Gentoo Archives: gentoo-user

From: Michael Sullivan <michael@××××××××××××.com>
To: gentoo-user <gentoo-user@l.g.o>
Subject: [gentoo-user] OT - Concerns (possible security threat?)
Date: Tue, 17 Jan 2006 17:21:00
Message-Id: 1137518063.16247.11.camel@camille.espersunited.com
1 I'm concerned. When I got out of the shower just now and came to check
2 my email, I didn't have any. Concerned that sendmail might not be
3 running, I ps'd for it:
4
5 bullet mail # ps ax | grep 'sendmail'
6 9939 ? Ss 0:00 sendmail: Queue runner@00:30:00
7 for /var/spool/clientmqueue
8 10305 ? Ss 0:00 sendmail: accepting connections
9 10801 ? S 0:00 sendmail: ./k0FKmpDE010833
10 gpeplpqel.shankscape.com.: user open
11 10810 pts/0 R+ 0:00 grep sendmail
12
13
14 I see that sendmail is connected with gpeplpqel.shankscape.com. I
15 assume that someone at that host is trying to send mail to my domain,
16 but I checked /var/spool/mail and I didn't see anything from them. I
17 ps'd sendmail again and saw that they were no longer connected. I
18 checked /var/log/maillog and see a bunch of these:
19
20 Jan 17 11:04:10 bullet sm-mta[10801]: k0FKmpDE010833:
21 to=<kkaempf@××××××××××××××××××××.com>, delay=1+20:15:18,
22 xdelay=00:03:10, mailer=esmtp, pri=8599167,
23 relay=gpeplpqel.shankscape.com. [69.25.212.153], dsn=4.0.0,
24 stat=Deferred: Connection timed out with gpeplpqel.shankscape.com.
25
26 Is there a way to make sure that unauthorized people are not sending
27 mail through my domain?
28
29
30 --
31 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] OT - Concerns (possible security threat?) John Jolet <john@×××××.net>
Re: [gentoo-user] OT - Concerns (possible security threat?) Alec Shaner <ashaner@×××××××××.org>