This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

root email - security
#1
root email - security
Hi I have been trying to secure my server down.

I am now getting this from root@domain.com
Has anyone encountered an issue like this.
thanks.


Time:    Tue Apr  4 23:42:23 2017 -0700
PID:     3046 (Parent PID:2542)
Account: postfix
Uptime:  112 seconds


Executable:

/usr/libexec/postfix/smtpd


Command Line (often faked in exploits):

smtpd -n 127.0.0.1:10025 -t inet -u -c -o content_filter= -o smtpd_helo_restrictions= -o smtpd_sender_restrictions= -o smtpd_recipient_restrictions=permit_mynetworks,reject -o mynetworks=127.0.0.0/8 -o smtpd_error_sleep_time=0 -o smtpd_soft_error_limit=1001 -o smtpd_hard_error_limit=1000 -o receive_override_options=no_header_body_checks -o smtpd_helo_required=no -o smtpd_client_restrictions= -o smtpd_restriction_classes= -o disable_vrfy_command=no -o strict_rfc821_envelopes=yes


Network connections by the process (if any):

tcp: 127.0.0.1:10025 -> 0.0.0.0:0
tcp: 127.0.0.1:10025 -> 127.0.0.1:53888


Files open by the process (if any):

/dev/null
/dev/null
/dev/null
/var/spool/postfix/pid/inet.127.0.0.1:10025
anon_inode:[eventpoll]
/etc/aliases.db
/etc/aliases.db
Reply
Thanks given by:
#2
RE: root email - security
nope but you might google it.
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#3
RE: root email - security
I have not seen this before either.
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:
#4
RE: root email - security
These messages were sent out by sentora because of CSF firewall. Removed it and alerts were gone. Still don't understand the messages.
Reply
Thanks given by:


Possibly Related Threads…
Thread Author Replies Views Last Post
change username from email umarzuki@gmail.com 0 1 ,257 11-25-2022, 05:46 PM
Last Post: umarzuki@gmail.com
Email has stopped coming through rsthomas 3 3 ,856 06-21-2022, 12:05 PM
Last Post: fearworks
spammer email plateform sentora scram 8 13 ,839 04-03-2020, 05:43 PM
Last Post: 5050

Forum Jump:


Users browsing this thread: 1 Guest(s)