G
G
grindle2018-02-20 00:15:19
postfix
grindle, 2018-02-20 00:15:19

Is the server sending spam?

Is the server spamming?
Not so long ago, our server was blocked for spam.
Unfortunately, the hoster does not provide detailed information about spam (headers, etc.).
That is, according to them, IDs snort detected spam and blocked the server.
We do not use the mail server at all, by default postfix was installed in the system (already disabled).
We have disabled this service for now.
What are the possible sources of spam?
so far we see the following:
1. problems with the postfix config, and someone could send letters through us.
2. vulnerability in the server, there is access to the server and someone sends letters via sendmail.
3. Maybe spoofing in the host network? Someone is pretending to be someone else's server.
4. false postive on tor hidden service, do we drive https traffic through it?
OS proxmox, also installed rabbitmq, tor as hidden service.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
P
Puma Thailand, 2018-02-20
@opium

Well, it’s stupid to look with a tisipidump who sends to port 25, well, there’s a netstat in your hands

G
grindle, 2018-02-20
@grindle

This is understandable, they are interested in the general vectors of possible "attacks". maybe we missed something (in paragraphs 1-4)

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question