Bluehost.com Web Hosting $6.95

Please help me analyse the log

This is a discussion on Please help me analyse the log within the mailing.postfix.users forums, part of the Mail Servers and Related category; I am vwry new in postfix and even linux. Begun from 2/2/2004 the following similar logs appear on ...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-10-2004
255_255_255_255
 
Posts: n/a
Default Please help me analyse the log


I am vwry new in postfix and even linux.

Begun from 2/2/2004 the following similar logs appear on my server. The sources were vary and the mails were tried to send to random user in my doamin (eg. Mary,Brain, etc). I want to know what was happening. I was afraid if my server being hacked, became an open relay server or if other server block emails from my servers.

Feb 2 18:07:26 www postfix/smtpd[9059]: connect from unknown[221.124.98.96]
Feb 2 18:07:26 www postfix/smtpd[9059]: 0E61037742: client=unknown[221.124.98.96]
Feb 2 18:07:26 www postfix/cleanup[9062]: 0E61037742: message-id=<20040202100726.0E61037742@www.foo.com>
Feb 2 18:07:26 www postfix/nqmgr[18634]: 0E61037742: from=<ray@kuririnmail.com>, size=31996, nrcpt=1 (queue active)
Feb 2 18:07:26 www postfix/smtpd[9059]: disconnect from unknown[221.124.98.96]
Feb 2 18:07:26 www postfix/local[9063]: 0E61037742: to=<mary@www.foo.com>, relay=local, delay=0, status=bounced (unknown user: "mary")
Feb 2 18:07:26 www postfix/cleanup[9062]: 1BC2C3774A: message-id=<20040202100726.1BC2C3774A@www.foo.com>
Feb 2 18:07:26 www postfix/nqmgr[18634]: 1BC2C3774A: from=<>, size=33520, nrcpt=1 (queue active)
Feb 2 18:07:46 www postfix/smtpd[9059]: connect from unknown[221.124.98.96]
Feb 2 18:07:46 www postfix/smtpd[9059]: 9D07E37742: client=unknown[221.124.98.96]
Feb 2 18:07:46 www postfix/cleanup[9062]: 9D07E37742: message-id=<20040202100746.9D07E37742@www.foo.com>
Feb 2 18:07:46 www postfix/smtpd[9059]: disconnect from unknown[221.124.98.96]
Feb 2 18:07:46 www postfix/nqmgr[18634]: 9D07E37742: from=<sandra@hellokitty.com>, size=32198, nrcpt=1 (queue active)
Feb 2 18:07:46 www postfix/local[9063]: 9D07E37742: to=<jose@www.foo.com>, relay=local, delay=0, status=bounced (unknown user: "jose")
Feb 2 18:07:46 www postfix/cleanup[9062]: B14DC3774B: message-id=<20040202100746.B14DC3774B@www.foo.com>
Feb 2 18:07:46 www postfix/nqmgr[18634]: B14DC3774B: from=<>, size=33724, nrcpt=1 (queue active)
Feb 2 18:08:26 www postfix/smtp[9066]: B14DC3774B: to=<sandra@hellokitty.com>, relay=hellokitty-com.mr.outblaze.com[205.158.62.52], delay=40, status=bounced (host hellokitty-com.mr.outblaze.com[205.158.62.52] said: 550 Error: Bounce likely due to MyDoom. Not wanted.)
Feb 2 18:08:59 www postfix/smtp[9065]: 1BC2C3774A: to=<ray@kuririnmail.com>, relay=kuririnmail-com.mr.outblaze.com[205.158.62.52], delay=93, status=bounced (host kuririnmail-com.mr.outblaze.com[205.158.62.52] said: 550 Error: Bounce likely due to MyDoom. Not wanted.)

Feb 6 15:11:05 www postfix/smtpd[27786]: connect from 061093215162.ctinets.com[61.93.215.162]
Feb 6 15:11:05 www postfix/smtpd[27786]: 7037037742: client=061093215162.ctinets.com[61.93.215.162]
Feb 6 15:11:05 www postfix/cleanup[27787]: 7037037742: message-id=<20040206071105.7037037742@www.olc.edu.hk>
Feb 6 15:11:05 www postfix/nqmgr[18634]: 7037037742: from=<dave@staff.sina.com>, size=32143, nrcpt=1 (queue active)
Feb 6 15:11:05 www postfix/local[27788]: 7037037742: to=<matt@www.olc.edu.hk>, relay=local, delay=0, status=bounced (unknown user: "matt")
Feb 6 15:11:05 www postfix/cleanup[27787]: AEB813774D: message-id=<20040206071105.AEB813774D@www.olc.edu.hk>
Feb 6 15:11:05 www postfix/nqmgr[18634]: AEB813774D: from=<>, size=33667, nrcpt=1 (queue active)
Feb 6 15:11:05 www postfix/smtpd[27786]: disconnect from 061093215162.ctinets.com[61.93.215.162]
Feb 6 15:11:29 www postfix/smtp[27790]: AEB813774D: to=<dave@staff.sina.com>, relay=mx2.sina.net[202.108.37.52], delay=24, status=bounced (host mx2.sina.net[202.108.37.52] said: 550 ???????? - invalid address (#5.5.0))
Feb 6 15:13:37 www postfix/smtpd[27792]: connect from 061093215162.ctinets.com[61.93.215.162]
Feb 6 15:13:37 www postfix/smtpd[27792]: 2361F37742: client=061093215162.ctinets.com[61.93.215.162]
Feb 6 15:13:37 www postfix/cleanup[27793]: 2361F37742: message-id=<20040206071337.2361F37742@www.olc.edu.hk>
Feb 6 15:13:37 www postfix/nqmgr[18634]: 2361F37742: from=<sandra@sinaman.com>, size=32852, nrcpt=1 (queue active)
Feb 6 15:13:37 www postfix/local[27794]: 2361F37742: to=<alice@www.olc.edu.hk>, relay=local, delay=0, status=bounced (unknown user: "alice")
Feb 6 15:13:37 www postfix/cleanup[27793]: 7C5AC3774D: message-id=<20040206071337.7C5AC3774D@www.olc.edu.hk>
Feb 6 15:13:37 www postfix/nqmgr[18634]: 7C5AC3774D: from=<>, size=34379, nrcpt=1 (queue active)
Feb 6 15:13:37 www postfix/smtpd[27792]: disconnect from 061093215162.ctinets.com[61.93.215.162]
Feb 6 15:13:52 www postfix/smtp[27796]: 7C5AC3774D: to=<sandra@sinaman.com>, relay=sinamail1.sina.com.hk[202.85.139.200], delay=15, status=bounced (host sinamail1.sina.com.hk[202.85.139.200] said: 553 sorry, your envelope sender is in my badmailfrom list (#5.7.1))

Thanks!!
================================================== ========================================
學普通話,免費學*^語 -
http://adimages.sina.com.hk/Lingua_0204.html
千羽鶴使你的戀愛願望成真 -
http://val04.sina.com.hk/

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 07:32 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0