Nie jesteś zalogowany.
Jeśli nie posiadasz konta, zarejestruj je już teraz! Pozwoli Ci ono w pełni korzystać z naszego serwisu. Spamerom dziękujemy!

Ogłoszenie

Prosimy o pomoc dla małej Julki — przekaż 1% podatku na Fundacji Dzieciom zdazyć z Pomocą.
Więcej informacji na dug.net.pl/pomagamy/.

#1  2016-08-15 23:15:56

  lewyx84 - Użytkownik

lewyx84
Użytkownik
Zarejestrowany: 2013-10-29

Postfix - dziura czy włam

Siema,
od wczoraj w logach widzę

Kod:

Aug 15 22:59:55 gw postfix/submission/smtpd[32241]: warning: unknown[179.158.24.133]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Aug 15 22:59:55 gw postfix/submission/smtpd[32619]: connect from cpe-69-201-178-103.nyc.res.rr.com[69.201.178.103]
Aug 15 22:59:56 gw postfix/submission/smtpd[32241]: lost connection after AUTH from unknown[179.158.24.133]
Aug 15 22:59:56 gw postfix/submission/smtpd[32241]: disconnect from unknown[179.158.24.133]
Aug 15 22:59:56 gw postfix/submission/smtpd[32619]: lost connection after UNKNOWN from cpe-69-201-178-103.nyc.res.rr.com[69.201.178.103]
Aug 15 22:59:56 gw postfix/submission/smtpd[32619]: disconnect from cpe-69-201-178-103.nyc.res.rr.com[69.201.178.103]
Aug 15 22:59:57 gw postfix/submission/smtpd[32619]: connect from c83-248-9-54.bredband.comhem.se[83.248.9.54]
Aug 15 22:59:57 gw postfix/submission/smtpd[32619]: lost connection after UNKNOWN from c83-248-9-54.bredband.comhem.se[83.248.9.54]
Aug 15 22:59:57 gw postfix/submission/smtpd[32619]: disconnect from c83-248-9-54.bredband.comhem.se[83.248.9.54]
Aug 15 22:59:58 gw postfix/submission/smtpd[32242]: connect from 178235170104.ostroleka.vectranet.pl[178.235.170.104]
Aug 15 22:59:58 gw postfix/submission/smtpd[32242]: lost connection after UNKNOWN from 178235170104.ostroleka.vectranet.pl[178.235.170.104]
Aug 15 22:59:58 gw postfix/submission/smtpd[32242]: disconnect from 178235170104.ostroleka.vectranet.pl[178.235.170.104]
Aug 15 22:59:58 gw postfix/submission/smtpd[32233]: connect from CableLink-187-160-84-155.PCs.InterCable.net[187.160.84.155]
Aug 15 22:59:58 gw postfix/submission/smtpd[32426]: warning: hostname CableLink-201-158-83-183.multimedios.net does not resolve to address 201.158.83.183: Name or service not known
Aug 15 22:59:58 gw postfix/submission/smtpd[32426]: connect from unknown[201.158.83.183]
Aug 15 22:59:59 gw postfix/submission/smtpd[32233]: lost connection after UNKNOWN from CableLink-187-160-84-155.PCs.InterCable.net[187.160.84.155]
Aug 15 22:59:59 gw postfix/submission/smtpd[32233]: disconnect from CableLink-187-160-84-155.PCs.InterCable.net[187.160.84.155]
Aug 15 22:59:59 gw postfix/submission/smtpd[32426]: lost connection after UNKNOWN from unknown[201.158.83.183]
Aug 15 22:59:59 gw postfix/submission/smtpd[32426]: disconnect from unknown[201.158.83.183]
Aug 15 22:59:59 gw postfix/submission/smtpd[32619]: warning: hostname b3d915f3.virtua.com.br does not resolve to address 179.217.21.243: Name or service not known
Aug 15 22:59:59 gw postfix/submission/smtpd[32619]: connect from unknown[179.217.21.243]
Aug 15 23:00:00 gw postfix/submission/smtpd[32619]: lost connection after UNKNOWN from unknown[179.217.21.243]
Aug 15 23:00:00 gw postfix/submission/smtpd[32619]: disconnect from unknown[179.217.21.243]
Aug 15 23:00:00 gw postfix/submission/smtpd[32233]: connect from CableLink-187-160-198-109.PCs.InterCable.net[187.160.198.109]
Aug 15 23:00:01 gw postfix/submission/smtpd[32233]: lost connection after UNKNOWN from CableLink-187-160-198-109.PCs.InterCable.net[187.160.198.109]

i dostaję zwrotki o treści

Kod:

This is the mail system at host domena.pl.

I'm sorry to have to inform you that your message could not be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own text from the attached returned message.

