<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sendmail mischief in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209864#M10422</link>
    <description>Correction:&lt;BR /&gt;&lt;BR /&gt;A INPUT -i eth0 -p tcp -s &lt;IPADDY&gt; --dport 25 -j DROP&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;-A INPUT -i eth0 -p ALL -s &lt;IPADDY&gt; -j DROP&lt;BR /&gt;&lt;BR /&gt;service iptables restart&lt;BR /&gt;&lt;BR /&gt;Same basic idea with ipchains, different syntax.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;/IPADDY&gt;&lt;/IPADDY&gt;</description>
    <pubDate>Fri, 05 Mar 2004 10:43:06 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-03-05T10:43:06Z</dc:date>
    <item>
      <title>Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209859#M10417</link>
      <description>The following snippit from netstat output shows an SMTP connection that has been ESTABLISHED for about a half hour now. Who can suggest how I might figure out what he's up to. Maillog shows no entries for this IP.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[veb@linda veb]$ netstat&lt;BR /&gt;Active Internet connections (w/o servers)&lt;BR /&gt;Proto Recv-Q Send-Q Local Address           Foreign Address         State&lt;BR /&gt;tcp        0      0 cabot-biz.com:smtp      210.117.89.197:4857     ESTABLISHED&lt;BR /&gt;tcp        0     81 linda.local:telnet      veb.local:32853         ESTABLISHED&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Mar 2004 15:00:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209859#M10417</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-03-04T15:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209860#M10418</link>
      <description>&lt;A href="http://www.apnic.net/apnic-bin/whois.pl" target="_blank"&gt;http://www.apnic.net/apnic-bin/whois.pl&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;From a whois lookup, the IP address, 210.117.89.197, belongs to a range designated to the Thrunet company in South Korea.&lt;BR /&gt;&lt;BR /&gt;% [whois.apnic.net node-1]&lt;BR /&gt;% Whois data copyright terms    &lt;A href="http://www.apnic.net/db/dbcopyright.html" target="_blank"&gt;http://www.apnic.net/db/dbcopyright.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;inetnum:      210.116.0.0 - 210.123.255.255&lt;BR /&gt;netname:      KRNIC-KR&lt;BR /&gt;descr:        KRNIC&lt;BR /&gt;descr:        Korea Network Information Center&lt;BR /&gt;country:      KR&lt;BR /&gt;admin-c:      HM127-AP&lt;BR /&gt;tech-c:       HM127-AP&lt;BR /&gt;remarks:      ******************************************&lt;BR /&gt;remarks:      KRNIC is the National Internet Registry&lt;BR /&gt;remarks:      in Korea under APNIC. If you would like to&lt;BR /&gt;remarks:      find assignment information in detail&lt;BR /&gt;remarks:      please refer to the KRNIC Whois DB&lt;BR /&gt;remarks:      &lt;A href="http://whois.nic.or.kr/english/index.html" target="_blank"&gt;http://whois.nic.or.kr/english/index.html&lt;/A&gt;&lt;BR /&gt;remarks:      ******************************************&lt;BR /&gt;mnt-by:       APNIC-HM&lt;BR /&gt;mnt-lower:    MNT-KRNIC-AP&lt;BR /&gt;changed:      hostmaster@apnic.net 19961126&lt;BR /&gt;changed:      hostmaster@apnic.net 20010606&lt;BR /&gt;status:       ALLOCATED PORTABLE&lt;BR /&gt;source:       APNIC&lt;BR /&gt;&lt;BR /&gt;person:       Host Master&lt;BR /&gt;address:      11F, KTF B/D, 1321-11, Seocho2-Dong, Seocho-Gu,&lt;BR /&gt;address:      Seoul, Korea, 137-857&lt;BR /&gt;country:      KR&lt;BR /&gt;phone:        +82-2-2186-4500&lt;BR /&gt;fax-no:       +82-2-2186-4496&lt;BR /&gt;e-mail:       hostmaster@nic.or.kr&lt;BR /&gt;nic-hdl:      HM127-AP&lt;BR /&gt;mnt-by:       MNT-KRNIC-AP&lt;BR /&gt;changed:      hostmaster@nic.or.kr 20020507&lt;BR /&gt;source:       APNIC&lt;BR /&gt;&lt;BR /&gt;inetnum:      210.117.89.0 - 210.117.89.255&lt;BR /&gt;netname:      THRUNET-INFRA-KR&lt;BR /&gt;descr:        Thrunet Co., Ltd (THRUNET)&lt;BR /&gt;descr:        1337-20 Seocho-2dong, Seocho-ku&lt;BR /&gt;descr:        SEOUL&lt;BR /&gt;descr:        137-072&lt;BR /&gt;country:      KR&lt;BR /&gt;admin-c:      NM965-KR&lt;BR /&gt;tech-c:       YH1111-KR&lt;BR /&gt;remarks:      This IP address space has been allocated to KRNIC.&lt;BR /&gt;remarks:      For more information, using KRNIC Whois Database&lt;BR /&gt;remarks:      whois -h whois.nic.or.kr&lt;BR /&gt;mnt-by:       MNT-KRNIC-AP&lt;BR /&gt;remarks:      This information has been partially mirrored by APNIC from&lt;BR /&gt;remarks:      KRNIC. To obtain more specific information, please use the&lt;BR /&gt;remarks:      KRNIC whois server at whois.krnic.net.