The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
postfix melanie_pfefer Linux 2 04-25-2008 07:43 AM
Postfix rbizzell UNIX for Advanced & Expert Users 3 11-03-2006 02:27 AM
One Question about security tayyabq8 Security 9 05-22-2006 07:56 AM
security question blanks UNIX for Dummies Questions & Answers 0 03-01-2005 10:33 AM
UNIX Security Question OBCCBIP UNIX for Dummies Questions & Answers 3 08-09-2004 03:02 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 06-06-2004
Registered User
 

Join Date: Oct 2003
Location: Rio de Janeiro - Brazil
Posts: 37
PostFix security question

I have a Postfix mail server running on my eMac, and been looking at /var/log/mail.log.

I am new to administrating a mail server.

I notice some servers tried to relay messages to unkown recipients in my server, and my Postfix denied access. The "from" and "rcpt to" look very phony.

I did a whois and Ip. And got an answer that these servers are from China and elsewhere.

Don't know exactly what these guys are trying to do with my server. But I blocked their IPs using "sudo ipfw add deny log ip from 111.222.333.444 to any"

Checked my system with "last" command on the terminal, and my firewall is up.

My guess is that they are collecting domain names using the smtp protocol. Next step they might just try to capture the users of server by making requests using a dictionary word followed by @mydomain. The ones that are accepted, they will write on a list. Am I right?

Questions:

1) What are these guys trying to do?

2) Blocking their IPs is relevant or just a waste of time?

3) Can they ruine my low band (64k)?

4) Should I expect them to come back with other requests on my server?

5) What can I do about this to protect my system?

Thanks for your comments...

Bernardo Höhl
Rio de Janeiro - Brazil
Reply With Quote
Forum Sponsor
  #2  
Old 06-06-2004
Registered User
 

Join Date: Jul 2002
Location: new york
Posts: 1,025
blocking their ip at the firewall is the right thing to do. however theres gonna be other people that are gonna try the same thing. you could write a daemon to moniter the mail log file, and for every relay request that is denied you could add the originating ip to the list of ip's to be blocked.
Reply With Quote
  #3  
Old 06-06-2004
Registered User
 

Join Date: Oct 2003
Location: Rio de Janeiro - Brazil
Posts: 37
Thanks for your post Norsk!

You have been very helpfull.
Reply With Quote
  #4  
Old 06-06-2004
Registered User
 

Join Date: Jul 2002
Location: new york
Posts: 1,025
no prob.
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 02:55 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0