Re: Mass Mailing Worm on Linux
"Shashank Khanvilkar" <shashank@mia.ece.uic.edu> wrote in message
news:c7rusc$bqj$1@newsx.cc.uic.edu
> However I checked my sendmail.mc file and relaying has been disabled
> (It listens only on the loop-back address).
>
> Has anyone ever faced such a problem and what steps did they take to
> eliminate it.
Why don't you check your maillog files to see where the stuff is coming
from? Listening only on 127.0.0.1 doesn't help if one is running an
insecure webmail application or provides other avenues of mail access.
Also perform an nmap and nessus scan from another machine on the network as
well as a machine from outside your LAN. You might be surprised at what
vulnerabilities you have wide open.
tony
--
use hotmail for email replies
|