&lt;BR /&gt;changed:      hostmaster@nic.or.kr 20040112&lt;BR /&gt;source:       KRNIC&lt;BR /&gt;&lt;BR /&gt;person:       Noh myung sun&lt;BR /&gt;descr:        Thrunet Co., Ltd (THRUNET)&lt;BR /&gt;descr:        1337-20 Seocho-2dong, Seocho-ku&lt;BR /&gt;descr:        SEOUL&lt;BR /&gt;descr:        137-072&lt;BR /&gt;country:      KR&lt;BR /&gt;phone:        +82-2-3488-8452&lt;BR /&gt;e-mail:       ip@thrunet.com&lt;BR /&gt;nic-hdl:      NM965-KR&lt;BR /&gt;mnt-by:       MNT-KRNIC-AP&lt;BR /&gt;remarks:      This information has been partially mirrored by APNIC from&lt;BR /&gt;remarks:      KRNIC. To obtain more specific information, please use the&lt;BR /&gt;remarks:      KRNIC whois server at whois.krnic.net.&lt;BR /&gt;changed:      hostmaster@nic.or.kr 20040112&lt;BR /&gt;source:       KRNIC&lt;BR /&gt;&lt;BR /&gt;person:       YU Hye Sook&lt;BR /&gt;descr:        Thrunet Co., Ltd (THRUNET)&lt;BR /&gt;descr:        1337-20 Seocho-2dong, Seocho-ku&lt;BR /&gt;descr:        SEOUL&lt;BR /&gt;descr:        137-072&lt;BR /&gt;country:      KR&lt;BR /&gt;phone:        +82-2-3488-8452&lt;BR /&gt;e-mail:       ip@thrunet.com&lt;BR /&gt;nic-hdl:      YH1111-KR&lt;BR /&gt;mnt-by:       MNT-KRNIC-AP&lt;BR /&gt;remarks:      This information has been partially mirrored by APNIC from&lt;BR /&gt;remarks:      KRNIC. To obtain more specific information, please use the&lt;BR /&gt;remarks:      KRNIC whois server at whois.krnic.net.&lt;BR /&gt;changed:      hostmaster@nic.or.kr 20040112&lt;BR /&gt;source:       KRNIC&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Mar 2004 16:22:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209860#M10418</guid>
      <dc:creator>James A. Donovan</dc:creator>
      <dc:date>2004-03-04T16:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209861#M10419</link>
      <description>Thanks for your efforts. I did the dig -x and whois stuff.&lt;BR /&gt;&lt;BR /&gt;I'm really searching for tools that might give a more detailed look into who's doing what in sendmail.&lt;BR /&gt;&lt;BR /&gt;Thanks for any help.</description>
      <pubDate>Thu, 04 Mar 2004 16:56:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209861#M10419</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-03-04T16:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209862#M10420</link>
      <description>..ahhh...then you could use ethereal to capture and analyze any packets being sent to/from that address.&lt;BR /&gt;&lt;BR /&gt;If you don't have it you can download it from here.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.ethereal.com" target="_blank"&gt;http://www.ethereal.com&lt;/A&gt;</description>
      <pubDate>Thu, 04 Mar 2004 17:58:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209862#M10420</guid>
      <dc:creator>James A. Donovan</dc:creator>
      <dc:date>2004-03-04T17:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209863#M10421</link>
      <description>I've noticed a number of problems with users in Korea attempting driect port 25 connections onto my box.&lt;BR /&gt;&lt;BR /&gt;The problem has been drasticallhy reduced by my upgrade to Red HAt Enterprise ES release 1.  Fedora Core is equivalent.&lt;BR /&gt;&lt;BR /&gt;I have added this ip address range to my /etc/mail/access list. They don't get on my server any more.&lt;BR /&gt;&lt;BR /&gt;I reccomend the following entry added to /etc/sysconfig/iptables configuration:&lt;BR /&gt;&lt;BR /&gt;-A INPUT -i eth0 -p tcp -s &lt;IPADDY&gt; --dport 25 -j DROP&lt;BR /&gt;&lt;BR /&gt;or &lt;BR /&gt;&lt;BR /&gt;-A INPT -i eth0 -p ALL -s &lt;IPADDY&gt; -j DROP&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;&lt;BR /&gt;-A&lt;BR /&gt;&lt;BR /&gt;&lt;/IPADDY&gt;&lt;/IPADDY&gt;</description>
      <pubDate>Fri, 05 Mar 2004 10:42:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209863#M10421</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-03-05T10:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209864#M10422</link>
      <description>Correction:&lt;BR /&gt;&lt;BR /&gt;A INPUT -i eth0 -p tcp -s &lt;IPADDY&gt; --dport 25 -j DROP&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;-A INPUT -i eth0 -p ALL -s &lt;IPADDY&gt; -j DROP&lt;BR /&gt;&lt;BR /&gt;service iptables restart&lt;BR /&gt;&lt;BR /&gt;Same basic idea with ipchains, different syntax.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;/IPADDY&gt;&lt;/IPADDY&gt;</description>
      <pubDate>Fri, 05 Mar 2004 10:43:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209864#M10422</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-03-05T10:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail mischief</title>
      <link>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209865#M10423</link>
      <description>Thanks Steven; I'm still using ipchains on my server. Your ipchains to iptables instructions are printed out and laying here on my desk. Switching over is on my todo list.&lt;BR /&gt;&lt;BR /&gt;I'll try blocking the IP in ipchains for now.&lt;BR /&gt;&lt;BR /&gt;Vern</description>
      <pubDate>Fri, 05 Mar 2004 10:55:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/sendmail-mischief/m-p/3209865#M10423</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-03-05T10:55:28Z</dc:date>
    </item>
  </channel>
</rss>

