Re: [SLUG] attacked!

From: Daniel Jarboe (daniel.jarboe@gmail.com)
Date: Fri Jun 16 2006 - 09:00:12 EDT


> First thing I did was stop Postfix. Turns out it was listening on all
> interfaces, instead of just "lo". Fixed.
>
> Now, I need to figure out how I was broken in to. I don't see any holes in
> the firewall, and root login is disabled through ssh.

How about eliminating the most likely possibility first. Have you
determined that port 25 was not open in the firewall? And that your
postfix is not configured as a relay?

~ Daniel
-----------------------------------------------------------------------
This list is provided as an unmoderated internet service by Networked
Knowledge Systems (NKS). Views and opinions expressed in messages
posted are those of the author and do not necessarily reflect the
official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 20:09:48 EDT