Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Exploited Postfix
PostPosted: Tue Mar 13, 2012 10:20 am 
Offline
Newbie

Joined: Tue Mar 13, 2012 10:13 am
Posts: 3
Hi All,

I have been notified about "Phishing Emails" being sent out of my Linode 2 days ago. After investigating logs and traffic, it turned out that my installation of Postfix is exploited.

This means that at the moment I start Postfix, it starts sending out spam emails. The traffic, I/O rate, and CPU usage increase dramatically upon starting Postfix.

And after stopping postfix, everything goes back to normal immediately.

Could you please help me fix this issue with Postfix?


Regards,
Ali


Top
   
 Post subject:
PostPosted: Tue Mar 13, 2012 1:54 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
Postfix is unlikely to be exploited. What you're more likely to be seeing are the messages in the queue. When you restart postfix it starts to send the queued messages. You need to run "postsuper -d ALL" to delete all messages in the queue.

But you need to find out _what_ part of your server was exploited to generate the messages. Just flushing the queue won't fix that problem. It's probably a web page, somewhere.

_________________
Rgds
Stephen
(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Tue Mar 13, 2012 3:02 pm 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
Also check your installation against http://www.abuse.net/relay.html

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
 Post subject:
PostPosted: Tue Mar 13, 2012 3:25 pm 
Offline
Newbie

Joined: Tue Mar 13, 2012 10:13 am
Posts: 3
sweh wrote:
Postfix is unlikely to be exploited. What you're more likely to be seeing are the messages in the queue. When you restart postfix it starts to send the queued messages. You need to run "postsuper -d ALL" to delete all messages in the queue.

But you need to find out _what_ part of your server was exploited to generate the messages. Just flushing the queue won't fix that problem. It's probably a web page, somewhere.



Thanks. "postsuper -d ALL" did the job. But I still need to find the source, so that it won't happen again...


Top
   
 Post subject:
PostPosted: Tue Mar 13, 2012 7:40 pm 
Offline
Senior Member

Joined: Fri May 02, 2008 8:44 pm
Posts: 1121
Any websites running outdated versions of popular CMS's, or a contact form?


Top
   
 Post subject:
PostPosted: Wed Mar 14, 2012 12:54 am 
Offline
Newbie

Joined: Tue Mar 13, 2012 10:13 am
Posts: 3
hybinet wrote:
Any websites running outdated versions of popular CMS's, or a contact form?


There is a website created using django that has a contact form. I should probably check http requests to/from the contact page.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group