Pasco
10th April 2007, 11:56
Hi 2gether
I have noticed a big traffic on my server network interface, so I examined the connections. There were a extraordinary load of mails. So I shut down SMTP Service and checked postfix's mail queue. There were over 500 mails in the queue...actually this was very strange, because for domain e-mail I use an external mailserver, not the ISPConfig Mailserver. I need the ISPConfig Mailserver only for delivering mails out of the users pages, like from contact formulars etc (mostly via php mail on the users webpages).
I discovered that the 500 mails in the queue were all SPAM-Mails. They should be sent over the virtual network interface configured during install procedure on perfect how-to for Debian 3 for SSL...:confused: How was it possible to inject these SPAM e-mails in my ISPConfig SMTP Server? It shouldn't be an open-relay mail-server in standard configuration, but somebody could use as it?! Recently I installed a webpage on "drupal 5.1" with contact form. I guess it was send via an security hole on that page. But it shouldn't be possible, shoud it? ISPConfig Server should block that? Otherwise I'm always exposed to the risk of the webpages of my users? Perhaps I should solve that with more restrictive rules.. ? :-)
I checked also /var/mail/ and there is a very big file for "www-data", it's about 250 MB. I guess this is the mailbox for user "www-data". I don't know who or what should be in there, in that mailbox for user "www-data"...I guess returned e-mails or something like that?
How can I a) access the "www-data" mailbox (what password?) and delete these e-mails?
And b) WHY is there that much data in? As far as I can see, "www-data" is my apache user which is used everytime an user of a users-page sends a e-mail via e.g. a web form like contact or similar. Can I change this? Is it possible each user has to authenticate or that I can see which of my users/customers has send out certain mails or which website was (mis)used for that? (instead of "www-data"). Does "suexec" also works for that? I guess it's only for CGI...actually I don't have checked "suexec" in my ISPConfig config.
How can I bring ISPConfig Server to send out mails from a domain that is hosted on that server, but e-mails are processed by an other, external e-mail server in my DMZ? Can I just choose Mailserver: External Mailserver under "options" of my ISP Web settings? Otherwise mails via an customers contact formular are not send out, because DNS reports the same external IP for my web and mail server (it's in the same LAN/DMZ), so ISPConfig Server tries to send it locally. But there is no such e-mail-user on ISPConfig Server, because I want to send those e-mails to my mailserver who's handling these e-mails for that domains...
Thanks so much for any help in advance,
p@sco
I have noticed a big traffic on my server network interface, so I examined the connections. There were a extraordinary load of mails. So I shut down SMTP Service and checked postfix's mail queue. There were over 500 mails in the queue...actually this was very strange, because for domain e-mail I use an external mailserver, not the ISPConfig Mailserver. I need the ISPConfig Mailserver only for delivering mails out of the users pages, like from contact formulars etc (mostly via php mail on the users webpages).
I discovered that the 500 mails in the queue were all SPAM-Mails. They should be sent over the virtual network interface configured during install procedure on perfect how-to for Debian 3 for SSL...:confused: How was it possible to inject these SPAM e-mails in my ISPConfig SMTP Server? It shouldn't be an open-relay mail-server in standard configuration, but somebody could use as it?! Recently I installed a webpage on "drupal 5.1" with contact form. I guess it was send via an security hole on that page. But it shouldn't be possible, shoud it? ISPConfig Server should block that? Otherwise I'm always exposed to the risk of the webpages of my users? Perhaps I should solve that with more restrictive rules.. ? :-)
I checked also /var/mail/ and there is a very big file for "www-data", it's about 250 MB. I guess this is the mailbox for user "www-data". I don't know who or what should be in there, in that mailbox for user "www-data"...I guess returned e-mails or something like that?
How can I a) access the "www-data" mailbox (what password?) and delete these e-mails?
And b) WHY is there that much data in? As far as I can see, "www-data" is my apache user which is used everytime an user of a users-page sends a e-mail via e.g. a web form like contact or similar. Can I change this? Is it possible each user has to authenticate or that I can see which of my users/customers has send out certain mails or which website was (mis)used for that? (instead of "www-data"). Does "suexec" also works for that? I guess it's only for CGI...actually I don't have checked "suexec" in my ISPConfig config.
How can I bring ISPConfig Server to send out mails from a domain that is hosted on that server, but e-mails are processed by an other, external e-mail server in my DMZ? Can I just choose Mailserver: External Mailserver under "options" of my ISP Web settings? Otherwise mails via an customers contact formular are not send out, because DNS reports the same external IP for my web and mail server (it's in the same LAN/DMZ), so ISPConfig Server tries to send it locally. But there is no such e-mail-user on ISPConfig Server, because I want to send those e-mails to my mailserver who's handling these e-mails for that domains...
Thanks so much for any help in advance,
p@sco