Ich hab mich jetzt wirklich stundenlang im Inet schlau gemacht und auch dieses Forum durchforstet. Habe zwar einige Hinweise gefunden, jedoch leider keine Lösung?!? So langsam verzweifel ich.
System:
1&1 Root Server
Confixx 3
Postfix
Seit gestern wird mein Server wohl als Open Relay missbraucht (anhand des Traffics und der Logs zu erkennen).
Wobei Postfix doch eigentlich standardmässig (was ich auch nicht geändert habe) eben KEIN open relay ist.
Ich hab einen Test bei abuse.com gemacht, der meinen Server als Open Relay identifiziert hat. Ã?ber telnet hab ich jedoch immer "relay denied" bekommen.
Hier mal meine main.cfg
Code: Select all
#
queue_directory = /var/spool/postfix
command_directory = /usr/sbin
daemon_directory = /usr/lib/postfix
mail_owner = postfix
default_privs = autoresponder
inet_interfaces = all
debug_peer_level = 2
debugger_command =
PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
xxgdb $daemon_directory/$process_name $process_id & sleep 5
sendmail_path = /usr/sbin/sendmail
newaliases_path = /usr/bin/newaliases
mailq_path = /usr/bin/mailq
setgid_group = maildrop
manpage_directory = /usr/share/man
sample_directory = /usr/share/doc/packages/postfix/samples
readme_directory = /usr/share/doc/packages/postfix/README_FILES
mail_spool_directory = /var/mail
canonical_maps = hash:/etc/postfix/canonical
virtual_maps = hash:/etc/postfix/virtual, hash:/etc/postfix/confixx_virtualUsers, hash:/etc/postfix/confixx_localDomains
relocated_maps = hash:/etc/postfix/relocated
transport_maps = hash:/etc/postfix/transport
sender_canonical_maps = hash:/etc/postfix/sender_canonical
masquerade_exceptions = root
masquerade_classes = envelope_sender, header_sender, header_recipient
myhostname = xxxxxxx.pureserver.info
program_directory = /usr/lib/postfix
masquerade_domains =
mydestination = $myhostname, localhost.$mydomain
defer_transports =
disable_dns_lookups = no
relayhost =
content_filter =
mailbox_command = /usr/bin/procmail
mailbox_transport =
smtpd_sender_restrictions = hash:/etc/postfix/access
smtpd_client_restrictions =
smtpd_helo_required = no
smtpd_helo_restrictions =
strict_rfc821_envelopes = no
smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination
smtp_use_tls = no
alias_maps = hash:/etc/aliases
mailbox_size_limit = 0
message_size_limit = 10240000
#SMTPD Auth
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
#TLS Support
smtpd_use_tls = yes
#smtpd_tls_auth_only = yes
smtpd_tls_key_file = /etc/postfix/key.pem
smtpd_tls_cert_file = /etc/postfix/cert.pem
smtpd_tls_CAfile = /etc/ssl/certs/xxxxxxx.pureserver.info-sample-ca.crt
smtpd_tls_loglevel = 1
smtpd_tls_received_header = yes
smtpd_tls_session_cache_timeout = 3600s
tls_random_source = dev:/dev/urandom
Dann hier noch ein Teil aus der messages Datei
Code: Select all
PAM-warn[559]: function=[pam_sm_authenticate] service=[smtp] terminal=[<unknown>] user=[web1p1] ruser=[<unknown>] rhost=[<unknown>] Code: Select all
Aug 25 16:58:37 xxxxxxx postfix/smtpd[21327]: connect from loncoche.terra.com.br[200.154.55.229]
Aug 25 16:58:38 xxxxxxx postfix/smtpd[21327]: 55D92C0017F: client=loncoche.terra.com.br[200.154.55.229]
Aug 25 16:58:38 xxxxxxx postfix/cleanup[21329]: 55D92C0017F: message-id=<01C48A8F.305EEBA0.dietmar@ahkpoa.com.br>
Aug 25 16:58:40 xxxxxxx postfix/qmgr[20758]: 55D92C0017F: from=<dietmar@ahkpoa.com.br>, size=146755, nrcpt=1 (queue active)
Aug 25 16:58:40 xxxxxxx postfix/smtpd[21327]: disconnect from loncoche.terra.com.br[200.154.55.229]
Aug 25 16:58:40 xxxxxxx spamd[862]: connection from localhost.localdomain [127.0.0.1] at port 46379
Aug 25 16:58:40 xxxxxxx spamd[21336]: processing message <01C48A8F.305EEBA0.dietmar@ahkpoa.com.br> for web1p1:104.
Aug 25 16:58:42 xxxxxxx spamd[21336]: clean message (1.8/5.0) for web1p1:104 in 1.7 seconds, 144571 bytes.
Wäre echt super, wenn ihr mir da helfen könnt, weil ich wirklich nicht mehr weiter weiß.
Vielen Dank schon mal
Chris