Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Probleme mit Spam - Problem Postfix?
View unanswered posts
View posts from last 24 hours
View posts from last 7 days

 
Reply to topic    Gentoo Forums Forum Index Deutsches Forum (German) Diskussionsforum
View previous topic :: View next topic  
Author Message
slick
Bodhisattva
Bodhisattva


Joined: 20 Apr 2003
Posts: 3495

PostPosted: Sat Feb 25, 2006 1:03 pm    Post subject: Probleme mit Spam - Problem Postfix? Reply with quote

Bekomme ich letzter Zeit immer häufiger Mails deren Zustellung ich mir eigentlich nicht erklären kann. Meist an accounting@DOMAIN.de oder support@DOMAIN.de. Das ganze ist Postfix mit virtuellen Domains über mysql. Sämtliche Account-Verwaltung findet in der Mysql statt. Die Accounts sind definitiv nicht vorhanden, und gemäß Log werden die Mails auch nicht akzeptiert, aber wieso kommen manchmal diese dann durch?

Log zu abgelehnten Mails
Code:
Feb 25 11:09:33 [postfix/smtpd] NOQUEUE: reject: RCPT from unknown[61.174.160.163]: 501 <36362798>: Helo command rejected: Invalid name; from=<garlandj@kittymail.com> to=<accounting@DOMAIN.de> proto=SMTP helo=<36362798>
Feb 25 11:10:05 [postfix/virtual] DA8AD47856: to=<accounting@DOMAIN.com>, relay=virtual, delay=0, status=undeliverable (unknown user: "accounting@DOMAIN.com")
Feb 25 11:10:08 [postfix/smtpd] NOQUEUE: reject: RCPT from mout21.kundenservices.net[81.169.163.87]: 550 <accounting@DOMAIN.com>: Recipient address rejected: undeliverable address: unknown user: "accounting@DOMAIN.com"; from=<jimtribulustion@xmail.net> to=<accounting@DOMAIN.com> proto=ESMTP helo=<mout21.kundenservices.net>
Feb 25 11:11:14 [postfix/virtual] 02DDD47856: to=<accounting@DOMAIN.org>, relay=virtual, delay=0, status=undeliverable (unknown user: "accounting@DOMAIN.org")
Feb 25 11:11:17 [postfix/smtpd] NOQUEUE: reject: RCPT from mout21.kundenservices.net[81.169.163.87]: 550 <accounting@DOMAIN.org>: Recipient address rejected: undeliverable address: unknown user: "accounting@DOMAIN.org"; from=<aarondoubton@ureach.com> to=<accounting@DOMAIN.org> proto=ESMTP helo=<mout21.kundenservices.net>


Auszug Mailheader der ankommenden Mail:
Code:
Received: from mout21.kundenservices.net (mout21.kundenservices.net [81.169.163.87])
   by MEINSERVER (Postfix) with ESMTP id A736E47856;
   Sat, 25 Feb 2006 11:11:14 +0100 (CET)
Received: from mx30.kundenservices.net ([81.169.163.70])
   by mout21.kundenservices.net with esmtp (Exim 4.60)
   (envelope-from <aarondoubton@ureach.com>)
   id 1FCwOQ-0007Qw-I4; Sat, 25 Feb 2006 11:11:14 +0100
Received: from [220.164.138.245] (helo=3635FBF8)
   by mx30.kundenservices.net with smtp (Exim 4.44)
   id 1FCwOO-0003tQ-HS; Sat, 25 Feb 2006 11:11:16 +0100
Received: from contravariant.free.fr (free.fr.we-help-u.biz [38.101.0.120])
       by regiomontano.com with SMTP id X3QWK507D2
       for <accounting@DOMAIN.org>; Sat, 25 Feb 2006 04:10:28 -0600
From: "Casandra Godfrey" <pitprost@outgun.com>
To: "Accounting" <accounting@DOMAIN.org>
Subject: accounting@DOMAIN.org


Auszug /etc/postfix/main.cf
Code:
smtpd_recipient_restrictions =
        permit_sasl_authenticated
        permit_mynetworks
        reject_unauth_destination
        reject_invalid_hostname
        reject_unauth_pipelining
        reject_unverified_recipient
        reject_non_fqdn_recipient
        reject_non_fqdn_sender
        reject_unknown_recipient_domain
        reject_unknown_sender_domain
        reject_rbl_client list.dsbl.org
        reject_rbl_client http.dnsbl.sorbs.net
        reject_rbl_client socks.dnsbl.sorbs.net
        reject_rbl_client smtp.dnsbl.sorbs.net
        reject_rbl_client nomail.rhsbl.sorbs.net
virtual_minimum_uid = 1000
virtual_gid_maps = mysql:/etc/postfix/mysql-virtual-gid.cf
virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-maps.cf
virtual_alias_maps = mysql:/etc/postfix/mysql-virtual.cf mysql:/etc/postfix/mysql-virtual-aliases.cf
virtual_uid_maps = mysql:/etc/postfix/mysql-virtual-uid.cf
virtual_mailbox_base = /
alias_maps = mysql:/etc/postfix/mysql-aliases.cf
alias_database = mysql:/etc/postfix/mysql-aliases.cf

Wie gesagt, das witzige ist die Accounts sind definitiv nicht vorhanden, warum kommen dann die Mail an? Manche werde ja auch verworfen, siehe Log. Kann mir nicht wirklich einen Reim darauf machen.


Last edited by slick on Wed Mar 01, 2006 6:29 am; edited 1 time in total
Back to top
View user's profile Send private message
slick
Bodhisattva
Bodhisattva


Joined: 20 Apr 2003
Posts: 3495

PostPosted: Wed Mar 01, 2006 5:08 am    Post subject: Reply with quote

*bump*

Keiner eine Idee? Ist echt nervig... service@DOMAIN.de gibt es natürlich auch nicht, kommt aber an:

Code:
Received: from 377829B0 (ARouen-152-1-22-86.w83-115.abo.wanadoo.fr [83.115.136.86])
   by MYSERVER (Postfix) with SMTP id D3F8347856;
   Tue, 28 Feb 2006 11:21:30 +0100 (CET)
Received: from [108.219.154.70] (HELO coco.tppa.com)
   by kichimail.com with SMTP id ACPH8Y6IR7
   for <service@DOMAIN.de>; Tue, 28 Feb 2006 04:21:32 -0600
Received: from 168city.com (switchman.168city.com [50.129.218.104])
   by mamma.com with SMTP id QJ5AQP20PX
   for <service@DOMAIN.de>; Tue, 28 Feb 2006 12:14:32 +0200
From: "Cathy Barber" <todd82@bolt.com>
To: "Service" <service@DOMAIN.de>
Subject: service@DOMAIN.de
Date: Tue, 28 Feb 2006 03:19:32 -0700
X-Mailer: The Bat! (v1.60q)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable
Message-Id: <20060228102130.D3F8347856@MYSERVER>
X-Length: 8366
X-UID: 10765


Das die Maschine gehackt wurde halte ich für relativ unwahrscheinlich (aber nicht unmöglich), einziger offener Port von außen ist 25. chkrootkit hat zumindest nichts gefunden.
Back to top
View user's profile Send private message
slick
Bodhisattva
Bodhisattva


Joined: 20 Apr 2003
Posts: 3495

PostPosted: Fri Mar 03, 2006 12:07 pm    Post subject: Reply with quote

So, letzter Versuch, wirklich keiner eine Idee?

*bump*
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Deutsches Forum (German) Diskussionsforum All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum