My mail server is attacked, i don't know if it come from inside or out side. lots of email were sent to yahoo, hotmail, etc, making other legitimate email on queue. please help.....
machine. sun cobalt qube 3 pro, (like redhat). sendmail v8.10.2, apache v1.3.20 Sun Cobalt, mailscanner v4.45.4-1
got lot like this on the log.
Dec 12 05:58:49 kube3 sendmail[31696]: kBBLho831696: from=httpd, size=8993, class=0, nrcpts=329, msgid=<200612112143.kBBLho831696@kube3.surfer-girl.com>, relay=httpd@localhost
Dec 12 05:58:49 kube3 sendmail[31696]: kBBLho831696: kBBLho931696: DSN: User unknown
************
next i also found these coresponding message id
************
Dec 12 06:40:17 kube3 sendmail[2011]: kBBLho831696: to=zero_0081@yahoo.com, ctladdr=httpd (15/11), delay=00:56:27, xdelay=00:13:24, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:17 kube3 sendmail[7518]: kBBMeB607514: to=admin, delay=00:00:06, xdelay=00:00:06, mailer=local, pri=47009, dsn=2.0.0, stat=Sent
Dec 12 06:40:17 kube3 sendmail[2011]: kBBLho831696: to=sandman_13_13@yahoo.com, ctladdr=httpd (15/11), delay=00:56:27, xdelay=00:13:24, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:18 kube3 sendmail[2011]: kBBLho831696: to=gracefulchick1967@yahoo.com, ctladdr=httpd (15/11), delay=00:56:28, xdelay=00:13:25, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:18 kube3 MailScanner[3706]: New Batch: Found 52 messages waiting
Dec 12 06:40:18 kube3 MailScanner[3706]: New Batch: Scanning 1 messages, 27971 bytes
Dec 12 06:40:18 kube3 sendmail[2011]: kBBLho831696: to=acesmx@yahoo.com, ctladdr=httpd (15/11), delay=00:56:28, xdelay=00:13:25, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
machine. sun cobalt qube 3 pro, (like redhat). sendmail v8.10.2, apache v1.3.20 Sun Cobalt, mailscanner v4.45.4-1
got lot like this on the log.
Dec 12 05:58:49 kube3 sendmail[31696]: kBBLho831696: from=httpd, size=8993, class=0, nrcpts=329, msgid=<200612112143.kBBLho831696@kube3.surfer-girl.com>, relay=httpd@localhost
Dec 12 05:58:49 kube3 sendmail[31696]: kBBLho831696: kBBLho931696: DSN: User unknown
************
next i also found these coresponding message id
************
Dec 12 06:40:17 kube3 sendmail[2011]: kBBLho831696: to=zero_0081@yahoo.com, ctladdr=httpd (15/11), delay=00:56:27, xdelay=00:13:24, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:17 kube3 sendmail[7518]: kBBMeB607514: to=admin, delay=00:00:06, xdelay=00:00:06, mailer=local, pri=47009, dsn=2.0.0, stat=Sent
Dec 12 06:40:17 kube3 sendmail[2011]: kBBLho831696: to=sandman_13_13@yahoo.com, ctladdr=httpd (15/11), delay=00:56:27, xdelay=00:13:24, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:18 kube3 sendmail[2011]: kBBLho831696: to=gracefulchick1967@yahoo.com, ctladdr=httpd (15/11), delay=00:56:28, xdelay=00:13:25, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients
Dec 12 06:40:18 kube3 MailScanner[3706]: New Batch: Found 52 messages waiting
Dec 12 06:40:18 kube3 MailScanner[3706]: New Batch: Scanning 1 messages, 27971 bytes
Dec 12 06:40:18 kube3 sendmail[2011]: kBBLho831696: to=acesmx@yahoo.com, ctladdr=httpd (15/11), delay=00:56:28, xdelay=00:13:25, mailer=esmtp, pri=9968993, relay=b.mx.mail.yahoo.com. [66.196.97.250], dsn=4.3.1, stat=Deferred: 452 Too many recipients