Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

email server been hacked ?

Status
Not open for further replies.

zxmax

Technical User
Joined
Nov 24, 2003
Messages
179
Location
CA
Hi all, this is driving me nuts, First of all i'm not really running exchange server , but runing a deerfeild mail server ,, my problem is , my email server keep relaying, and i'm not open for relaying at all, i even blocked sending any emails out .. even after that i look at the raw log and i find lots of things like:
----------------------------------------------------
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:36 -0500 Client session Connected
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:37 -0500 Client session <<< 220 sinamail.com ESMTP Service(Sinamail SMTPD) ready Thu, 27 Nov 2003 16:29:41 +0800 (CST)
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:37 -0500 Client session >>> EHLO mail.pcclick.ca
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:38 -0500 Client session <<< 250 SIZE 10240000
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:38 -0500 Client session >>> MAIL From:<bramble's@yahoo.com> SIZE=1070
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:38 -0500 Client session <<< 250 Sender <bramble's@yahoo.com> OK
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:38 -0500 Client session >>> RCPT To:<spick@sinamail.com>
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:40 -0500 Client session <<< 250 Recipient <spick@sinamail.com> OK
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:40 -0500 Client session >>> DATA
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:41 -0500 Client session <<< 354 Enter mail, end <CRLF>.<CRLF>
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:44 -0500 Client session <<< 250 Message accepted for delivery
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:44 -0500 Client session *** <bramble's@yahoo.com> <spick@sinamail.com> 1 1070 00:00:02 OK
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:44 -0500 Client session >>> QUIT
210.200.138.21 [00000478] Thu, 27 Nov 2003 03:33:45 -0500 Client session <<< 221 sinamail.com
SYSTEM [00000478] Thu, 27 Nov 2003 03:33:45 -0500 Client session Disconnected
-------------------------------------------------------------
How could it be accepted for delivery from a non local sender to a non local receipiant, Could that be some kind of hacking in into my server , if it is, can someone suggest a software that could resolve this problem

Any any suggestion will be greatly appreciated,

Thanks
 
See the FAQs pages about relaying and spam please

Marc
If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all. Please specify details.
Free Tip: The F1 Key does NOT destroy your PC!
 
i took a look at that, but some of these domains are yahoo.com or hotmail, also even if i block their ip address, i noticed that they are still sending emails, (as shown in my first post)

Any thing else i should look at ?

Thanks again
 
They are using your server as realy, so double and triple check your settings.
There is nothing else to look at, but it has to be setup correctly.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top