- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: spam from my server?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2002 04:39 AM
тАО07-01-2002 04:39 AM
Recently we started recieving spam emails, appearing to come from our webserver. Today some users on my network are getting spam emails apparently coming from me.
I realize the "from address" could be spoofed and that they may not actually be sent from either of my servers, but I need to know.
I'm not sure where to begin looking; I know that my sendmail server cannot relay, but that's all I know.
Any assistance would be welcome, particularly if this has happened to you.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2002 05:12 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2002 05:34 AM
тАО07-01-2002 05:34 AM
Re: spam from my server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2002 12:52 PM
тАО07-01-2002 12:52 PM
Re: spam from my server?
Meantime, I closed a door in the firewall, too, although I'm not certain that's where the compromise came from. I watched the logs pretty closely. I had allowed a consultant to ftp to the server from the internet. Yeah, I know, vanilla ftp is insecure. Anyway - no more, I shut that door.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2002 01:19 PM
тАО07-01-2002 01:19 PM
Re: spam from my server?
/var/adm/syslog/mail.log
Reading the log can be somewhat boring but then what log is fun to read. If your HPUX box is being used for the "Spam email" then there will be an entry in the mail.log file for each mail that it sends/receives. At least this will tell you if your box is the culprit and wether you really have "relay" turned off.
Good luck,
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 12:10 AM
тАО07-02-2002 12:10 AM
Re: spam from my server?
daemon was the latest version, but its configuation files were not ... You can test your relay protection at http://www.abuse.net/relay.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 05:26 AM
тАО07-02-2002 05:26 AM
Re: spam from my server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 09:39 AM
тАО07-02-2002 09:39 AM
Re: spam from my server?
>From fmartin@applicatorssales.com Tue Jul 2 13:32:40 EDT 2002
Received: from ARouen-102-1-2-200.abo.wanadoo.fr (ARouen-102-1-2-200.abo.wanadoo.fr [80.11.95.200])
by corp.applicatorssales.com (8.9.3 (PHNE_24419)/8.9.3) with SMTP id NAA01654;
Tue, 2 Jul 2002 13:32:32 -0400 (EDT)
X-Authentication-Warning: corp.applicatorssales.com: ARouen-102-1-2-200.abo.wanadoo.fr [80.11.95.200] didn't use HELO protocol
Message-Id: <3J2Q2.9L2L2W2IKAH.fmartin@applicatorssales.com>
From: fmartin@applicatorssales.com
Received: from applicatorssales.com by OW63EH3.applicatorssales.com with SMTP for fmartin@applicatorssales.com; Tue, 02 Jul 2002 13:36:13 -0500
Date: Tue, 02 Jul 2002 13:36:13 -0500
MIME-Version: 1.0
Subject: You're Paying Too Much
----
So maybe I'm wrong about my server not relaying? 80.11.95.200 seems to be the origination IP... and the "received from OW63EH3.applicatorssales.com" is bogus.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 10:09 AM
тАО07-02-2002 10:09 AM
Re: spam from my server?
I chosen options:
2 Relay OFF
6 Access DB
And in the access DB is the first three octets of my internal network address, like:
192.10.10 RELAY
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 10:45 AM
тАО07-02-2002 10:45 AM
Re: spam from my server?
ARouen-102-1-2-200.abo.wanadoo.fr
I'd say the spam originated from there. They may using you as the from address (forged) because they don't want the bounce if there's a non-delivery opportunity. They're may be using you as the to address because they're spamming you.
Apparently this isn't a relay issue (there's no relay if you're the final recipient). To fix something like this, you have to add a reject rule for ARouen-102-1-2-200.abo.wanadoo.fr in the access database, block access for ARouen-102-1-2-200.abo.wanadoo.fr at a network or computer device, or subscribe to one of the blackhole lists and hope they include ARouen-102-1-2-200.abo.wanadoo.fr
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 10:51 AM
тАО07-02-2002 10:51 AM
Re: spam from my server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-02-2002 11:14 AM
тАО07-02-2002 11:14 AM
Re: spam from my server?
http://www.mail-abuse.org
or
http://brightmail.com
Implementation details are at
http://www.sendmail.org/m4/features.html
{search for rbl}
and
http://mail-abuse.org/rbl/usage.html