Hallo,
ich habe seit gestern Mails in der mailq welche mir verdächtig vorkommen!
Ich kenne den Absender sowie den Empfänger nicht!
hier ein kleiner Ausschnitt:
77C35CC281E8 3984 Tue Jan 21 11:05:29 FG@mail2.test.com
(host mx02.htp-tel.de[81.14.243.107] said: 451 4.7.1 Greylisting in action, please come back later (in reply to RCPT TO command))
dr.t.bimmler@htp-tel.de
78195CC281DD 3974 Tue Jan 21 11:02:56 Fiducia@mail2.test.com
(host mail.metaling.com[212.72.100.18] said: 450 4.2.0 <pavel.nemet@netsi.si>: Recipient address rejected: Greylisted, see Postgrey Help (in reply to RCPT TO command))
pavel.nemet@netsi.si
279F3CC281E9 3960 Tue Jan 21 11:05:32 FG@mail2.test.com
(host mxgate02.telemed.de[193.158.110.35] said: 450 4.7.1 <binder@telemed.de>: Recipient address rejected: Greylisted, see Postgrey - Postfix Greylisting Policy Server (in reply to RCPT TO command))
binder@telemed.de
90A4ACC28073 4008 Tue Jan 21 11:02:40 Fiducia@mail2.test.com
(host mailin.ssp-europe.eu[94.16.0.20] refused to talk to me: 554-mail03.ssp-europe.eu 554 Your access to this mail system has been rejected due to the sending MTA's poor reputation. If you believe that this failure is in error, please contact the intended recipient via alternate means.)
montage-5445@ortner-anlagen.at
9BF5ECC281E7 3976 Tue Jan 21 11:05:26 FG@mail2.test.com
(host mail.urologie-syke.de[212.223.165.71] said: 451 Too busy - try again later or see http://www.clustermail.de/fehler.html#9 (in reply to RCPT TO command))
info@urologie-syke.de
3C822CC281E3 3968 Tue Jan 21 11:05:21 FG@mail2.test.com
(host mail.endoc-med.de[85.13.134.133] said: 450 4.2.0 <praxis@endoc-med.de>: Recipient address rejected: Greylisted, see Postgrey Help (in reply to RCPT TO command))
praxis@endoc-med.de
mittlerweile bin ich von BARRACUDA blacklisted worden!
das habe ich im syslog gefunden:
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: connect from localhost[127.0.0.1]
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: 7345BCC2824C: client=localhost[127.0.0.1]
Jan 21 11:13:29 mail2 postfix/cleanup[7213]: 7345BCC2824C: message-id=<01cf1691$Blat.v3.1.1$6e41496d$bd09674490e@test.com>
Jan 21 11:13:29 mail2 postfix/qmgr[3497]: 7345BCC2824C: from=<Volksbank@mail2.test.com>, size=3970, nrcpt=1 (queue active)
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: disconnect from localhost[127.0.0.1]
Jan 21 11:13:29 mail2 amavis[6024]: (06024-18) Passed CLEAN, [217.81.27.166] [217.81.27.166] <Volksbank@mail2.test.com> -> <schulz@lm-anlagen.de>, Message-ID: <01cf1691$Blat.v3.1.1$6e41496d$bd09674490e@test.com>, mail_id: 3JMFSITEmTMq, Hits: 0.102, size: 3520, queued_as: 7345BCC2824C, 103 ms
Jan 21 11:13:29 mail2 postfix/smtp[7214]: 482A9CC28076: to=<schulz@lm-anlagen.de>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.22, delays=0.12/0/0/0.1, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=06024-18, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 7345BCC2824C)
Jan 21 11:13:29 mail2 postfix/qmgr[3497]: 482A9CC28076: removed
Jan 21 11:13:29 mail2 postfix/smtp[7239]: 7345BCC2824C: to=<schulz@lm-anlagen.de>, relay=mail.nacura.de[193.151.32.48]:25, delay=0.49, delays=0.02/0/0.12/0.35, dsn=4.2.0, status=deferred (host mail.nacura.de[193.151.32.48] said: 450 4.2.0 <schulz@lm-anlagen.de>: Recipient address rejected: Greylisted_for_300_seconds_(see_http://isg.ee.ethz.ch/tools/postgrey/help/nacura.de.html) (in reply to RCPT TO command))
Wenn ich das richtig lese kommen die Mails vom localhost, nur wie kann ich herausfinden von wo genau ???????
rkhunter habe ich schon durchlaufen lassen der hat nichts gefunden nur 2 Warnings:
Checking loaded kernel modules [ Warning ]
Checking if SSH root access is allowed [ Warning ]
System checks summary
=====================
File properties checks...
Files checked: 137
Suspect files: 0
Rootkit checks...
Rootkits checked : 247
Possible rootkits: 0
Applications checks...
All checks skipped
The system checks took: 1 minute and 43 seconds
Kann mir hier wer helfen der Ursache auf den Grund zu gehen???
Danke im Voraus!
sigi
ich habe seit gestern Mails in der mailq welche mir verdächtig vorkommen!
