OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Postfix 2.0.19 problem

From: Aladdin (aladdinantakalnis.lt)
Date: Sat Apr 03 2004 - 04:28:56 CST


Hello,

 

I'm very new with postfix so don't be mad on me. So I moved to postfix from
sendmail. And after that I noticed that my logs started to grow very
rapidly. I even can press Ctrl+R and can see how log grows. It seems that
this is not mail log but that something tries to put file through ftp:-) So
my logs are full of following crap:

 

Apr 3 12:29:11 antakalnis postfix/smtpd[22686]: 1B6055AB5C:
client=www.shioji.net[211.17.149.186]

Apr 3 12:29:11 antakalnis postfix/smtpd[22663]: 525365AB5D:
client=unknown[213.226.135.18]

Apr 3 12:29:11 antakalnis postfix/smtpd[22659]: connect from
unknown[195.119.131.226]

Apr 3 12:29:11 antakalnis postfix/smtpd[22663]: 525365AB5D: reject: RCPT
from unknown[213.226.135.18]: 504 <vmindaug>:

Helo command rejected: need fully-qualified hostname;
from=<216683_nutekejes_trachtibid.ax> to=<216684Aladdinaladdin.re

movethisstuffantakalnis.lt> proto=SMTP helo=<vmindaug>

Apr 3 12:29:11 antakalnis postfix/smtpd[22658]: disconnect from
61-218-228-156.HINET-IP.hinet.net[61.218.228.156]

Apr 3 12:29:11 antakalnis postfix/smtpd[22686]: 1B6055AB5C: reject: RCPT
from www.shioji.net[211.17.149.186]: 450 <aybl

oantakalnis.lt>: User unknown in local recipient table; from=<>
to=<aybloantakalnis.lt> proto=ESMTP helo=<www.shioji.n

et>

Apr 3 12:29:11 antakalnis postfix/smtpd[22665]: connect from
ritig8.rit.reuters.com[199.171.195.9]

Apr 3 12:29:11 antakalnis postfix/smtpd[22676]: disconnect from
p508E5E23.dip.t-dialin.net[80.142.94.35]

Apr 3 12:29:11 antakalnis postfix/smtpd[22673]: C8C995AB5B:
client=unknown[211.5.226.240]

Apr 3 12:29:11 antakalnis postfix/smtpd[22659]: CDB6B5AB5E:
client=unknown[195.119.131.226]

Apr 3 12:29:12 antakalnis postfix/smtpd[22665]: 043145AB60:
client=ritig8.rit.reuters.com[199.171.195.9]

Apr 3 12:29:12 antakalnis postfix/smtpd[22665]: 043145AB60: reject: RCPT
from ritig8.rit.reuters.com[199.171.195.9]: 45

0 <aybloantakalnis.lt>: User unknown in local recipient table; from=<>
to=<aybloantakalnis.lt> proto=ESMTP helo=<ritig

8.rit.reuters.com>

Apr 3 12:29:12 antakalnis postfix/smtpd[22661]: 669DA5AB59: reject: RCPT
from mail525.nifty.com[202.248.37.142]: 450 <a

laddin.removethisstuffantakalnis.lt>: User unknown in local recipient
table; from=<aee07422nifty.com> to=<aladdin.remo

vethisstuffantakalnis.lt> proto=ESMTP helo=<mail525.nifty.com>

Apr 3 12:29:12 antakalnis postfix/smtpd[22659]: CDB6B5AB5E: reject: RCPT
from unknown[195.119.131.226]: 450 <antsue1999

antakalnis.lt>: User unknown in local recipient table; from=<>
to=<antsue1999antakalnis.lt> proto=ESMTP helo=<athena.p

andacom.gr>

Apr 3 12:29:12 antakalnis postfix/smtpd[22562]: disconnect from
mxsf26.cluster1.charter.net[209.225.28.226]

Apr 3 12:29:12 antakalnis postfix/smtpd[22673]: C8C995AB5B: reject: RCPT
from unknown[211.5.226.240]: 450 <akkshun2000

antakalnis.lt>: User unknown in local recipient table; from=<>
to=<akkshun2000antakalnis.lt> proto=ESMTP helo=<ns.sky-i

net.ne.jp>

 

As you can see mail goes to various nonexistent mail addresses under my
domain: antsue1999antakalnis.lt

akkshun2000antakalnis.lt and so on. And connections goes from everywhere:-(
Is it possible to prevent this in some way. Im so tired from these huge
logs. Log fills to 200MB in three days:-( It is unacceptable for me. And I'm
not some kind of open relay:-( HELP ME GUYS!!!