LxCenter HyperVM & Kloxo Support

Forum



Members   Search      Help    Register    Login    Home
Home » LxCenter » GNU/Linux Help » Qmail - Mass Spamming(SPAM)
Qmail - Mass Spamming [message #73322] Thu, 18 March 2010 07:29 Go to next message
thecokey is currently offline thecokey  United Kingdom
Messages: 262
Registered: March 2008
Location: UK
Senior Member
Hi

I have a serious problem with qmail, I have a LOT of entries similar to this when I do a ps -aux:

qmailr 25412 0.0 0.1 4816 1184 pts/0 S 11:29 0:00 qmail-remote ltinet.com ecainfo@uneca.org alichild@ltinet.com

And I have now been blacklisted by one spam list.

Can somebody please help with this.
I have checked that I am not an open relay so I am not sure how these are being sent.

Regards
Col


http://www.cwdev.co.uk
Cambridge Website Design, SEO and Bespoke I.T. Development.
Re: Qmail - Mass Spamming [message #73324 is a reply to message #73322] Thu, 18 March 2010 08:26 Go to previous messageGo to next message
thecokey is currently offline thecokey  United Kingdom
Messages: 262
Registered: March 2008
Location: UK
Senior Member
Just discovered that UID 0 (root) is sending the email.

Any help identifying the issue would be a huge help.

Cheers
Col


http://www.cwdev.co.uk
Cambridge Website Design, SEO and Bespoke I.T. Development.
Re: Qmail - Mass Spamming [message #73330 is a reply to message #73324] Thu, 18 March 2010 16:27 Go to previous messageGo to next message
Walter  Brazil
Messages: 865
Registered: February 2009
Location: Florianopolis / BR
Senior Master
Forum Moderator
LxCenter Project Manager

Are you hosting "uneca.org" domain?
Re: Qmail - Mass Spamming [message #73334 is a reply to message #73322] Thu, 18 March 2010 16:50 Go to previous messageGo to next message
thecokey is currently offline thecokey  United Kingdom
Messages: 262
Registered: March 2008
Location: UK
Senior Member
Hi

Odd question.
No I do not host that domain.

Regards
Col


http://www.cwdev.co.uk
Cambridge Website Design, SEO and Bespoke I.T. Development.
Re: Qmail - Mass Spamming [message #73335 is a reply to message #73322] Thu, 18 March 2010 17:15 Go to previous messageGo to next message
Walter  Brazil
Messages: 865
Registered: February 2009
Location: Florianopolis / BR
Senior Master
Forum Moderator
LxCenter Project Manager

I ask because of this:

qmail-remote ltinet.com ecainfo@uneca.org alichild@ltinet.com
                |              |                  |
          [remote host]  [e-mail from]      [e-mail to]


Check the logs to see if the e-mails are actually delivered (@ /var/log/kloxo).

And if you are now blacklisted, it's possible your mail server is an open relay.
Re: Qmail - Mass Spamming [message #73336 is a reply to message #73322] Thu, 18 March 2010 17:58 Go to previous messageGo to next message
thecokey is currently offline thecokey  United Kingdom
Messages: 262
Registered: March 2008
Location: UK
Senior Member
Hi

Thanks for your reply.
I was not sure of the contents of the qmail-remote log, thanks.

I have checked the server with http://www.mailradar.com/openrelay/
and passed all tests.

All the spam was being generated from a small class c address which I have now blocked which has stopped the spam attack.

However, it does not explain how the spammer bypassed qmail.

Any more ideas would be thankfully accepted.

Thanks again.

Col


http://www.cwdev.co.uk
Cambridge Website Design, SEO and Bespoke I.T. Development.
Re: Qmail - Mass Spamming [message #73339 is a reply to message #73322] Thu, 18 March 2010 20:24 Go to previous messageGo to next message
Walter  Brazil
Messages: 865
Registered: February 2009
Location: Florianopolis / BR
Senior Master
Forum Moderator
LxCenter Project Manager

Not enough info so I could help you further.
But I'll give you a couple tips.

Follow RFC 2142 guidelines (see item 4). Create an alias or an e-mail to deal with abuse (spam). That's where people or automated systems will try to contact you to solve an issue. If it doesn't exist, go to DNSBL, do not pass go, do not collect $200.

Check APF, BFD and CSF. Special attention to DNSBL. CSF or APF, pick one - never both.
Re: Qmail - Mass Spamming [message #73348 is a reply to message #73322] Fri, 19 March 2010 05:58 Go to previous message
thecokey is currently offline thecokey  United Kingdom
Messages: 262
Registered: March 2008
Location: UK
Senior Member
Hi

Again thanks for your replies.
I already had all the email accounts setup as per the RFC.

My server is locked down pretty tight. I have key based ssh access only. Iptables rules that allow only the minimum.

I have done a registered scan with abuse.net for a mail relay and passed all the tests.

As far as I am aware my qmail confs and as they should be.

I am puzzled on how this one spammer was able to use my server as a relay.

Any clues on where to start looking?

Haystack and needle is starting ring true here Smile

Regards
Col



http://www.cwdev.co.uk
Cambridge Website Design, SEO and Bespoke I.T. Development.
Previous Topic:Cannot see my drupal page, when set with online server.
Next Topic:xinetd notifications
Goto Forum:
  


Current Time: Wed May 22 17:59:32 EDT 2013

Total time taken to generate the page: 0.01116 seconds
.:: Contact :: Home :: Privacy ::.

Click here to lend your support to: LxCenter and make a donation at www.pledgie.com !

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software