LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-18-2010, 11:02 AM   #1
tom_sawyer70
LQ Newbie
 
Registered: Jul 2009
Posts: 21

Rep: Reputation: 1
Sendmail on RHEL 5.3


I have been asked to look into an issue with a RHEL 5.3 server with Sendmail on it. Apparently, the server is scanning for SMTP ports on external servers, about once every two minutes or so. The server had been up for a month prior to this activity which started a couple of days ago. In the interim, the server was shut down.

So tonight the server will be brought back online and I'll get to look at it. While the server has Sendmail on it, it may not even be a Sendmail issue.

Malware could be a culprit, but the server is behind a firewall and relatively locked down from service accounts, etc.

Any thoughts on either something specific to Sendmail that might be generating requests or anything else to investigate?

TIA,
Dave
 
Old 02-18-2010, 04:37 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
What exactly do you mean by 'scanning' ? .. attempting to send mail ? Have a look at /var/log/maillog, see if the activity is initiated by sendmail.

cheers
 
Old 02-18-2010, 04:38 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If you have access to the machine you could boot a Live CD and scrape off all logs for analysis (logwatch, slst, grep?) if not then I'd boot it with a firewall ruleset that restricts access to your management IP (range) and at least -j LOG all traffic unless you have access to router logs. Wrt router logs, if you're going to do analysis then take those into account to, there might be some things to be learnt from scanned addresses or ranges. Wrt checking things I'd say read and perform the usual routine like with any system you suspect.
 
Old 02-19-2010, 12:32 PM   #4
tom_sawyer70
LQ Newbie
 
Registered: Jul 2009
Posts: 21

Original Poster
Rep: Reputation: 1
Quote:
Originally Posted by kbp View Post
What exactly do you mean by 'scanning' ? .. attempting to send mail ? Have a look at /var/log/maillog, see if the activity is initiated by sendmail.

cheers
It's apparently sending out requests. Our firewall is seeing this:

"Date" "Time" "Action" "Service" "Source" "Destination" "Protocol"
"18Feb2010" "21:16:56" "Drop" "smtp" "xx.xx.xx.xx" "fk-in-f27.1e100.net" "tcp"
"18Feb2010" "21:18:29" "Drop" "smtp" "xx.xx.xx.xx" "fk-in-f27.1e100.net" "tcp"
"18Feb2010" "21:20:05" "Drop" "smtp" "xx.xx.xx.xx" "mail-ew0-f60.google.com" "tcp"
"18Feb2010" "21:21:38" "Drop" "smtp" "xx.xx.xx.xx" "mail-ew0-f60.google.com" "tcp"

/var/log/maillog and the associated versions going back a few weeks are all zero bytes.

Sendmail is not in active processes and there is nothing in top that looks peculiar.
 
Old 02-19-2010, 04:24 PM   #5
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
Try 'netstat -tunlp' as root to list all the listening processes... if there's nothing on tcp/25 then it's possible it's malware, it could also be an app of some kind ( java? ).. I've seen developers configure them to send email directly out rather than via the local mta

cheers
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to configure sendmail in RHEL 5 abhijeetdutta Linux - Server 1 08-31-2009 09:41 PM
rhel-sendmail krilo6by Linux - Server 1 11-30-2008 06:19 AM
Sendmail works but only after "sendmail restart" on RHEL 5 Tralobyte Linux - Server 2 06-15-2008 03:19 AM
Sendmail 8.13 on RHEL 4 mks_jangra Linux - Server 7 02-27-2008 03:10 AM
RHEL 4 and Sendmail Corrado Red Hat 1 09-01-2005 03:25 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration