<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mail questions , maybe a hacker ? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620002#M38462</link>
    <description>The mails are coming from projedy.net.mx and are trying to go to blackplanet.com through your server. So, obviously your server is being unsuccessfully used as a relay.&lt;BR /&gt;&lt;BR /&gt;If the purpose of this server is only for web, you can turn off sendmail on it and comment out 25 from your services.&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
    <pubDate>Mon, 26 Nov 2001 16:33:40 GMT</pubDate>
    <dc:creator>Sridhar Bhaskarla</dc:creator>
    <dc:date>2001-11-26T16:33:40Z</dc:date>
    <item>
      <title>mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619994#M38454</link>
      <description>Hey everyone&lt;BR /&gt;I hope everyone had a good long weekend.Well over the weekend we had a server that had some issue with /var getting full. After digging around I found the big files were in /var/spool/mqueue. Theese files were huge emails with atachments that were just sitting there. The thing is this is not a mail server at all. No dns no nothing.It is running a website. And it is open to the public. I have attached part of my mail.log. My questions are how can I find who is doing this and what they are doing?&lt;BR /&gt;Also I moved the files in the mailq to another dir. have a crash and burn pc set up where I can check theese atachments.Soi f I move them back to /var/spool/mqueue can I force them to be sent to a specific email? Any other advice would be helpfull.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Richard</description>
      <pubDate>Mon, 26 Nov 2001 16:07:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619994#M38454</guid>
      <dc:creator>someone_4</dc:creator>
      <dc:date>2001-11-26T16:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619995#M38455</link>
      <description>Richard,&lt;BR /&gt;&lt;BR /&gt;What kind of products do you have installed on your host? The mail log looked like it was trying send something to prodigy.net and blackplanet.com.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Mon, 26 Nov 2001 16:12:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619995#M38455</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-11-26T16:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619996#M38456</link>
      <description>Hi,&lt;BR /&gt;Mails are from prodigy.net to blackplanet.com.&lt;BR /&gt;You've some large size mails got stuck in mail queue. You can check the details of this mail by opening files start with letter q in /var/spool/mqueue directory and then take action accordingly&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Goodluck&lt;BR /&gt;-USA.&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Nov 2001 16:21:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619996#M38456</guid>
      <dc:creator>Uday_S_Ankolekar</dc:creator>
      <dc:date>2001-11-26T16:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619997#M38457</link>
      <description>I don't think you can force the file in /var/spool/mqueue to be sent to specific email. Looking at the content of that file is as good as looking as reading the email itself. Examine these huge files will give you some indication what is being sent out. As for who is sending it, in my opinion a few areas to look for clues ..&lt;BR /&gt;- syslog file&lt;BR /&gt;- browser history/cache log</description>
      <pubDate>Mon, 26 Nov 2001 16:23:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619997#M38457</guid>
      <dc:creator>S.K. Chan</dc:creator>
      <dc:date>2001-11-26T16:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619998#M38458</link>
      <description>Looks like someone trying to use your server to relay mail.&lt;BR /&gt;&lt;BR /&gt;You can shutdown sendmail in /etc/rc.config.d/mailservs or turn off port 25 in /etc/services.&lt;BR /&gt;&lt;BR /&gt;From the size of them, it must have slowed your webserver access down.</description>
      <pubDate>Mon, 26 Nov 2001 16:25:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619998#M38458</guid>
      <dc:creator>John Bolene</dc:creator>
      <dc:date>2001-11-26T16:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619999#M38459</link>
      <description>Richard,&lt;BR /&gt;&lt;BR /&gt;first of all, if you do not use mail on this computer, turn of either sendmail or block port 25/tcp in your firewall for this host.&lt;BR /&gt;&lt;BR /&gt;Since your server does not seem to have internet DNS configured, all the attempted mail delivery did not work.&lt;BR /&gt;&lt;BR /&gt;This looks very much, like someone wants to use your server as a mail relay, which could be a quite costy thing.&lt;BR /&gt;&lt;BR /&gt;Check your public mailservers as well, for relay features. A public mailserver configured as an "open relay" might be missused.&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;Volker</description>
      <pubDate>Mon, 26 Nov 2001 16:25:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2619999#M38459</guid>
      <dc:creator>Volker Borowski</dc:creator>
      <dc:date>2001-11-26T16:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620000#M38460</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Looks like it is failing to reach relay host name.&lt;BR /&gt;&lt;BR /&gt;Check /var/adm/syslog/mail.log for more details.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Joe.</description>
      <pubDate>Mon, 26 Nov 2001 16:26:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620000#M38460</guid>
      <dc:creator>Joseph Chakkery</dc:creator>
      <dc:date>2001-11-26T16:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620001#M38461</link>
      <description>Richard,&lt;BR /&gt;&lt;BR /&gt;secure your server:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://people.hp.se/stevesk/bastion.html" target="_blank"&gt;http://people.hp.se/stevesk/bastion.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Mon, 26 Nov 2001 16:33:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620001#M38461</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-11-26T16:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620002#M38462</link>
      <description>The mails are coming from projedy.net.mx and are trying to go to blackplanet.com through your server. So, obviously your server is being unsuccessfully used as a relay.&lt;BR /&gt;&lt;BR /&gt;If the purpose of this server is only for web, you can turn off sendmail on it and comment out 25 from your services.&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Mon, 26 Nov 2001 16:33:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620002#M38462</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-11-26T16:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620003#M38463</link>
      <description>Richard:&lt;BR /&gt;&lt;BR /&gt;I have a mail server that is having this same problem with prodigy.net.mx. Did you ever find out a resolution to this problem other than shutting down sendmail?</description>
      <pubDate>Tue, 12 Feb 2002 22:18:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620003#M38463</guid>
      <dc:creator>Tony Rose</dc:creator>
      <dc:date>2002-02-12T22:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620004#M38464</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;i don't think somebody did break into your system. But somebody found your server has open ports. &lt;BR /&gt;&lt;BR /&gt;So he tried to missuse your system. The damage is not done to the system itselfe, but it costs your money and resources.&lt;BR /&gt;&lt;BR /&gt;Check your system for unused open ports and close them as a first reaction.&lt;BR /&gt;&lt;BR /&gt;Someone has postet the link to the bastion host documents; have a look at them.&lt;BR /&gt;&lt;BR /&gt;I would save the logs and mailfiles in case you or your company decides to take them to the police.&lt;BR /&gt;&lt;BR /&gt;Regards Stefan&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Feb 2002 08:26:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620004#M38464</guid>
      <dc:creator>Stefan Schulz</dc:creator>
      <dc:date>2002-02-13T08:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620005#M38465</link>
      <description>Tony,&lt;BR /&gt;They are probably using your and Richards servers as email relays. A lot of people actually blacklist open email relay sites, to check it out go to orbz.org and see if any mail servers in your netblock are listed as open email relays. If not, have them test your server, then see what they say. They will usually recommend how to fix the problem.&lt;BR /&gt;&lt;BR /&gt;GL,&lt;BR /&gt;C</description>
      <pubDate>Wed, 13 Feb 2002 10:15:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620005#M38465</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2002-02-13T10:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620006#M38466</link>
      <description>Hey everyone .. I totaly forgot about this post. But anyways .. I was a relay problem I upgraded to 8.9.3 and turned on the anti relay features and we done. &lt;BR /&gt;&lt;BR /&gt;Thanks everyone&lt;BR /&gt;for your help&lt;BR /&gt;Richard</description>
      <pubDate>Wed, 13 Feb 2002 16:45:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620006#M38466</guid>
      <dc:creator>someone_4</dc:creator>
      <dc:date>2002-02-13T16:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: mail questions , maybe a hacker ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620007#M38467</link>
      <description>Hey guys, I know it has been a while since this forum was updated, but I have some information on prodigy.net.mx. This is a domain that mail is sent to if a computer has the Sircam virus. We have lots of resident students who had this virus, and my mail server was getting slammed hard. I don't know if this was Richard's problem or not, but I thought I would mention it in case someone caught this discussion while searching on prodigy.net.mx.&lt;BR /&gt;&lt;BR /&gt;Also, the blackplanet domain is one that is used by a common spammer, so I would tend to believe that Richard's problem was more along the lines of someone trying to relay, rather than the Sircam.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;-tr</description>
      <pubDate>Wed, 17 Apr 2002 17:49:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/mail-questions-maybe-a-hacker/m-p/2620007#M38467</guid>
      <dc:creator>Tony Rose</dc:creator>
      <dc:date>2002-04-17T17:49:26Z</dc:date>
    </item>
  </channel>
</rss>

