Linux RHEL5 running as as proxy server with no mailing daemon but i have receive mails from the service provider stating mails originating from my machine (xx.xx.xx.11)

Iptables also has
-A OUTPUT -p tcp --dport 25 -j REJECT

PLease help me how to stop any SMTP from this machine from any port.
If mail services aren't running on that system, then it's obviously coming from some other system on your network. But you say nothing about what's there, or your environment, so there isn't much we can tell you. While you may be blocking port 25, there are other ports that are used as well, are you blocking those? You don't tell us what mail system(s) are in use at your location, so again...can't tell you much of anything, or even where to check.

However, you're using RHEL5..which is very old, and TOTALLY UNSUPPORTED at this point, and is a commercial, pay-for distro. Are you PAYING for Red Hat support, and have you contacted the support you're paying for, and asked for assistance?

You've also been posting about email for years now...have you checked ANY of the mail logs or done any troubleshooting??? Without details, we can't help, but see any of the numerous other posts about spam emails that you've started over many years for more suggestions.

http://www.linuxquestions.org/questi...sassin-863459/
http://www.linuxquestions.org/questi...em-4175436239/
http://www.linuxquestions.org/questi...il-4175464929/
http://www.linuxquestions.org/questi...lp-4175515218/

Basic mail server hardening has to be done; you've never followed up in any of those other threads, to say if you've done/tried/researched anything regarding it. Again, we are happy to try to help you, but you have to participate in the conversation, give feedback, and provide details.

Last edited by TB0ne; 03-08-2017 at 07:52 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix: Spammer using my mail server SMTP port, How can I stop it ?please Help jamsheduddin Linux - Server 3 11-12-2014 01:36 PM
qmail smtp hang / stop working a few times everyday icechong Linux - Server 8 10-05-2011 08:04 AM
[SOLVED] Stop SMTP hammering via route command? cnmoore Linux - Newbie 8 03-28-2011 12:20 PM
How to stop outside hosts from using my smtp server cyborgprime Linux - Security 2 11-29-2009 06:34 AM
How To Stop All SMTP Traffic to a Domain? carlosinfl Linux - Server 3 04-23-2008 08:25 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration