Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

qmail-1.03_5 FreeBSD combo compromised. Suggested reading requested

Status
Not open for further replies.

dmcginn

ISP
Nov 14, 2007
3
Hello all,

I am a network administrator, and our systems administrator has gone on leave of absence for 3 months due to some 'fatherhood' status he recently aquired. Regardless I am now stuck holding the ball for our systems, a field which I am half aquainted at best.

I was wondering if there is any suggested reading that would help me determine how I was compromised and how to prevent this from hapenning again. At the same time if there is any output anyone would like me to capture and include as documentation I would gladly add it.

I am running out of inodes on my machine, which is fine because I don't want to add to the problem!

my /var/log/message file is flooded with pam authentication errors.

my /var/log/auth.log is flooded with invalid attempts to access my box!

This is a production server, and it is running several essential services, from tracking, to dhcp, mail relay services, and acts as a proxy gateway to my internal network.

Any reccomended reading or useful tips are welcome.


 
Hello all.

It seems one of the users within my network was the probable cause. I went into /var/qmail/queue/mess/ folder and looked at some of the mail. It was almost entirely from one IP, and looked like spam. I tracked the IP/MAC and blocked the user.

Still interested in learning more about qmail though, useful links are appreciated, more elegant solutions welcome!
 
qmail can be hardened with tools like
RBL checks
CHKUSER
Anti-virus
Anti-spam
greylisting


some good googling around
"life with qmail"
"netqmail"
"qmail toaster"
"qmail-scanner"
"dspam"
"spamassassin"
"clamav"
"chkuser" (tonix)
"rbl xbl"


D.E.R. Management - IT Project Management Consulting
 
Thanks thedaver. I have been plowing through life with qmail, this stuff is gold
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top