Go Back   HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials > Linux Forums > HOWTO-Related Questions

Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
Reply
 
Thread Tools Display Modes
  #1  
Old 22nd October 2011, 15:49
gorav gorav is offline
Junior Member
 
Join Date: Aug 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default someone faking smtp authentication

Hi,

Someone is faking smtp authentication on our server and sending out emails. This is from header of one of such emails -

---------------
Received: from 178.89.32.193 (account <info@domain.com> HELO domain.com) by domain.com (CommuniGate Pro SMTP 5.2.3) with ESMTPA id 086072675 for <info@domain.com>; Fri, 7 Oct 2011 16:35:15 +0600

(our actual domain name substituted by domain.com)
---------------

Even the maillog shows info@domain.com as authenticated but there is no such user as info@domain.com in our user list. I checked main.cf, it seems normal.

Any clues on how this is happening. I need to block it immediately before our domain gets marked for spamming.

Thanks in advance for helping.

Regards
Gorav
Reply With Quote
Sponsored Links
  #2  
Old 23rd October 2011, 18:58
falko falko is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,701
Thanks: 1,900
Thanked 2,747 Times in 2,578 Posts
 
Default

Is domain.com hosted on your server? I think someone is sending to that domain as info@domain.com. If that is the case and your server doesn't send the maail to another SMTP server, this should be no problem spam-wise.
__________________
Falko
--
Download the ISPConfig 3 Manual! | Check out the ISPConfig 3 Billing Module!

FB: http://www.facebook.com/howtoforge

nginx-Webhosting: Timme Hosting | Follow me on:
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need some Hints to "The Perfect Server - Debian Lenny (Debian 5.0) [ISPConfig 3]" wahid HOWTO-Related Questions 10 25th August 2010 16:18
amavis rejects all inbound emails aclhkaclhk Installation/Configuration 5 28th February 2010 05:24
Postfix issues NewMee Installation/Configuration 7 20th April 2009 19:52
Mail server attack princebenin Server Operation 1 19th November 2007 15:02
Centos 4.4 32bit Hangs, High Server load 3cwired_com Server Operation 11 16th November 2006 16:47


All times are GMT +2. The time now is 22:48.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.