|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: John Nichel (john
kegworks.com)
Date: Wed Feb 27 2008 - 10:15:56 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
John Nichel wrote:
> Hi,
>
> Recently our company grew enough to warrant a separate web server.
> This box came as a default RHEL4 install, and since this box only needed
> to send mail out, I just left the default Postfix install on and closed
> off all ports other than 80, 443 and 22. Everything has been working
> fine for about a year now, but I have started to notice some strange
> entries in the log watch for that box....
>
>> Foreign Bounce:
>> To achgo
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.68]
>> said: 550 <achgo
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To achgo
mail.com Msg="host mail-com.mr.outblaze.com[64.62.181.82]
>> said: 550 <achgo
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To aczfm
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.17]
>> said: 550 <aczfm
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To aczfm
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.55]
>> said: 550 <aczfm
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To azrdj
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.55]
>> said: 550 <azrdj
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To azrdj
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.68]
>> said: 550 <azrdj
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To bbzmy
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.55]
>> said: 550 <bbzmy
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To bbzmy
mail.com Msg="host mail-com.mr.outblaze.com[208.36.123.68]
>> said: 550 <bbzmy
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To cewvm
mail.com Msg="host mail-com.mr.outblaze.com[64.62.181.82]
>> said: 550 <cewvm
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>> To cewvm
mail.com Msg="host mail-com.mr.outblaze.com[64.71.166.199]
>> said: 550 <cewvm
mail.com>: User unknown (in reply to RCPT TO command"
>> : 1 Time(s)
>
>
> So on, and so forth. There are a few hundred entries a day like
> this...just random, gibberish addresses. Being that the box won't even
> accept smtp connections, I'm guessing this machine has been compromised
> in some way. I've looked and looked, Googled and Googled, but have
> found nothing. I can look at all these messages in the queue, but I
> haven't found any way to determine who or what put the messages there.
> Any suggestions? Thanks.
>
Nevermind. I found the problem. Seems that an internal app was built
to "send this to a friend" from our product pages, and it's now being
used by spammers.
--
John C. Nichel IV
System Administrator
KegWorks
http://www.kegworks.com
716.362.9212 x16
john
kegworks.com
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]