Koozali.org: home of the SME Server

Am I receiving/sending SPAM??

Offline mauro

  • ****
  • 101
  • +0/-0
Am I receiving/sending SPAM??
« on: August 15, 2007, 09:30:08 AM »
Hi,
 today I received two nice messages from sme7admin: last night at 1:17 I received 919 mails and I sent out another 103!
Now, I had a look at both qmail and qpsmtpd logs around that time and I did not find any strange traffic.
Nobody was in the office, all PC clients shut down, no VPN connections, no ntp time adjustments this night...
None of us received any extra amount of spam, even if I can see the incoming mail graph in sme7admin actually showing a peak of incoming and outcoming emails.
What else should I check? I'm a bit warried...

Have a nice day!
Mauro
All parts should go together without forcing. You must remember that the parts you are reassembling were disassembled by you. Therefore, if you can't get them together again, there must be a reason. By all means, do not use a hammer.
-- IBM maintenance manual (1975)

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: Am I receiving/sending SPAM??
« Reply #1 on: August 15, 2007, 10:30:03 AM »
Hi,
 today I received two nice messages from sme7admin: last night at 1:17 I received 919 mails and I sent out another 103!
Now, I had a look at both qmail and qpsmtpd logs around that time and I did not find any strange traffic.
Nobody was in the office, all PC clients shut down, no VPN connections, no ntp time adjustments this night...
None of us received any extra amount of spam, even if I can see the incoming mail graph in sme7admin actually showing a peak of incoming and outcoming emails.
What else should I check? I'm a bit warried...
Normally SME Server is closed to relaying, so it would be very hard to SPAM using a SME Server. Did you modify any configuration entries like remote access settings or open ports for external access to mail, define remote hosts as local hosts?
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline mauro

  • ****
  • 101
  • +0/-0
Re: Am I receiving/sending SPAM??
« Reply #2 on: August 15, 2007, 10:35:46 AM »
No, I mean, I allow SSH connections only from local networks; no PPTP; external access through POP3S only (no webmail)... but the strange thing is that I really can't find all those messages in the log files. :-?
All parts should go together without forcing. You must remember that the parts you are reassembling were disassembled by you. Therefore, if you can't get them together again, there must be a reason. By all means, do not use a hammer.
-- IBM maintenance manual (1975)

Offline mauro

  • ****
  • 101
  • +0/-0
Re: Am I receiving/sending SPAM??
« Reply #3 on: August 15, 2007, 10:57:51 AM »
I think it's a known bug (bugzilla #1051), basically an interference between sme7admin and logrotate; I have logrotate running at 1:12 and sme7admin sent out the alert exactly 5 minutes later. I feel better now...
Cactus, thanks for the suggestions anyway.
All parts should go together without forcing. You must remember that the parts you are reassembling were disassembled by you. Therefore, if you can't get them together again, there must be a reason. By all means, do not use a hammer.
-- IBM maintenance manual (1975)

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: Am I receiving/sending SPAM??
« Reply #4 on: August 15, 2007, 11:03:11 AM »
Cactus, thanks for the suggestions anyway.
You are welcome!
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline Confucius

  • *****
  • 235
  • +0/-0
Re: Am I receiving/sending SPAM??
« Reply #5 on: August 15, 2007, 12:44:53 PM »
Seems to me a situation of the bulk is marked as spam and the mail you think you are sending out might be replies from qmail that you don't have the adresses they were trying to reach. Common thing with spam, they try every option they can come up with.

Offline micropitt

  • ***
  • 44
  • +0/-0
Re: Am I receiving/sending SPAM??
« Reply #6 on: August 15, 2007, 03:16:13 PM »
Hi,
 today I received two nice messages from sme7admin: last night at 1:17 I received 919 mails and I sent out another 103!
Now, I had a look at both qmail and qpsmtpd logs around that time and I did not find any strange traffic.
Nobody was in the office, all PC clients shut down, no VPN connections, no ntp time adjustments this night...
None of us received any extra amount of spam, even if I can see the incoming mail graph in sme7admin actually showing a peak of incoming and outcoming emails.
What else should I check? I'm a bit warried...

Have a nice day!
Mauro


Yep, same here. Last night I had 413 incoming and 173 outgoing but nothing in the logs......
...