Hey,
A client of ours has a OpenNA rpm based linux distribution. Basically its cut down and everything is locked down by default, but anyways. The client phones me today to tell me that their email is not sending and they cant access the world wide web.
So to give you a break down of the packages I am working with here:
- The Exim MTA
- Dansguardian (this had a "cant connect to clam AV socket error)
- ClamAV/Freshclam
So I went into the config file for dansguardian, #`d out the ClamAV reference and it worked... however.. exim did not work. Meaning the client was still unable to send an email.
The problem here is that whoever setup this server used a custom IPTABLES rule set called Giptables. And I am not very very familiar with this, or IPTABLES yet... so because they have dansguardian, it looks like just about every port is firewalled out to be pushed through dansguardian and it looks like exim is the only SMTP server allowed.
Below is a copy of the logs that show the problems I am having and the errors I am getting, so I am hoping that someone out there will be able to help me with this.
When I start clam I get this error:
/var/log/clamav/clamav.log
Code:
Wed May 21 15:00:07 2008 -> Running as user mail (UID 8, GID 12)
Wed May 21 15:00:07 2008 -> Log file size limited to 2097152 bytes.
Wed May 21 15:00:07 2008 -> Reading databases from /var/lib/clamav
Wed May 21 15:00:07 2008 -> Not loading PUA signatures.
Wed May 21 15:00:17 2008 -> ERROR: Malformed database
Wed May 21 15:00:55 2008 -> +++ Started at Wed May 21 15:00:55 2008
Wed May 21 15:00:55 2008 -> clamd daemon 0.92 (OS: linux-gnu, ARCH: i386, CPU: i686)
These are the exim logs
/var/log/maillog
Code:
May 21 12:56:38 mail exim[16137]: [9\20] T To: <david@bat.co.za>
May 21 12:56:38 mail exim[16137]: [10\20] Subject: test
May 21 12:56:38 mail exim[16137]: [11\20] Date: Wed, 21 May 2008 12:30:01 +0200
May 21 12:56:38 mail exim[16137]: [12\20] MIME-Version: 1.0
May 21 12:56:38 mail exim[16137]: [13\20] Content-Type: multipart/alternative;
May 21 12:56:38 mail exim[16137]: [14\20] ^Iboundary="----=_NextPart_000_0010_01C8BB3E.63BD5CA0"
May 21 12:56:38 mail exim[16137]: [15\20] X-Priority: 3
May 21 12:56:38 mail exim[16137]: [16\20] X-MSMail-Priority: Normal
May 21 12:56:38 mail exim[16137]: [17\20] X-Mailer: Microsoft Outlook Express 6.00.2900.2180
May 21 12:56:38 mail exim[16137]: [18\20] X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
May 21 12:56:38 mail exim[16137]: [19\20] X-SA-Do-Not-Run: Yes
May 21 12:56:38 mail exim[16137]: [20/20] X-Broken-Reverse-DNS: no host name for IP address 192.168.1.110
May 21 12:56:38 mail exim[16137]: 2008-05-21 12:56:38 SMTP connection from (Wks6) [192.168.1.110]:1222 I=[192.168.1.254]:25 lost
May 21 12:56:38 mail pop3-login: Login: shantele [192.168.1.110]
May 21 12:56:38 mail pop3-login: SSL_read() syscall failed: EOF [192.168.1.110]
May 21 13:02:05 mail exim[17410]: 2008-05-21 13:02:05 cwd=/ 3 args: send-mail -i root
May 21 13:02:05 mail exim[17410]: 2008-05-21 13:02:05 1Jym57-0004Wo-PE SA: Action: Not running SA because SAEximRunCond expanded to false (Message-Id: 1Jym57-0004Wo-PE). From <root@arb.co.za> (local) for root@arb.co.za
May 21 13:02:05 mail exim[17410]: 2008-05-21 13:02:05 1Jym57-0004Wo-PE <= root@arb.co.za U=root P=local S=13490 T="mail.arb.co.za 05/21/08:13.00 ACTIVE SYSTEM ATTACK!" from <root@arb.co.za> for root
May 21 13:02:05 mail exim[8298]: 2008-05-21 13:02:05 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1Jym57-0004Wo-PE
May 21 13:02:09 mail exim[8298]: 2008-05-21 13:02:09 1Jym57-0004Wo-PE => support@bat.co.za (postmaster@arb.co.za) <root@arb.co.za> F=<root@arb.co.za> R=smarthost T=remote_smtp S=13423 H=smtp.isdsl.net [196.26.208.200] C="250 OK id=1Jym5A-0009JD-AE"
May 21 13:02:09 mail exim[8298]: 2008-05-21 13:02:09 1Jym57-0004Wo-PE Completed
May 21 13:11:38 mail exim[11662]: 2008-05-21 13:11:38 SMTP connection from [192.168.1.110]:1225 I=[192.168.1.254]:25 (TCP/IP connection count = 1)
May 21 13:11:38 mail exim[3202]: 2008-05-21 13:11:38 no IP address found for host wks6 (during SMTP connection from [192.168.1.110]:1225 I=[192.168.1.254]:25)
May 21 13:11:40 mail exim[3202]: 2008-05-21 13:11:40 1JymEO-0000pe-LZ malware acl condition: unable to connect to sophie UNIX socket (/var/run/sophie). errno=2
May 21 13:11:40 mail exim[3202]: 2008-05-21 13:11:40 1JymEO-0000pe-LZ malware acl condition: unable to connect to sophie UNIX socket (/var/run/sophie). errno=2
May 21 13:11:40 mail exim[3202]: 2008-05-21 13:11:40 1JymEO-0000pe-LZ H=(Wks6) [192.168.1.110]:1225 I=[192.168.1.254]:25 F=<shantele@arb.co.za> temporarily rejected after DATA
And in case you need it this is /var/log/messages
Code:
May 21 12:18:13 mail dansguardian: Error connecting to ClamD socket
May 21 12:18:13 mail dansguardian: scanFile/Memory returned error: -1
May 21 12:18:13 mail dansguardian: Error connecting to ClamD socket
May 21 12:18:13 mail dansguardian: scanFile/Memory returned error: -1
May 21 12:19:23 mail dansguardian: Error connecting to ClamD socket
May 21 12:19:23 mail dansguardian: scanFile/Memory returned error: -1
May 21 12:19:24 mail dansguardian: Error connecting to ClamD socket
May 21 12:19:24 mail dansguardian: scanFile/Memory returned error: -1