Re: localhost forged



In article <1140959133.739433.81600@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
"larsk" <larskman@xxxxxxxxx> wrote:

Right, that what i was thinking an hour ago too. That I would not have
this issue if I redesign the network with 2 mail servers. One for
incoming mail and one for outgoing. On the incoming I can block
loopback so that what no one can generate local mail via telnet to 25.
and outgoing will not allow incoming connections from the internet.

But I don't think the problem relates to why the web server is able to
send mail. I think the problem is that someone/script kiddies telnet to
my box on 25 and sent mail locally which this will explain why i see
the relay as 127.0.0.1.

No, that wouldn't show up as coming from 127.0.0.1, but from wherever
they are coming from.

Someone has cracked your machine for use as a spam sender. For web
servers, the most common paths for this are sloppy CGI scripts (e.g.
Matt Wright's formmail) and poorly-maintained and poorly-written PHP
applications.

--
Now where did I hide that website...
.



Relevant Pages

  • Re: Error message
    ... actively scanning incoming and outgoing email? ... Are you properly authenticating to the ISP servers? ...
    (microsoft.public.outlook.general)
  • Re: e-mail IMAP server name problem
    ... it askes me the name of servers - incoming and outgoing names. ... Does anyone know what the aol incoming and outgoing server ...
    (microsoft.public.windows.vista.mail)
  • Re: e-mail IMAP server name problem
    ... it askes me the name of servers - incoming and outgoing names. ... Does anyone know what the aol incoming and outgoing ...
    (microsoft.public.windows.vista.mail)
  • e-mail IMAP server name problem
    ... it askes me the name of servers - incoming and outgoing names. ... Does anyone know what the aol incoming and outgoing server ...
    (microsoft.public.windows.vista.mail)
  • Re: pop3 smtp settings muddle
    ... Disable email scanning (outgoing and incoming) by your anti-virus application. ... You prolly will have to reconfigure the Outgoing mailserver manually after disabling email scanning. ... Seperate authentication information is correrctly added for the smtp server ...
    (microsoft.public.windowsxp.general)

Loading