View previous topic :: View next topic |
Author |
Message |
slick Bodhisattva


Joined: 20 Apr 2003 Posts: 3495
|
Posted: Sat Feb 25, 2006 1:03 pm Post subject: Probleme mit Spam - Problem Postfix? |
|
|
Bekomme ich letzter Zeit immer häufiger Mails deren Zustellung ich mir eigentlich nicht erklären kann. Meist an accounting@DOMAIN.de oder support@DOMAIN.de. Das ganze ist Postfix mit virtuellen Domains über mysql. Sämtliche Account-Verwaltung findet in der Mysql statt. Die Accounts sind definitiv nicht vorhanden, und gemäß Log werden die Mails auch nicht akzeptiert, aber wieso kommen manchmal diese dann durch?
Log zu abgelehnten Mails
Code: | Feb 25 11:09:33 [postfix/smtpd] NOQUEUE: reject: RCPT from unknown[61.174.160.163]: 501 <36362798>: Helo command rejected: Invalid name; from=<garlandj@kittymail.com> to=<accounting@DOMAIN.de> proto=SMTP helo=<36362798>
Feb 25 11:10:05 [postfix/virtual] DA8AD47856: to=<accounting@DOMAIN.com>, relay=virtual, delay=0, status=undeliverable (unknown user: "accounting@DOMAIN.com")
Feb 25 11:10:08 [postfix/smtpd] NOQUEUE: reject: RCPT from mout21.kundenservices.net[81.169.163.87]: 550 <accounting@DOMAIN.com>: Recipient address rejected: undeliverable address: unknown user: "accounting@DOMAIN.com"; from=<jimtribulustion@xmail.net> to=<accounting@DOMAIN.com> proto=ESMTP helo=<mout21.kundenservices.net>
Feb 25 11:11:14 [postfix/virtual] 02DDD47856: to=<accounting@DOMAIN.org>, relay=virtual, delay=0, status=undeliverable (unknown user: "accounting@DOMAIN.org")
Feb 25 11:11:17 [postfix/smtpd] NOQUEUE: reject: RCPT from mout21.kundenservices.net[81.169.163.87]: 550 <accounting@DOMAIN.org>: Recipient address rejected: undeliverable address: unknown user: "accounting@DOMAIN.org"; from=<aarondoubton@ureach.com> to=<accounting@DOMAIN.org> proto=ESMTP helo=<mout21.kundenservices.net> |
Auszug Mailheader der ankommenden Mail:
Code: | Received: from mout21.kundenservices.net (mout21.kundenservices.net [81.169.163.87])
by MEINSERVER (Postfix) with ESMTP id A736E47856;
Sat, 25 Feb 2006 11:11:14 +0100 (CET)
Received: from mx30.kundenservices.net ([81.169.163.70])
by mout21.kundenservices.net with esmtp (Exim 4.60)
(envelope-from <aarondoubton@ureach.com>)
id 1FCwOQ-0007Qw-I4; Sat, 25 Feb 2006 11:11:14 +0100
Received: from [220.164.138.245] (helo=3635FBF8)
by mx30.kundenservices.net with smtp (Exim 4.44)
id 1FCwOO-0003tQ-HS; Sat, 25 Feb 2006 11:11:16 +0100
Received: from contravariant.free.fr (free.fr.we-help-u.biz [38.101.0.120])
by regiomontano.com with SMTP id X3QWK507D2
for <accounting@DOMAIN.org>; Sat, 25 Feb 2006 04:10:28 -0600
From: "Casandra Godfrey" <pitprost@outgun.com>
To: "Accounting" <accounting@DOMAIN.org>
Subject: accounting@DOMAIN.org
|
Auszug /etc/postfix/main.cf
Code: | smtpd_recipient_restrictions =
permit_sasl_authenticated
permit_mynetworks
reject_unauth_destination
reject_invalid_hostname
reject_unauth_pipelining
reject_unverified_recipient
reject_non_fqdn_recipient
reject_non_fqdn_sender
reject_unknown_recipient_domain
reject_unknown_sender_domain
reject_rbl_client list.dsbl.org
reject_rbl_client http.dnsbl.sorbs.net
reject_rbl_client socks.dnsbl.sorbs.net
reject_rbl_client smtp.dnsbl.sorbs.net
reject_rbl_client nomail.rhsbl.sorbs.net
virtual_minimum_uid = 1000
virtual_gid_maps = mysql:/etc/postfix/mysql-virtual-gid.cf
virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-maps.cf
virtual_alias_maps = mysql:/etc/postfix/mysql-virtual.cf mysql:/etc/postfix/mysql-virtual-aliases.cf
virtual_uid_maps = mysql:/etc/postfix/mysql-virtual-uid.cf
virtual_mailbox_base = /
alias_maps = mysql:/etc/postfix/mysql-aliases.cf
alias_database = mysql:/etc/postfix/mysql-aliases.cf
|
Wie gesagt, das witzige ist die Accounts sind definitiv nicht vorhanden, warum kommen dann die Mail an? Manche werde ja auch verworfen, siehe Log. Kann mir nicht wirklich einen Reim darauf machen.
Last edited by slick on Wed Mar 01, 2006 6:29 am; edited 1 time in total |
|
Back to top |
|
 |
slick Bodhisattva


Joined: 20 Apr 2003 Posts: 3495
|
Posted: Wed Mar 01, 2006 5:08 am Post subject: |
|
|
*bump*
Keiner eine Idee? Ist echt nervig... service@DOMAIN.de gibt es natürlich auch nicht, kommt aber an:
Code: | Received: from 377829B0 (ARouen-152-1-22-86.w83-115.abo.wanadoo.fr [83.115.136.86])
by MYSERVER (Postfix) with SMTP id D3F8347856;
Tue, 28 Feb 2006 11:21:30 +0100 (CET)
Received: from [108.219.154.70] (HELO coco.tppa.com)
by kichimail.com with SMTP id ACPH8Y6IR7
for <service@DOMAIN.de>; Tue, 28 Feb 2006 04:21:32 -0600
Received: from 168city.com (switchman.168city.com [50.129.218.104])
by mamma.com with SMTP id QJ5AQP20PX
for <service@DOMAIN.de>; Tue, 28 Feb 2006 12:14:32 +0200
From: "Cathy Barber" <todd82@bolt.com>
To: "Service" <service@DOMAIN.de>
Subject: service@DOMAIN.de
Date: Tue, 28 Feb 2006 03:19:32 -0700
X-Mailer: The Bat! (v1.60q)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable
Message-Id: <20060228102130.D3F8347856@MYSERVER>
X-Length: 8366
X-UID: 10765 |
Das die Maschine gehackt wurde halte ich für relativ unwahrscheinlich (aber nicht unmöglich), einziger offener Port von außen ist 25. chkrootkit hat zumindest nichts gefunden. |
|
Back to top |
|
 |
slick Bodhisattva


Joined: 20 Apr 2003 Posts: 3495
|
Posted: Fri Mar 03, 2006 12:07 pm Post subject: |
|
|
So, letzter Versuch, wirklich keiner eine Idee?
*bump* |
|
Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|