[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Problem z pocztą



Witajcie

Od zeszlej nocy mam nastepujący problem. Na początek kawałek loga, który jest praktycznie identyczny z moim logiem z exima

2005-12-29 15:08:26 Connection from [211.134.105.180] refused: too many connections 2005-12-29 15:08:26 H=(001.ams.or.at) [85.60.41.70] F=<e.battle_as@stanleyinteractive.co.uk> rejected RCPT <tate@sporti$ 2005-12-29 15:08:26 H=(teapowder.com) [59.40.39.216] sender verify fail for <oil@teapowder.com>: unrouteable mail domain "te$ 2005-12-29 15:08:27 Connection from [211.134.105.180] refused: too many connections 2005-12-29 15:08:27 Connection from [59.40.39.216] refused: too many connections 2005-12-29 15:08:27 Connection from [81.215.22.66] refused: too many connections 2005-12-29 15:08:27 Connection from [61.246.7.144] refused: too many connections 2005-12-29 15:08:27 Connection from [69.253.127.159] refused: too many connections 2005-12-29 15:08:28 Connection from [61.246.7.144] refused: too many connections 2005-12-29 15:08:28 Connection from [81.215.22.66] refused: too many connections


2005-12-29 15:08:28 Connection from [86.55.147.221] refused: too many connections 2005-12-29 15:08:29 Connection from [69.90.186.30] refused: too many connections 2005-12-29 15:08:29 Connection from [69.90.186.30] refused: too many connections 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (home) [84.21.206.232] 2005-12-29 15:08:29 H=(1-st.nl) [222.120.170.91] F=<lorenvalenzuelaro@eman.demon.nl> rejected RCPT <patton@sporti$ 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cm218-252-217-214.hkcable.com.hk) [218.252.217$ 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (binter.com) [218.253.194.93] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (69.61.59.20) [218.85.30.201] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (softbank219020212038.bbtec.net) [219.20.212.38] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cieletespace.fr) [70.103.202.235] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cims.bc.ca) [206.117.140.19] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (modernlight.ch) [84.61.38.111] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cic.ipn.mx) [80.236.47.225] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (modelcars.co.uk) [72.234.9.125] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (stanilands.freeserve.co.uk) [220.208.168.176] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (10-a.de) [85.60.52.150] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cide.edu) [218.110.14.157] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (000.co.jp) [60.239.28.54] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (mofa.jp) [201.11.176.192] 2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (star-pos.ru) [61.230.23.90] 2005-12-29 15:08:30 unexpected disconnection while reading SMTP command from a mail(cifec-sa.fr) [193.206.52.36] 2005-12-29 15:08:32 1EryRF-0002bT-PC <= luannera@macross-7.net H=(macross-7.net) [220.188.183.209] P=smtp S=1731 id=c3

Co trzeci wpis w logu to unexpected disconnection while reading SMTP command from a po pewnym czasie wywala refused: too many connections. Mam też sporo wpisów, gdzie nazwa hosta z którego przychodzą maile jest zbudowana z losowo wybranych duzych liter. Podejrzewam, że ktos mnie dopisał do open relaya albo przechodze własnie jakis dłuższy atak.

Iptables niewiele tu pomoże, bo wszystko przychodzi z różnych adresów.

Poradzcie jakies rozwiązanie. Przypomnę, że na mszynie stoi exim.

Pozdrawiam


Reply to: