swedendedicated
05/04/11, 16:03
Iemand logt in met smtp en stuurt spam, maar wie?
[root@sha01 log]# lsof -ni tcp:25
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
exim 3432 mail 3u IPv4 7752 TCP *:smtp (LISTEN)
exim 26786 mail 5u IPv4 9282534 TCP 93.158.114.85:smtp->117.2.127.1:20376 (ESTABLISHED)
exim 26786 mail 6u IPv4 9282534 TCP 93.158.114.85:smtp->117.2.127.1:20376 (ESTABLISHED)
exim 26787 mail 5u IPv4 9282536 TCP 93.158.114.85:smtp->117.2.127.1:20381 (ESTABLISHED)
exim 26787 mail 6u IPv4 9282536 TCP 93.158.114.85:smtp->117.2.127.1:20381 (ESTABLISHED)
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] sender verify fail for <ffartemus@ahm.honda.com>: Unrouteable address
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <trofimov@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <trofimova@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <ts@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tsv@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tt@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tur@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tv@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <ty@svetasavina.ru>: Sender verify failed
2011-04-05 16:16:40 H=(localhost) [117.2.127.1] incomplete transaction (RSET) from <amaycy@paigeme.com>
2011-04-05 16:16:44 H=(localhost) [117.2.127.1] incomplete transaction (RSET) from <ffartemus@ahm.honda.com>
2011-04-05 16:17:44 failed to expand condition "${perl{check_limits}}" for lookuphost router: You (unknown) have reached your daily email limit of 200 emails
exim draait nu enkel op 587, 25 heb ik verwijderd maar dat is uiteraard geen oplossing.
[root@sha01 log]# lsof -ni tcp:25
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
exim 3432 mail 3u IPv4 7752 TCP *:smtp (LISTEN)
exim 26786 mail 5u IPv4 9282534 TCP 93.158.114.85:smtp->117.2.127.1:20376 (ESTABLISHED)
exim 26786 mail 6u IPv4 9282534 TCP 93.158.114.85:smtp->117.2.127.1:20376 (ESTABLISHED)
exim 26787 mail 5u IPv4 9282536 TCP 93.158.114.85:smtp->117.2.127.1:20381 (ESTABLISHED)
exim 26787 mail 6u IPv4 9282536 TCP 93.158.114.85:smtp->117.2.127.1:20381 (ESTABLISHED)
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] sender verify fail for <ffartemus@ahm.honda.com>: Unrouteable address
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <trofimov@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <trofimova@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <ts@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tsv@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tt@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tur@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <tv@svetasavina.ru>: Sender verify failed
2011-04-05 16:15:38 H=(localhost) [117.2.127.1] F=<ffartemus@ahm.honda.com> rejected RCPT <ty@svetasavina.ru>: Sender verify failed
2011-04-05 16:16:40 H=(localhost) [117.2.127.1] incomplete transaction (RSET) from <amaycy@paigeme.com>
2011-04-05 16:16:44 H=(localhost) [117.2.127.1] incomplete transaction (RSET) from <ffartemus@ahm.honda.com>
2011-04-05 16:17:44 failed to expand condition "${perl{check_limits}}" for lookuphost router: You (unknown) have reached your daily email limit of 200 emails
exim draait nu enkel op 587, 25 heb ik verwijderd maar dat is uiteraard geen oplossing.