Ich kenne den Absender sowie den Empfänger nicht!
hier ein kleiner Ausschnitt:
77C35CC281E8 3984 Tue Jan 21 11:05:29 FG@mail2.test.com
(host mx02.htp-tel.de[81.14.243.107] said: 451 4.7.1 Greylisting in action, please come back later (in reply to RCPT TO command))
dr.t.bimmler@htp-tel.de
78195CC281DD 3974 Tue Jan 21 11:02:56 Fiducia@mail2.test.com
(host mail.metaling.com[212.72.100.18] said: 450 4.2.0 <pavel.nemet@netsi.si>: Recipient address rejected: Greylisted, see Postgrey Help (in reply to RCPT TO command))
pavel.nemet@netsi.si
279F3CC281E9 3960 Tue Jan 21 11:05:32 FG@mail2.test.com
(host mxgate02.telemed.de[193.158.110.35] said: 450 4.7.1 <binder@telemed.de>: Recipient address rejected: Greylisted, see Postgrey - Postfix Greylisting Policy Server (in reply to RCPT TO command))
binder@telemed.de
90A4ACC28073 4008 Tue Jan 21 11:02:40 Fiducia@mail2.test.com
(host mailin.ssp-europe.eu[94.16.0.20] refused to talk to me: 554-mail03.ssp-europe.eu 554 Your access to this mail system has been rejected due to the sending MTA's poor reputation. If you believe that this failure is in error, please contact the intended recipient via alternate means.)
montage-5445@ortner-anlagen.at
9BF5ECC281E7 3976 Tue Jan 21 11:05:26 FG@mail2.test.com
(host mail.urologie-syke.de[212.223.165.71] said: 451 Too busy - try again later or see http://www.clustermail.de/fehler.html#9 (in reply to RCPT TO command))
info@urologie-syke.de
3C822CC281E3 3968 Tue Jan 21 11:05:21 FG@mail2.test.com
(host mail.endoc-med.de[85.13.134.133] said: 450 4.2.0 <praxis@endoc-med.de>: Recipient address rejected: Greylisted, see Postgrey Help (in reply to RCPT TO command))
praxis@endoc-med.de
mittlerweile bin ich von BARRACUDA blacklisted worden!
das habe ich im syslog gefunden:
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: connect from localhost[127.0.0.1]
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: 7345BCC2824C: client=localhost[127.0.0.1]
Jan 21 11:13:29 mail2 postfix/cleanup[7213]: 7345BCC2824C: message-id=<01cf1691$Blat.v3.1.1$6e41496d$bd09674490e@test.com>
Jan 21 11:13:29 mail2 postfix/qmgr[3497]: 7345BCC2824C: from=<Volksbank@mail2.test.com>, size=3970, nrcpt=1 (queue active)
Jan 21 11:13:29 mail2 postfix/smtpd[5741]: disconnect from localhost[127.0.0.1]
Jan 21 11:13:29 mail2 amavis[6024]: (06024-18) Passed CLEAN, [217.81.27.166] [217.81.27.166] <Volksbank@mail2.test.com> -> <schulz@lm-anlagen.de>, Message-ID: <01cf1691$Blat.v3.1.1$6e41496d$bd09674490e@test.com>, mail_id: 3JMFSITEmTMq, Hits: 0.102, size: 3520, queued_as: 7345BCC2824C, 103 ms
Jan 21 11:13:29 mail2 postfix/smtp[7214]: 482A9CC28076: to=<schulz@lm-anlagen.de>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.22, delays=0.12/0/0/0.1, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=06024-18, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 7345BCC2824C)
Jan 21 11:13:29 mail2 postfix/qmgr[3497]: 482A9CC28076: removed
Jan 21 11:13:29 mail2 postfix/smtp[7239]: 7345BCC2824C: to=<schulz@lm-anlagen.de>, relay=mail.nacura.de[193.151.32.48]:25, delay=0.49, delays=0.02/0/0.12/0.35, dsn=4.2.0, status=deferred (host mail.nacura.de[193.151.32.48] said: 450 4.2.0 <schulz@lm-anlagen.de>: Recipient address rejected: Greylisted_for_300_seconds_(see_http://isg.ee.ethz.ch/tools/postgrey/help/nacura.de.html) (in reply to RCPT TO command))
Wenn ich das richtig lese kommen die Mails vom localhost, nur wie kann ich herausfinden von wo genau ???????
rkhunter habe ich schon durchlaufen lassen der hat nichts gefunden nur 2 Warnings:
Checking loaded kernel modules [ Warning ]
Checking if SSH root access is allowed [ Warning ]
System checks summary
=====================
File properties checks...
Files checked: 137
Suspect files: 0
Rootkit checks...
Rootkits checked : 247
Possible rootkits: 0
Applications checks...
All checks skipped
The system checks took: 1 minute and 43 seconds
Kann mir hier wer helfen der Ursache auf den Grund zu gehen???
Danke im Voraus!
sigi