Re: Attack on my mailsystem

2015-06-17 Thread Jithesh AP
On Wed, 17 Jun 2015 06:05:17 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 09:37:24PM -0700, Jithesh AP wrote: >> mynetworks was fully commented, now i have added as you indicated, but >> fully commenting it will also have a similar effect right? > &

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
On Tue, 16 Jun 2015 20:45:12 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 08:34:38PM -0700, Jithesh AP wrote: I tried that, the first line client = ip-172 is the internal/private ip of my server. So does this mean somehow it is being sent from my server itself? grep

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
.0, status=sent (delivered via spamassassin service) On Tue, 16 Jun 2015 20:22:24 -0700, Noel Jones wrote: On 6/16/2015 9:43 PM, Jithesh AP wrote: Grep for the message-id in maillog just gives this, should i search in some other location grep kflvqedfdosxjjhkebewy...@sfilc.com /var/maill

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
On Tue, 16 Jun 2015 19:26:48 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 07:21:39PM -0700, Jithesh AP wrote: >This was created locally via the "sendmail" command. What user >account has "uid" 5005? If this is www-data or similar, you likely >hav

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
On Tue, 16 Jun 2015 19:08:36 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 06:51:24PM -0700, Jithesh AP wrote: This is the maillog result of the grep, but i dont see IP address etc (not sure if the actual log got deleted when i removed the big log). Jun 16 13:21:49 ml postfix

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
gure out and slowly open and see On Tue, 16 Jun 2015 16:11:38 -0700, Wietse Venema wrote: Jithesh AP: unfortunately have logs of messages generating like the below (snippet from postqueue -p) 0C9B14166A 7886 Tue Jun 16 13:21:49 cdbphlavjop...@wysina.com.tw (delivery temporarily suspen

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
sure if there is some config or blocking i am missing. will be setting up fail2ban soon. Regards Jithesh On Tue, 16 Jun 2015 13:24:58 -0700, Jithesh AP wrote: oh ok, then i am out of luck :(, in haste i removed that log file as it was 700MB. On Tue, 16 Jun 2015 11:12:37 -0700, Viktor

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
oh ok, then i am out of luck :(, in haste i removed that log file as it was 700MB. On Tue, 16 Jun 2015 11:12:37 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 10:25:05AM -0700, Jithesh AP wrote: On Tue, 16 Jun 2015 09:26:52 -0700, Viktor Dukhovni wrote: >On Tue, Jun 16, 2

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
On Tue, 16 Jun 2015 09:26:52 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 08:45:55AM -0700, Jithesh AP wrote: Did a grep for the q ID - 15542416CE and looks like that is the last i see of it. (this check is nearly an hour after (08.45) Jun 16 07:50:15 ml postfix/error[653

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
: connect to mx-tw.mail.gm0.yahoodns.net[203.188.197.119]:25: Connection timed out) Regards Jithesh On Tue, 16 Jun 2015 08:33:09 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 08:26:33AM -0700, Jithesh AP wrote: Thank you for the mail below is my postconf -n output [...] >>Jun

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
I have not tried fail2ban, i will check it out on this, hopefully by weekend. Regards Jithesh On Tue, 16 Jun 2015 08:12:19 -0700, Mauricio Tavares wrote: On Tue, Jun 16, 2015 at 9:51 AM, Jithesh AP wrote: Ok thank you for the info, this did scare me :). Its taxing my small system

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
/postfix/mysql-virtual-mailbox-domains.cf virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-mailbox-maps.cf virtual_transport = dovecot Regards Jithesh On Tue, 16 Jun 2015 08:06:21 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 08:01:31AM -0700, Jithesh AP wrote: Did a restart of

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx-tw.mail.gm0.yahoodns.net[203.188.197.119]:25: Connection timed out) Regards Jithesh On Tue, 16 Jun 2015 07:03:35 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 06:51:51AM -0700, Jithesh AP wrote: Ok thank yo

Re: Attack on my mailsystem

2015-06-16 Thread Jithesh AP
Ok thank you for the info, this did scare me :). Its taxing my small system. Regards Jithesh On Tue, 16 Jun 2015 06:48:01 -0700, Viktor Dukhovni wrote: On Tue, Jun 16, 2015 at 06:43:47AM -0700, Jithesh AP wrote: I have an attack on my mail system and the mail i got from mailer deamon

Attack on my mailsystem

2015-06-16 Thread Jithesh AP
Hi All, I have an attack on my mail system and the mail i got from mailer deamon is (got 1000s of such mails) -- Transcript of session follows. Out: 220 ml.w8timez.com ESMTP Postfix In: HELO 54.183.212.207 Out: 250 ml.w8timez.com In: MAIL FROM: Out: 25

Re: Di I need to open port 25?

2015-06-15 Thread Jithesh AP
rocedures for getting them lifted. -- Mike McKoy 404.590.7176 http://MyForeverHair.com http://www.MyModelTalk.com http://InCrowdUSA.net http://www.google.com/profiles/mikemckoy On Sun, Jun 14, 2015 at 11:54 PM, Jithesh AP wrote: Hi I am newbie into mail and mTA setup. I have my port

Re: Di I need to open port 25?

