V
V
Vic Shostak2017-11-01 15:01:56
Debian
Vic Shostak, 2017-11-01 15:01:56

Is it possible to create a rule like this for iptables (Debian 9.x)?

Good day!
Tell me if it is possible to write a rule for iptablesthe following:
1. Close all OUTGOING from port 25 (SMTP);
2. If the script (PHP) makes an attempt to send via smtp.gmail.com(for example), then we allow it.
Let me explain. I can’t catch a spam bot that flew into the client’s VDS in any way (apparently through vulnerabilities in the bicycle self-writing on PHP 5.2 the size of a normal CRM, some php files for 500+ MB). Because his IP is on the spam lists (spamhaus.org) every week and mail stupidly doesn't reach Gmail mailboxes from VDS, for
example
. Thank you.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
A
Andrey, 2017-11-01
@VELIK505

Disable the mail() function on the server first.
in php.ini find:
disable_functions =
and add mail and eval at the same time.
tell ip to glow it constantly in spam lists? Ban him
What is Exim used for? you can allow sending only to trusted mailboxes for postfix there is something like that.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question