                   The mail system

<olegan80@mail.ru>: host mxs.mail.ru[94.100.180.150] said: 550 spam message
    rejected. Please visit
    http://help.mail.ru/notspam-support/id?c=jyQy2uHMuuDp6Q5UxrfrNv2TnZU5qQ4u6pm5zim5AYR2wr4NxqBBudqe9FIUu1esvcKBvsszPjAg8M47YfeECKI-XqVo2HcPO22uhenqLX9Mayt0AnHTh2ciGEqzsFhZ6vxSKGEENMtHjvss6vCAW_2zSlpkLcu-5OSOQ2pP223RYRh9rgzYbT1vH0Q06qEkLzFS9VfkbfZd5oGJCpLuwhrS_HShjvHpbUwlEVry7g_4NnQ-fYZV2qnn2WZPqIfryWA8CCNay1wE5TIEsk5ao602aq3-kY0GAt2-7xm-xunfcWIkf_f4POow4DWmLox6S_xcPMJtBz5dE3LQ0qJh78CEvfz9FK6ghFRInaiNKT5n62fvJQEllQoAAAD9EgEAWL2cLg~~
    or  report details to abuse@corp.mail.ru. Error code:
    DA32248FE0BACCE1540EE9E936EBB7C6959D93FD2E0EA939CEB999EA8401B9290DBEC276B941A0C652F49EDAAC57BB14BE81C2BD303E33CB3BCEF0200884F761A55E3EA20F77D86885AE6D3B7F2DEAE9742B6B4C87D371024A1822675958B0B32852FCEACB3404612CFB8E475B80F0EA5A4AB3FDBECB2D64438EE4E46DDB4F6A7D1861D16DD80CAE441F6F3D24A1EA34F552312FF66DE4578981E65DC2EE920A74FCD21AE9F18EA111254C6D0FEEF25A3E7436F8DA55867D66D9E7A9EB87A84F083C60C95CCB5A230432E504A35A4EB2AD6A36AD068D91FEEFBEDD02E9C6BE19246271DF3CF8F77F35E030EA7A8C2EA63C5CFC4B3E076DC
    (in reply to end of DATA command)

nie za bardzo wiem gdzie szukać rozwiązania. Na pewno jestem zabezpieczony przed open relay.

Offline

 

#2  2016-08-16 00:19:41

  Jacekalex - Podobno człowiek...;)

Jacekalex
Podobno człowiek...;)
Skąd: /dev/urandom
Zarejestrowany: 2008-01-07

Re: Postfix - dziura czy włam

1. Na Sumbission powinieneś mieć autoryzację.

2. Jeśli to włam, to w logach Postfixa powinny być dużo ciekawsze kawałki.

Chyba że, ktoś ma wjazd na roota do twojego serwera, i może majstrować w logach.
W takim wypadku musisz zaorać serwer i następnym razem postawić go porządniej.

To by było na tyle
;-)

Ostatnio edytowany przez Jacekalex (2016-08-16 00:33:14)


W demokracji każdy naród ma taką władzę, na jaką zasługuje ;)
Si vis pacem  para bellum  ;)       |       Pozdrawiam :)

Offline

 

Stopka forum

Powered by PunBB
© Copyright 2002–2005 Rickard Andersson
Nas ludzie lubią po prostu, a nie klikając w przyciski ;-)

[ Generated in 0.009 seconds, 11 queries executed ]

Informacje debugowania

Time (s) Query
0.00010 SET CHARSET latin2
0.00004 SET NAMES latin2
0.00132 SELECT u.*, g.*, o.logged FROM punbb_users AS u INNER JOIN punbb_groups AS g ON u.group_id=g.g_id LEFT JOIN punbb_online AS o ON o.ident='3.143.218.180' WHERE u.id=1
0.00072 REPLACE INTO punbb_online (user_id, ident, logged) VALUES(1, '3.143.218.180', 1732739893)
0.00072 SELECT * FROM punbb_online WHERE logged<1732739593
0.00077 SELECT topic_id FROM punbb_posts WHERE id=304260
0.00071 SELECT id FROM punbb_posts WHERE topic_id=28862 ORDER BY posted
0.00072 SELECT t.subject, t.closed, t.num_replies, t.sticky, f.id AS forum_id, f.forum_name, f.moderators, fp.post_replies, 0 FROM punbb_topics AS t INNER JOIN punbb_forums AS f ON f.id=t.forum_id LEFT JOIN punbb_forum_perms AS fp ON (fp.forum_id=f.id AND fp.group_id=3) WHERE (fp.read_forum IS NULL OR fp.read_forum=1) AND t.id=28862 AND t.moved_to IS NULL
0.00006 SELECT search_for, replace_with FROM punbb_censoring
0.00080 SELECT u.email, u.title, u.url, u.location, u.use_avatar, u.signature, u.email_setting, u.num_posts, u.registered, u.admin_note, p.id, p.poster AS username, p.poster_id, p.poster_ip, p.poster_email, p.message, p.hide_smilies, p.posted, p.edited, p.edited_by, g.g_id, g.g_user_title, o.user_id AS is_online FROM punbb_posts AS p INNER JOIN punbb_users AS u ON u.id=p.poster_id INNER JOIN punbb_groups AS g ON g.g_id=u.group_id LEFT JOIN punbb_online AS o ON (o.user_id=u.id AND o.user_id!=1 AND o.idle=0) WHERE p.topic_id=28862 ORDER BY p.id LIMIT 0,25
0.00081 UPDATE punbb_topics SET num_views=num_views+1 WHERE id=28862
Total query time: 0.00677 s