store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 10:24 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: Spam through our server
Unread postPosted: Thu Mar 08, 2012 5:16 pm 
Offline
Forum User
Forum User

Joined: Fri Dec 14, 2007 11:35 am
Posts: 40
Hi,

We recently started to get tons of spam through our server:

Image


I have changed all email passwords for the domain flamingoblinds.co.uk and ban the IP address trying to connect to IMAP but it looks like it's still able to do it.

What am I doing wrong please?

Code:
[root@zeus ~]# grep 10073 /etc/passwd
qscand:x:10073:156:Qmail-Scanner Account:/var/spool/qscan:/bin/false
[root@zeus ~]#



Image


Image


Image


Top
 Profile  
 
 Post subject: Re: Spam through our server
Unread postPosted: Fri Mar 09, 2012 10:37 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
If I understand you corrrectly, the qscand user isnt the one logging in thats the user the mailservers antivirus system uses. So if you didnt change the passwords for the mailuser then they may still be logging in as that user.

As for blacklisting the IP, thats done via the kernels firewalling system. What are your firewall rules:

iptables -L -n

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Spam through our server
Unread postPosted: Sat Mar 10, 2012 12:04 am 
Offline
Forum User
Forum User

Joined: Fri Dec 14, 2007 11:35 am
Posts: 40
Hi Michael,

Thanks for your reply.

According to the dumps in qmhandle he is logging in using info@flamingoblinds.co.uk?!?! There is no such mailuser, it's just an alias to a different user and I have changed all the passwords for that domain.

iptables rules here (long list, .cn, .br and .mx blocked):

http://seology.com/iptables.txt

More maillog concerning info@flamingoblinds.co.uk here:

http://seology.com/spamfb.txt


Top
 Profile  
 
 Post subject: Re: Spam through our server
Unread postPosted: Sat Mar 10, 2012 11:04 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
I'm not seeing what I expect to see from you /usr/psa/var/log/maillog

Assuming this user is sending via smtp, there should be a "connect" entry and/or a "login" entry before any "from" entries. I'm not seeing either in your log extract.

Authenticated smtp logs can also be found in /var/log/secure depending on your config.

Is romani-online your server? If not, then the header might be faked. The whole thing may be generated by a php or perl script. I'm also baffled as to why the bad guy is using a real domain on your server as the "from" address. I've not seen this done before (though I'm not saying it doesn't happen -- just saying I've not seen it done personally). Normally they use any old address.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group