Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member goodgbb's Avatar
    Join Date
    Aug 2005
    Location
    Thailand
    Posts
    75

    Exclamation help~ my mail server got attacked

    Dear Helpers

    My mail server (exim 4.52) got attacked by using random senders & random receivers.
    He's also attached some viruses to emails.
    I've been banned his ip address. I'm afraid that he'll use proxy or socks then do it again.

    How do I protect my mail server?

    pls help me..
    Thank You from my heart

    #a part of reject logs

    2005-09-26 15:24:19 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <register@xxx.com>: no such address here
    2005-09-26 15:24:19 H=(xxx.com) [xxx.185.132.xxx] F=<register@xxx.com> rejected RCPT <smith@xxx.com>: Sender verify failed
    2005-09-26 15:30:07 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <administrator@xxx.com>: no such address here
    2005-09-26 15:30:07 H=(xxx.com) [xxx.185.132.xxx] F=<administrator@xxx.com> rejected RCPT <ted@xxx.com>: Sender verify failed
    2005-09-26 15:30:11 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <administrator@xxx.com>: no such address here
    Last edited by goodgbb; 09-27-2005 at 12:41 AM.

  2. #2
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Install a virus scanner - well since most of the viruses are for windows, its good to have a virus scanner on your linux box to protect the home users.

    ClamAV, also try Mailscanner and the dictionary attack rules. I personally don't recommend MailScanner as it's a resource hog.
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  3. #3
    Member
    Join Date
    Sep 2005
    Posts
    20

    Default Use...

    Quote Originally Posted by goodgbb
    Dear Helpers

    My mail server (exim 4.52) got attacked by using random senders & random receivers.
    He's also attached some viruses to emails.
    I've been banned his ip address. I'm afraid that he'll use proxy or socks then do it again.

    How do I protect my mail server?

    pls help me..
    Thank You from my heart

    #a part of reject logs

    2005-09-26 15:24:19 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <register@xxx.com>: no such address here
    2005-09-26 15:24:19 H=(xxx.com) [xxx.185.132.xxx] F=<register@xxx.com> rejected RCPT <smith@xxx.com>: Sender verify failed
    2005-09-26 15:30:07 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <administrator@xxx.com>: no such address here
    2005-09-26 15:30:07 H=(xxx.com) [xxx.185.132.xxx] F=<administrator@xxx.com> rejected RCPT <ted@xxx.com>: Sender verify failed
    2005-09-26 15:30:11 H=(xxx.com) [xxx.185.132.xxx] sender verify fail for <administrator@xxx.com>: no such address here
    BFD (that bans exim attempts like that)

    http://www.rfxnetworks.com/proj.php

    Integrate BFD with iptables or use it with APF

Similar Threads & Tags
Similar threads

  1. Server attacked by phishers
    By neonix in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-25-2007, 07:12 PM
  2. Am I being attacked?
    By PitadaVespa in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-22-2007, 06:59 AM
  3. My server attacked?
    By persianwhois in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-14-2007, 10:13 AM
  4. How can i know that my server was attacked bye another or not?
    By 4402734 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-21-2005, 11:40 AM
  5. please,help me my server is attacked
    By preleaf in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-11-2004, 10:56 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube