OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: tracking local mail generators

From: Tomasz Grobelny (tomaszgrobelny.oswiecenia.net)
Date: Fri Dec 01 2006 - 15:34:38 CST


Dnia Friday, 1 of December 2006 22:26, Ralf Hildebrandt napisaƂ:
> * Tomasz Grobelny <tomaszgrobelny.oswiecenia.net>:
> > In my logs I found this:
> >
> > Nov 27 20:34:45 serwerek postfix/cleanup[8069]: D90AF36B1:
> > message-id=<20061127193445.D90AF36B1poczta.oswiecenia.net>
> > Nov 27 20:34:45 serwerek postfix/qmgr[22561]: D90AF36B1: from=<>,
> > size=5909, nrcpt=1 (queue active)
> >
> > I guess it is locally generated message.
>
> Don't guess, grep:
>
> grep D90AF36B1 /var/log/mail*
That's what I did. The above are the first two lines of output. Later there
are 450 replies from destination server. I also tried my logs in archiv and
nothing more is known about D90AF36B1. But something must have generated this
message, if it wasn't external host (since that would have been stated in the
logs) then, by elimination, it must have been a local process. Am I right?
And if so, which one?
--
Regards,
Tomasz Grobelny