arliehedges
MIS
I could really use some help from anyone out there. I've got a box runing SCO 5.0.5 with sendmail running. Judging by what i've found in syslog i think someone has found this machine and either compromised it or it was never locked down to begin with. Anyways, /root is filling up almost daily since its small and in syslog i've found the following:
(this is just a clip, if we need more i can post it)
ep 9 14:07:52 vhg2149 sendmail[29297]: OAA29297: collect: unexpected close on
onnection from [211.187.135.127], sender=<hqfbb2i7@yahoo.co.kr>: Error 0
ep 9 14:48:43 vhg2149 sendmail[28083]: NAA28083: SYSERR(root): collect: I/O e
or on connection from [211.187.135.127], from=<oxrjga67jcdwdvj@yahoo.co.kr>: C
nection reset by [211.187.135.127]
ep 9 15:04:47 vhg2149 sendmail[2593]: PAA02593: SYSERR(root): collect: I/O er
r on connection from [211.187.135.127], from=<hqfbb2i7@yahoo.co.kr>: Connectio
reset by [211.187.135.127]
ep 9 16:02:27 vhg2149 sendmail[5800]: QAA05800: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 16:33:38 vhg2149 sendmail[3795]: PAA03795: SYSERR(root): collect: I/O er
r on connection from [211.187.135.127], from=<oxrjga67jcdwdvj@yahoo.co.kr>: Co
ection reset by [211.187.135.127]
ep 9 16:45:19 vhg2149 sendmail[8134]: QAA08134: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 16:50:09 vhg2149 sendmail[8369]: QAA08369: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 17:14:24 vhg2149 sendmail[9787]: RAA09787: collect: unexpected close on
nnection from [211.187.135.127], sender=<hqfbb2i7@yahoo.co.kr>: Error 0
ep 9 17:19:24 vhg2149 telnetd[9038]: can't find user in protected password d
abase
I need to figure out how to disable the open relay, and ultimately disable sendmail completely( dont want to if i dont have to ). somebody help!
Thanks in advance
(this is just a clip, if we need more i can post it)
ep 9 14:07:52 vhg2149 sendmail[29297]: OAA29297: collect: unexpected close on
onnection from [211.187.135.127], sender=<hqfbb2i7@yahoo.co.kr>: Error 0
ep 9 14:48:43 vhg2149 sendmail[28083]: NAA28083: SYSERR(root): collect: I/O e
or on connection from [211.187.135.127], from=<oxrjga67jcdwdvj@yahoo.co.kr>: C
nection reset by [211.187.135.127]
ep 9 15:04:47 vhg2149 sendmail[2593]: PAA02593: SYSERR(root): collect: I/O er
r on connection from [211.187.135.127], from=<hqfbb2i7@yahoo.co.kr>: Connectio
reset by [211.187.135.127]
ep 9 16:02:27 vhg2149 sendmail[5800]: QAA05800: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 16:33:38 vhg2149 sendmail[3795]: PAA03795: SYSERR(root): collect: I/O er
r on connection from [211.187.135.127], from=<oxrjga67jcdwdvj@yahoo.co.kr>: Co
ection reset by [211.187.135.127]
ep 9 16:45:19 vhg2149 sendmail[8134]: QAA08134: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 16:50:09 vhg2149 sendmail[8369]: QAA08369: collect: unexpected close on
nnection from [211.187.135.127], sender=<oxrjga67jcdwdvj@yahoo.co.kr>: Error 0
ep 9 17:14:24 vhg2149 sendmail[9787]: RAA09787: collect: unexpected close on
nnection from [211.187.135.127], sender=<hqfbb2i7@yahoo.co.kr>: Error 0
ep 9 17:19:24 vhg2149 telnetd[9038]: can't find user in protected password d
abase
I need to figure out how to disable the open relay, and ultimately disable sendmail completely( dont want to if i dont have to ). somebody help!
Thanks in advance