Massive outgoing on port 25. Under attack?
Posted: Tue Oct 17, 2006 11:57 am
Ove the past few days I have been seeing about 8K/hour messages in my syslog showing somethin similar to the following:
Not all the traffic is going to (or attempting to go to) that specific goldenware.com server. There are many different servers involved, but all from goldenware.com.
Interestingly, the corresponding incoming traffic is also listed, but it is being blocked by the firewall. I guess I don't understand how I have nothing coming in from these servers, but so much going out....
I have used three different methods to make sure I'm not an open relay. I have blocked all INCOMING traffic from all the goldenware.com IP's. I have even blacklisted all theri IP's in my Barracuda spam firewall. But I continue to get all these outgoing attempts.
I rebooted the Scalix server, and after the restart the message did not appear for about an hour. But then they all started again.
Is there some newbie mistake I am making here? My typical syslog traffic is 3K message per hour. Now I am running at 13K and its' still climbing...
Code: Select all
allow out eth1:0 60 tcp 20 64 192.168.111.17 (emailserver) 68.142.82.239 (badaling2.goldenware.com) 51218 25 syn (SMTP-Outgoing)
Not all the traffic is going to (or attempting to go to) that specific goldenware.com server. There are many different servers involved, but all from goldenware.com.
Interestingly, the corresponding incoming traffic is also listed, but it is being blocked by the firewall. I guess I don't understand how I have nothing coming in from these servers, but so much going out....
I have used three different methods to make sure I'm not an open relay. I have blocked all INCOMING traffic from all the goldenware.com IP's. I have even blacklisted all theri IP's in my Barracuda spam firewall. But I continue to get all these outgoing attempts.
I rebooted the Scalix server, and after the restart the message did not appear for about an hour. But then they all started again.
Is there some newbie mistake I am making here? My typical syslog traffic is 3K message per hour. Now I am running at 13K and its' still climbing...