CentOS 6.3 with Panel 11.0.9 Update #15
Hello, I have been having spam appear in my queue originating from external network without using an authenticated account which I appear to be relaying.
subject "СТРОИТЕЛЬНАЯ ДЕЯТЕЛЬНОСТЬ"
sender, "=?windows-1251?B?wtGoIM4g0dLQzsjSxcvczc7JIMTF39LFy9zN?="
Checking it from the queue I see,
X-No-Relay: not in my network
X-No-Relay: not in my network
--snip--
Received: from Unknown (unknown [190.251.104.30])
--snip--
Why does it say received? I should not have allowed it as they are a non-authenticated user.
Checking Maillog I see repeated,
Oct 1 03:45:00 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:01 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:01 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: noah - short names not allowed from @ [::ffff:200.91.77.46]IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: nina - short names not allowed from @ [::ffff:200.91.77.46]ERR: LOGIN FAILED, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGIN FAILED, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:09 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:09 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:10 uber postfix/qmgr[7152]: 3B9FDEC206F: from=<tsmithinpekin@insightbb.com>, size=19340, nrcpt=20 (queue active)
Oct 1 03:45:10 uber postfix/qmgr[7152]: 21AD2EC21F1: from=<yannicksouevamanien@wanadoo.fr>, size=60283, nrcpt=20 (queue active)
Oct 1 03:45:11 uber pop3d: IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: noah - short names not allowed from @ [::ffff:200.91.77.46]IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: nina - short names not allowed from @ [::ffff:200.91.77.46]
Aside from blocking the IP address, any ideas on how to prevent this?
Thank you,
Hello, I have been having spam appear in my queue originating from external network without using an authenticated account which I appear to be relaying.
subject "СТРОИТЕЛЬНАЯ ДЕЯТЕЛЬНОСТЬ"
sender, "=?windows-1251?B?wtGoIM4g0dLQzsjSxcvczc7JIMTF39LFy9zN?="
Checking it from the queue I see,
X-No-Relay: not in my network
X-No-Relay: not in my network
--snip--
Received: from Unknown (unknown [190.251.104.30])
--snip--
Why does it say received? I should not have allowed it as they are a non-authenticated user.
Checking Maillog I see repeated,
Oct 1 03:45:00 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:01 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:01 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: noah - short names not allowed from @ [::ffff:200.91.77.46]IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: nina - short names not allowed from @ [::ffff:200.91.77.46]ERR: LOGIN FAILED, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGIN FAILED, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:07 uber pop3d: LOGOUT, ip=[::ffff:200.91.77.46]
Oct 1 03:45:09 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:09 uber pop3d: Connection, ip=[::ffff:200.91.77.46]
Oct 1 03:45:10 uber postfix/qmgr[7152]: 3B9FDEC206F: from=<tsmithinpekin@insightbb.com>, size=19340, nrcpt=20 (queue active)
Oct 1 03:45:10 uber postfix/qmgr[7152]: 21AD2EC21F1: from=<yannicksouevamanien@wanadoo.fr>, size=60283, nrcpt=20 (queue active)
Oct 1 03:45:11 uber pop3d: IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: noah - short names not allowed from @ [::ffff:200.91.77.46]IMAP connect from @ [::ffff:200.91.77.46]checkmailpasswd: FAILED: nina - short names not allowed from @ [::ffff:200.91.77.46]
Aside from blocking the IP address, any ideas on how to prevent this?
Thank you,