http://www.spamcop.net/w3m?i=z771927124zda0d27e7655172dbb1079dcc05d01992z
How can somebody use my qmail in order to send spam? Could my qmail incidently have an open relay? How can I check on that and close it?
Before I stopped qmail via daemontools I had this suspicious netstat:
tcp 0 0 ipx10231.arasis.de:http dialin-145-254-191:3199 SYN_RECV
tcp 24 0 ipx10231.arasis.d:10000 p508DBF81.dip.t-di:4485 CLOSE_WAIT
tcp 0 0 ipx-132-247-190-80:http p508DBF81.dip.t-di:4986 TIME_WAIT
tcp 0 0 ipx10231.arasis.de:http crawler2.googlebo:38592 TIME_WAIT
tcp 0 1 ipx10231.arasis.d:49847 angel-mta6.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49828 angel-mta6.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49830 angel-mta6.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49845 angel-mta5.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49827 angel-mta5.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49811 angel-mta5.whowher:smtp SYN_SENT
tcp 0 0 ipx10231.arasis.de:http dialin-145-254-191:3179 TIME_WAIT
tcp 0 1 ipx10231.arasis.d:49832 angel-mta4.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49782 angel-mta4.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49846 angel-mta3.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49810 angel-mta3.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49819 angel-mta3.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49783 angel-mta3.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49781 angel-mta2.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49831 angel-mta1.whowher:smtp SYN_SENT
tcp 0 1 ipx10231.arasis.d:49812 angel-mta1.whowher:smtp SYN_SENT
I just checked again and this angel-mta3.whowher:smtp is still hitting on my server...
What else is weird is that my webmin cannot load the qmail configuration index anymore although it can load i.e. the sendmail configuration index...
And I just checked out how many qmail processes are running... wow there are couple qmail-remote processes:
[root@ipx10231 root]# ps auxww | grep qmail
root 637 0.0 0.0 1372 252 ? S 2003 0:00 supervise qmail-smtpd
qmaill 643 0.0 0.0 1388 204 ? S 2003 0:00 /usr/local/bin/multilog t /var/log/qmail
qmaill 649 0.0 0.0 1392 256 ? S 2003 0:00 /usr/local/bin/multilog t /var/log/qmail/smtpd
qmails 10543 0.0 0.0 1860 452 ? S Feb18 0:58 qmail-send
qmaill 10544 0.0 0.0 1392 432 ? S Feb18 0:25 splogger qmail
root 10545 0.0 0.0 1392 280 ? S Feb18 0:01 qmail-lspawn ./Maildir/
qmailr 10546 0.0 0.0 1400 304 ? S Feb18 0:31 qmail-rspawn
qmailq 10547 0.0 0.0 1384 292 ? S Feb18 0:05 qmail-clean
root 1417 0.0 0.0 1372 252 ? S Mar08 0:01 supervise qmail-send
qmailr 16872 0.0 0.0 1472 444 ? S 11:45 0:00 qmail-remote yahoo.com angel_looking4u@cb3.so-net.ne.jpacid_burn_tr@yahoo.com
qmailr 16873 0.0 0.0 1472 444 ? S 11:45 0:00 qmail-remote yahoo.com angel_looking4u@cb3.so-net.ne.jpdcm67@yahoo.com
root 17513 1.2 6.8 40324 34888 ? S 11:48 0:05 /usr/libexec/webmin/qmailadmin/index.cgi
root 17516 2.1 0.0 1396 300 ? D 11:48 0:10 /var/qmail/bin/qmail-qread
qmailr 18452 0.0 0.0 1468 460 ? S 11:50 0:00 qmail-remote angelfire.com ammo181@agrarpaedak.athidesaka@angelfire.com
qmailr 19137 0.0 0.0 1472 464 ? S 11:51 0:00 qmail-remote angelfire.com ammo181@agrarpaedak.athideseller@angelfire.com
qmailr 20160 0.0 0.0 1468 460 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhideseng@angelfire.com
qmailr 20161 0.0 0.0 1468 460 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidesert.kgm@angelfire.com
qmailr 20171 0.0 0.0 1472 464 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidetakejo@angelfire.com
qmailr 20181 0.0 0.0 1468 460 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidetakeo@angelfire.com
qmailr 20194 0.0 0.0 1476 464 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidetani@angelfire.com
qmailr 20201 0.0 0.0 1468 460 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidetaro@angelfire.com
qmailr 20202 0.0 0.0 1468 460 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidingcrow@angelfire.com
qmailr 20204 0.0 0.0 1472 464 ? S 11:53 0:00 qmail-remote angelfire.com adamjh2@astro.com.auhidinger@angelfire.com
qmailr 20336 0.0 0.0 1472 464 ? S 11:53 0:00 qmail-remote angelfire.com bingo@catus.ithidn@angelfire.com
qmailr 20346 0.0 0.0 1476 468 ? S 11:53 0:00 qmail-remote angelfire.com bingo@catus.ithidnrainbo@angelfire.com
qmailr 20509 0.0 0.0 1476 468 ? S 11:54 0:00 qmail-remote angelfire.com amml5@bubble.iehidy@angelfire.com
qmailr 20510 0.0 0.0 1476 468 ? S 11:54 0:00 qmail-remote angelfire.com amml5@bubble.iehidyho16@angelfire.com
qmailr 20511 0.0 0.0 1468 460 ? S 11:54 0:00 qmail-remote angelfire.com amml5@bubble.iehidylan@angelfire.com
qmailr 20532 0.0 0.0 1468 460 ? S 11:55 0:00 qmail-remote angelfire.com alien_girl_38574@capitolonline.nlhiebert@angelfire.com
qmailr 20533 0.0 0.0 1468 460 ? S 11:55 0:00 qmail-remote angelfire.com alien_girl_38574@capitolonline.nlhiec@angelfire.com
qmailr 20546 0.0 0.0 1472 464 ? S 11:55 0:00 qmail-remote columbus.rr.com ammalouz@bollebygd.sectguy@columbus.rr.com
And I somehow cannot svc -u /service/qmail-* anymore... It tells me that it cannot connect or localhost:25
Help? I think I need it ![]()
Request notifications