2015-06-15 Thread Jithesh AP
THank you for the responses, really helped my understanding :) Regards Jithesh On Mon, 15 Jun 2015 00:06:14 -0700, Dennis Carr wrote: On Sun, 14 Jun 2015 20:54:58 -0700 "Jithesh AP" wrote: I am newbie into mail and mTA setup. Welcome. =) I have my port 465 smtps/587 (

Di I need to open port 25?

2015-06-14 Thread Jithesh AP
Hi I am newbie into mail and mTA setup. I have my port 465 smtps/587 (submission) working, so do i need to keep port 25 open? I am asking this because when i try to telnet gmail then it does not work, so was wondering if blocking port 25 will stop all my incoming mails or not? To try it

Re: smtps via 465 is not working

2015-06-12 Thread Jithesh AP
THank you for the clarifications, makes sense. Regards Jithesh On Fri, 12 Jun 2015 06:47:06 -0700, Kris Deugau wrote: Jithesh AP wrote: This does not work - telnet ml.w8timez.com 465 This works - openssl s_client -connect ml.w8timez.com:465 Unless you've redefined the behaviour, th

Re: smtps via 465 is not working

2015-06-11 Thread Jithesh AP
it started working fine with the opera client but telnet is broken, it would help me understand better and kill my curiosity? Thank you Jithesh On Thu, 11 Jun 2015 13:20:38 -0700, Noel Jones wrote: On 6/11/2015 2:30 PM, Jithesh AP wrote: Hi, Apologies for long mail, wanted to give all the i

Re: smtps via 465 is not working

2015-06-11 Thread Jithesh AP
what i am missing :(. Regards Jithesh On Thu, 11 Jun 2015 07:35:13 -0700, Christian Kivalo wrote: On 2015-06-11 16:15, Jithesh AP wrote: Hi Hi, Thank you for your mail. I reduced the log level and here is the error that shows up as soon as i try to send a mail from my desktop opera c

Re: smtps via 465 is not working

2015-06-11 Thread Jithesh AP
parameter not present in main.cf, i am using virtual users thru mysql not sure what this parameter needs to map to. Hope this gives sufficient info to help me out. Regards Jithesh On Wed, 10 Jun 2015 23:09:02 -0700, Christian Kivalo wrote: On 2015-06-11 07:51, Jithesh AP wrote: Hi, Hi, I

smtps via 465 is not working

2015-06-10 Thread Jithesh AP
Hi, I am a newbie and setting up my postfix+mysql+dovecot. I got things working for receiving/sending mails, via port 993 and 25 (used a client opera mail). After that i tried to enable smtps via 465, but it is not working, the log is giving this error (receiving via 993 still works fine).

Re: Mail loops back to myself

2015-06-09 Thread Jithesh AP
thank you, makes it clear. Jithesh On Tue, 09 Jun 2015 21:27:35 -0700, Viktor Dukhovni wrote: On Wed, Jun 10, 2015 at 03:54:31AM +, Viktor Dukhovni wrote: Port 587 is not for inter-domain mail delivery. It is for submission of mail by users (Outlook, Thunderbird, ...) to the outbound

Re: Mail loops back to myself

2015-06-09 Thread Jithesh AP
Thank you, gives me better idea now. Regards Jithesh On Tue, 09 Jun 2015 20:54:31 -0700, Viktor Dukhovni wrote: On Tue, Jun 09, 2015 at 08:44:20PM -0700, Jithesh AP wrote: Currently sending mail is thru port 25, how to make it to use port 587 (i understand that is more secure). Port

Re: Mail loops back to myself

2015-06-09 Thread Jithesh AP
Currently sending mail is thru port 25, how to make it to use port 587 (i understand that is more secure). Regards Jithesh On Tue, 09 Jun 2015 20:40:28 -0700, Viktor Dukhovni wrote: On Tue, Jun 09, 2015 at 08:28:44PM -0700, Jithesh AP wrote: Thank you, this worked very well. I made it

Re: Mail loops back to myself

2015-06-09 Thread Jithesh AP
:08PM -0700, Jithesh AP wrote: relayhost = $mydomain That's the cause of the loop. Eithet set this empty, or set it to a suitable smarthost MTA, in the example below a hypothetical "smarthost.example.com": relayhost = [smarthost.example.com] -- Using Opera'

Re: Mail loops back to myself

2015-06-09 Thread Jithesh AP
8 AM, "Jithesh AP" wrote: Hi All, I have setup postfix + mysql + dovecot. I can get mails from gmail and other external and also send mails within my domain, but i am not able to send any mail to outside address, like gmail.com yahoo.com etc. I get the error indicating as pasted belo

Mail loops back to myself

2015-06-09 Thread Jithesh AP
Hi All, I have setup postfix + mysql + dovecot. I can get mails from gmail and other external and also send mails within my domain, but i am not able to send any mail to outside address, like gmail.com yahoo.com etc. I get the error indicating as pasted below Jun 9 14:04:40 ml postfix/smtp