Networking Forums

Networking Forums > Computer Networking > Linux Networking > Denial of Service attack in sendmail

Reply
Thread Tools Display Modes

Denial of Service attack in sendmail

 
 
John
Guest
Posts: n/a

 
      09-06-2007, 05:52 AM
Dear all,



For the sendmail server, it seems to still have "denial of service attack"
after re-installing the whole Redhat 9.0.In fact, such type of email is that
we let customers send their information from the internet through php
webpage. Anyway, some other hackers may attack our server through the email.



Please give me possible advice on how to eliminate such kind of rubbish
email, thanks



Regards,

John.



---------------------------------------------------------------

The feedback from the MailScanner is given as follows:



The following e-mails were found to have: Virus Detected
Sender: (E-Mail Removed)
IP Address: 127.0.0.1
Recipient: (E-Mail Removed)
Subject: Welcome to your advice
MessageID: l857AWmf003853
Quarantine:
Report: Denial of Service attack in message!

Full headers are:

Return-Path: <?g>
Received: from ns.xx-xx.com (localhost.localdomain [127.0.0.1])
by ns.xx-xx.com (8.12.8/8.12.8) with ESMTP id l857AWmf003853
for <(E-Mail Removed)>; Wed, 5 Sep 2007 15:10:33 +0800
Full-Name: Nobody
Received: (from nobody@localhost)
by ns.xx-xx.com (8.12.8/8.12.8/Submit) id l857AWk4003851;
Wed, 5 Sep 2007 15:10:32 +0800
Date: Wed, 5 Sep 2007 15:10:32 +0800
Message-Id: <(E-Mail Removed)>
To: (E-Mail Removed)
Subject: Welcome to your advice
From: <(E-Mail Removed)>
--
MailScanner
Email Virus Scanner
www.mailscanner.info


This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

===============================

The original message was received at Thu, 30 Aug 2007 07:51:43 +0800
from localhost.localdomain [127.0.0.1]

----- The following addresses had permanent fatal errors -----
<(E-Mail Removed)>
(reason: 550 5.1.1 <(E-Mail Removed)>... User unknown)

----- Transcript of session follows -----
.... while talking to zoso.email.net.:
>>> DATA

<<< 550 5.1.1 <(E-Mail Removed)>... User unknown
550 5.1.1 <(E-Mail Removed)>... User unknown
<<< 503 5.0.0 Need RCPT (recipient)




 
Reply With Quote
 
 
 
 
Scott Grayban
Guest
Posts: n/a

 
      09-06-2007, 06:33 AM
John wrote:
> For the sendmail server, it seems to still have "denial of service attack"
> after re-installing the whole Redhat 9.0.In fact, such type of email is that
> we let customers send their information from the internet through php
> webpage. Anyway, some other hackers may attack our server through the email.
>


First off RH 9.0 is not even supported anymore, it was released 2003 and EOL
was 2005.

You give no sendmail version. And allowing php mail scripts is just asking for
trouble.

>
>
> Please give me possible advice on how to eliminate such kind of rubbish
> email, thanks


Install something newer.

-- Scott
 
Reply With Quote
 
Scott Grayban
Guest
Posts: n/a

 
      09-06-2007, 06:38 AM
John wrote:
> Please give me possible advice on how to eliminate such kind of rubbish
> email, thanks
>


Opps correction - *Everything* you are using is old. Even your sendmail
version, 8.12.8, is old. The newest version is 8.14.1 which is 2 *WHOLE*
versions newer.

>
> ---------------------------------------------------------------
>
> The feedback from the MailScanner is given as follows:
>
>
>
> The following e-mails were found to have: Virus Detected
> Sender: (E-Mail Removed)
> IP Address: 127.0.0.1
> Recipient: (E-Mail Removed)
> Subject: Welcome to your advice
> MessageID: l857AWmf003853
> Quarantine:
> Report: Denial of Service attack in message!
>
> Full headers are:
>
> Return-Path: <?g>
> Received: from ns.xx-xx.com (localhost.localdomain [127.0.0.1])
> by ns.xx-xx.com (8.12.8/8.12.8) with ESMTP id l857AWmf003853
> for <(E-Mail Removed)>; Wed, 5 Sep 2007 15:10:33 +0800
> Full-Name: Nobody
> Received: (from nobody@localhost)
> by ns.xx-xx.com (8.12.8/8.12.8/Submit) id l857AWk4003851;
> Wed, 5 Sep 2007 15:10:32 +0800
> Date: Wed, 5 Sep 2007 15:10:32 +0800
> Message-Id: <(E-Mail Removed)>
> To: (E-Mail Removed)
> Subject: Welcome to your advice
> From: <(E-Mail Removed)>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible attack? Anon E. Muss Linux Networking 13 12-02-2008 04:57 PM
About IP Helper API and new SYN attack notification on Microsoft Windows Server 2003 Service Pack 1 Didier P Windows Networking 1 08-05-2006 04:35 AM
Connection Denial List Lee Windows Networking 5 03-30-2006 05:36 PM
"denial of service" attacks Mr.Jason Linux Networking 12 06-06-2005 01:49 AM
SYN attack R.J. Rabenberg Wireless Internet 2 02-01-2004 05:16 PM



1 2 3 4 5 6 7 8 9 10 11