jeremynd01
Technical User
I need some serious help here. I setup a postfix server for a friend five years ago, and lately it seems to be sending on a ton of spam. The logs of full of entries like this:
Oct 14 23:05:03 mail postfix/cleanup[30758]: 1BCF12402D: message-id=<20071015030503.1BCF12402D@mail.mungedmydomain.com>
Oct 14 23:05:03 mail postfix/nqmgr[30535]: 1BCF12402D: from=<>, size=3103, nrcpt=1 (queue active)
Oct 14 23:05:04 mail postfix/smtp[30756]: 1BCF12402D: to=<LoriecacophonistSouza@newscientist.com>, relay=my.isps.mailhost.relay.com[207.115.20.115], delay=1, status=sent (250 2.0.0 l9F35DZf011965 Message accepted for delivery)
(I've munged my domain name and relayhost, for privacy).
You can see that this message bogus and has and empty "from" field, and I don't know of any way to trace its origin. I thought it might be a local PC with a virus, but I disabled the entire LAN interface and the messages keep appearing, so they must be either from the outside or the mail server itself. I doubled checked, and postfix is set not to relay any message but from local clients, and abuse.net/relay.html confirms I didn't screw up and make an open relay.
So how can I find out where these things are coming from, so I can plug that hole?? Thanks!
Oct 14 23:05:03 mail postfix/cleanup[30758]: 1BCF12402D: message-id=<20071015030503.1BCF12402D@mail.mungedmydomain.com>
Oct 14 23:05:03 mail postfix/nqmgr[30535]: 1BCF12402D: from=<>, size=3103, nrcpt=1 (queue active)
Oct 14 23:05:04 mail postfix/smtp[30756]: 1BCF12402D: to=<LoriecacophonistSouza@newscientist.com>, relay=my.isps.mailhost.relay.com[207.115.20.115], delay=1, status=sent (250 2.0.0 l9F35DZf011965 Message accepted for delivery)
(I've munged my domain name and relayhost, for privacy).
You can see that this message bogus and has and empty "from" field, and I don't know of any way to trace its origin. I thought it might be a local PC with a virus, but I disabled the entire LAN interface and the messages keep appearing, so they must be either from the outside or the mail server itself. I doubled checked, and postfix is set not to relay any message but from local clients, and abuse.net/relay.html confirms I didn't screw up and make an open relay.
So how can I find out where these things are coming from, so I can plug that hole?? Thanks!