LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-22-2004, 07:48 AM   #1
slack66
Member
 
Registered: Jul 2003
Location: manila
Distribution: slackware 8 to 9
Posts: 199

Rep: Reputation: 30
unknow user????


hi!
For the past few days, my logwatch entries for Sendmail are full of attempts
to send mail to unknown users no less than two times per. It looks like this
person is working through the alphabet, and all of these are coming from
multiple IP's. I'm pretty sure it is one person as these unknown users
appear to be sequential. Is there anyway I can stop this?

I tried Google'ing, I have searched through FAQ's, but to be honest, I just
don't know what to look for.
 
Old 11-22-2004, 08:06 AM   #2
rjlee
Senior Member
 
Registered: Jul 2004
Distribution: Ubuntu 7.04
Posts: 1,994

Rep: Reputation: 76
If they are all coming from the same IP address, then you can block it from the firewall.

Also, check that you are not running an open mail relay.

You might also look at filtering software like SpamAssassin.
 
Old 11-22-2004, 08:23 AM   #3
slack66
Member
 
Registered: Jul 2003
Location: manila
Distribution: slackware 8 to 9
Posts: 199

Original Poster
Rep: Reputation: 30
i tried to block the ip address thru iptables but it keeps coming with a different ip address??? iam sure that my server is not an open relay server cuz i saw in my maillog that someone try to relay to me and my mailserver reject it
i try also enable dnsl's in sendmail.cf it work in some spammer site like verizon.net but not this one i dont want too install a 3rd party software...
cuz iam afraid to misconfigure my mailserver...can sendmail and iptables do the job???

Last edited by slack66; 11-22-2004 at 08:26 AM.
 
Old 11-22-2004, 03:15 PM   #4
peacebwitchu
Member
 
Registered: Apr 2004
Distribution: Debian
Posts: 185

Rep: Reputation: 30
People are going to try this as long as you have a email server accessible to the internet. All you need to do is make surethat you aren't an open relay and don't worry about it. I get thousands of attempts daily but there is really nothing you can do. Just as if you have a webserver open to the inet you will see thousands of hits from infected boxes looking for .dlls.
 
Old 11-23-2004, 01:01 AM   #5
slack66
Member
 
Registered: Jul 2003
Location: manila
Distribution: slackware 8 to 9
Posts: 199

Original Poster
Rep: Reputation: 30
thk guys! now i know iam not alone to this attack
one more question? if i can not do anything to prevent the attack is there a way to hardening my linux box??? iam using slackware 10.0 thks again!
 
Old 11-23-2004, 09:00 AM   #6
peacebwitchu
Member
 
Registered: Apr 2004
Distribution: Debian
Posts: 185

Rep: Reputation: 30
If you were running postfix you could very easily run it in a chroot environment, I have never tried to run sendmail in a chroot jail but i'm sure it is possible.
 
Old 11-23-2004, 03:19 PM   #7
dmigh
LQ Newbie
 
Registered: Oct 2004
Posts: 29

Rep: Reputation: 15
Hi,
Don't use sendmail.
use exim4 or something else.
http://www.exim.org/

--
 
Old 11-24-2004, 06:03 PM   #8
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
The attack is called a "dictionary attack" and isn't used by anything but spammer 'n00bs" now. The solution you're looking for is tarpitting.

As an alternative, you could write a cron job that inspects the maillog for lots of attempts for invalid users from the same IP and then adds it to the list of DENY IPs in your firewall rules. Beware though, as this can block real (legit) mail in certain circumstances.

RBL checks would probably help too.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
'xterm': unknow terminal type longnam Slackware 2 08-27-2005 09:37 PM
unknow monitor!!!!! vito_huang Red Hat 3 12-11-2004 09:31 PM
kernel panic...... unknow block mrlucio79 Red Hat 6 09-02-2004 08:16 AM
unknow app running at startup toddncl Linux - General 1 08-24-2004 04:57 AM
User Unknow at SendMail ??? URGENT Help ??? freddata Linux - Software 0 03-27-2003 10:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration