Freesco, NND, CDN, EOS
http://forum.freesco.pl/

Wirus w exim
http://forum.freesco.pl/viewtopic.php?f=24&t=10412
Strona 1 z 1

Autor:  w_o_j [ piątek, 23 grudnia 2005, 02:44 ]
Tytuł:  Wirus w exim

Witam

Coś się podpieło pod mój serwer i wysyła mi jakieś maile w świat, jak exim jest odpalony o procesor zajęty jest w 100%. Zatrzymałem exim'a i jest spokój, ale to nie rowiązuje sprawy bo mi poczta nie działa. Ktoś ma jaiś pomysł jak to ustrojstwo wywalić.

Poniżej trochę logów z mainlog exima ,który w 7 dni urósł mi do ponad 500MB

: [/] [] ()
(-51): retry time not reached
2005-12-14 06:06:33 1EmOdY-0004Hh-9x == janny27@pchome.com.tw routing defer (-51): retry time not reached
2005-12-14 06:06:33 1EmBw1-0006Vo-W2 == alllo@cm1.ethome.net.tw R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmMuK-0004yM-O2 SMTP error from remote mailer after RCPT TO:<ggdq@hanmir.com>: host mailex11.paran.com [211.41.82.76]: 452 Too many recipients received this hour
2005-12-14 06:06:33 1EmKuM-0005Qi-Gv SMTP error from remote mailer after RCPT TO:<younij@hanmir.com>: host mailex10.paran.com [211.41.82.75]: 452 Too many recipients received this hour
2005-12-14 06:06:33 1EmOgp-0004ox-23 == newrich@hitel.net R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOgp-0004ox-23 == newricom@hitel.net R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOgp-0004ox-23 == k2593006@paxnet.co.kr R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOgp-0004ox-23 == k27840@paxnet.co.kr R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOgp-0004ox-23 == p2389159@paxnet.co.kr R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOgp-0004ox-23 == p303@paxnet.co.kr R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
2005-12-14 06:06:33 1EmOfz-0004fj-17 Message is frozen


A teraz trochę z rejectlog:
: [/] [] ()
2005-12-23 00:48:24 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <kor-ljy2000@hanmail.co.kr                                                       |        |˘Ĺż¬°á˝ÇĆĐ>")
2005-12-23 00:48:38 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <kor4816@hitel.net                                                               |        |˘Ĺż¬°á˝ÇĆĐ>")
2005-12-23 00:48:40 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <kowic@unitel.co.kr                                                              |        |˘˝ŔüĽŰĽş°ř>")
2005-12-23 00:48:42 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <kor4816@hitel.net                                                               |        |˘Ĺż¬°á˝ÇĆĐ>")
2005-12-23 00:48:44 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <kowic@unitel.co.kr                                                              |        |˘˝ŔüĽŰĽş°ř>")
2005-12-23 00:49:36 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <ksk1002@dreamwiz.com                                                            |        |˘˝ŔüĽŰĽş°ř>")
2005-12-23 00:49:45 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <krootone@yahoo.co.kr                                                            |        |˘˝ŔüĽŰĽş°ř>")
2005-12-23 00:49:49 SMTP call from (83.19.147.154) [58.77.217.42] dropped: too many syntax or protocol errors (last command was "RCPT TO: <krootone@yahoo.co.kr                                                            |        |˘˝ŔüĽŰĽş°ř>")


Ktoś ma może jakiś pomysł ???

8O

Strona 1 z 1 Strefa czasowa UTC+2godz.
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/