[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Re: Re: Re: [RaQ2] SMTP server failure after RaQ2-All-Security Release update



> /var/log/maillog is loaded with this (none of these IP 
> addresses or e-mail
> adresses are known to me)
> 
> May 16 08:17:28 paine sendmail[31427]: IAA31419: 
> to=angus@xxxxxxxxxxxx,
> ctladdr=nobody (99/99), delay=00:00:38, xdelay=00:00:04, mailer=esmtp,
> relay=overland.net.overl...t.mail2.psmtp.com. [64.75.1.251],
stat=Deferred: 451 Error while writing spool file
> May 16 08:17:29 paine sendmail[31427]: IAA31419: to=angus@xxxxxxx,
ctladdr=nobody (99/99), delay=00:00:39, xdelay=00:00:01, mailer=esmtp,
relay=mail.tr.osg.net. [204.244.179.200], stat=Sent (OK
id=178KEm-0000zq-00)
> May 16 08:17:32 paine sendmail[31427]: IAA31419: 
> to=angus@xxxxxxxxxxxxx, ctladdr=nobody (99/99), delay=00:00:42,
xdelay=00:00:03, mailer=esmtp,
> relay=mx2.optonline.net. [167.206.5.3], stat=Sent (2.0.0 g4GCH2l24398
Message accepted for  delivery)
> May 16 08:17:32 paine sendmail[31427]: IAA31419: IAA31427: DSN: User
unknown
> May 16 08:17:32 paine sendmail[31427]: IAA31427: to=/dev/null,
delay=00:00:00, x delay=00:00:00, mailer=*file*, stat=Sent
> 

I hope you found whatever script was owned by the user nobody and
stopped it. At least the spammer was only in the "A"s.

-- 
Dan Kriwitsky