Mail Server Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationMail Server Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 8th, 2004, 09:25 AM
bper bper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2001
Posts: 12 bper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 21 m 14 sec
Reputation Power: 0
How Can I Tell if My Sendmail Server is being used for spam by a hacker?

Hi,

I believe that I've configured sendmail so that only certain machines and users are allowed to send mail from my server.

In my logwatch email, I can see that there are unknown users listed in the sendmail begin section.

I have also seen at times relaying denied messages from other users.

Does this mean that I have configured sendmail correctly to deny unauthorized use or does it mean that someone has gotten in somehow but just hasn't cracked the safe yet?

Is there a log file that shows what messages has been sent out and by what users?

Thanks.

Reply With Quote
  #2  
Old July 8th, 2004, 11:21 AM
obi_wonton's Avatar
obi_wonton obi_wonton is offline
(not) Banned
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2004
Location: Toronto, CANADA
Posts: 598 obi_wonton User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 4 m 13 sec
Reputation Power: 5
You config is running fine. If they get the relaying denied error, it means your server is refusing to send (relay) mail from them to another mail server. They have to be able to connect so that they can send your server mail, so no, they have not 'hacked' in.

Reply With Quote
  #3  
Old July 23rd, 2004, 11:54 AM
bper bper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2001
Posts: 12 bper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 21 m 14 sec
Reputation Power: 0
thanks a lot.

Reply With Quote
  #4  
Old July 30th, 2004, 02:21 PM
dba_frog's Avatar
dba_frog dba_frog is offline
cave painting, the 1st Opn Src
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2003
Posts: 394 dba_frog User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 h 55 m 5 sec
Reputation Power: 6
I will argue with Obi Wonton on this one.

If you 'feel' you've been hacked, then follow your gut young grasshopper.

spend a little time checking the log files in /var/logs. Snoop around a little and see if your server is sending an inordinate amount of emails. Do you have bounce backs from accts not on your system.

I'm not saying your 'hacked', but you may want to spend some time poking around. One is never safe in the wild west of the WWW.

just my 2 cents worth...

Frog
__________________
Curious by Nature,
Linux by Choice

Reply With Quote
  #5  
Old August 2nd, 2004, 06:51 PM
obi_wonton's Avatar
obi_wonton obi_wonton is offline
(not) Banned
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2004
Location: Toronto, CANADA
Posts: 598 obi_wonton User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 4 m 13 sec
Reputation Power: 5
Quote:
Originally Posted by dba_frog
I will argue with Obi Wonton on this one.

If you 'feel' you've been hacked, then follow your gut young grasshopper.

spend a little time checking the log files in /var/logs. Snoop around a little and see if your server is sending an inordinate amount of emails. Do you have bounce backs from accts not on your system.

I'm not saying your 'hacked', but you may want to spend some time poking around. One is never safe in the wild west of the WWW.

just my 2 cents worth...

Frog


I'd normally agree with that, but this sounds like a newbie post. The 'symtoms' he/she reported sound like completely normal traffic. I really wouldn't worry, but checking your logs regularly is definitely a must.
__________________
May the source be with you - obi_wonton

Reply With Quote
  #6  
Old August 4th, 2004, 04:02 PM
nogginthenog nogginthenog is offline
Principal Goatkeeper
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Location: Galway, Ireland
Posts: 157 nogginthenog User rank is Corporal (100 - 500 Reputation Level)nogginthenog User rank is Corporal (100 - 500 Reputation Level)nogginthenog User rank is Corporal (100 - 500 Reputation Level)nogginthenog User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 18 h 26 m
Reputation Power: 6
try hacking it yourself - telnet to your server and try to send mail 'manually' to addresses not in your domain.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationMail Server Help > How Can I Tell if My Sendmail Server is being used for spam by a hacker?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway