Re: possible compromised system

2011-07-28 Thread Michael Orlitzky
On 07/27/11 17:41, Reindl Harald wrote: Am 27.07.2011 23:22, schrieb Wietse Venema: Is this machine running a webserver? Look in the access logs if this is the reason consider disable smtp on 127.0.0.1 because most of dumb injected scripts are trying this instead the network address!

Re: possible compromised system

2011-07-28 Thread Reindl Harald
Am 28.07.2011 15:49, schrieb Michael Orlitzky: On 07/27/11 17:41, Reindl Harald wrote: Am 27.07.2011 23:22, schrieb Wietse Venema: Is this machine running a webserver? Look in the access logs if this is the reason consider disable smtp on 127.0.0.1 because most of dumb injected scripts

possible compromised system

2011-07-27 Thread Julian Opificius
When I connect to my Postfix server using ssh from a remote location, postings show up as something like (suitably modified for security): Jul 27 15:50:35 winston postfix/smtpd[28303]: connect from localhost[127.0.0.1] Jul 27 15:50:36 winston postfix/smtpd[28303]: 57A5A220BA:

Re: possible compromised system

2011-07-27 Thread Jeroen Geilman
On 2011-07-27 23:10, Julian Opificius wrote: When I connect to my Postfix server using ssh from a remote location, postings show up as something like (suitably modified for security): Jul 27 15:50:35 winston postfix/smtpd[28303]: connect from localhost[127.0.0.1] Jul 27 15:50:36 winston

Re: possible compromised system

2011-07-27 Thread Wietse Venema
Is this machine running a webserver? Look in the access logs. Wietse

Re: possible compromised system

2011-07-27 Thread Reindl Harald
Am 27.07.2011 23:22, schrieb Wietse Venema: Is this machine running a webserver? Look in the access logs if this is the reason consider disable smtp on 127.0.0.1 because most of dumb injected scripts are trying this instead the network address! disable php's mail()-function and every

Re: possible compromised system

2011-07-27 Thread Julian Opificius
On Wed, 2011-07-27 at 23:21 +0200, Jeroen Geilman wrote: On 2011-07-27 23:10, Julian Opificius wrote: When I connect to my Postfix server using ssh from a remote location, postings show up as something like (suitably modified for security): Jul 27 15:50:35 winston postfix/smtpd[28303]: