[svlug] spam question

Gordon Vrololjak gvrdolja at nature.Berkeley.EDU
Fri Aug 31 10:15:01 PDT 2001


Hello,
I just saw the following in a log today....
Security Violations
=-=-=-=-=-=-=-=-=-=
Aug 30 23:40:50 wilfred sendmail[9464]: XAA09464: ruleset=check_rcpt,
arg1=<csbeing at hotmail.com>, relay=[61.154.230.76], reject=550
<csbeing at hotmail.com>... Relaying denied
Aug 30 23:41:08 wilfred sendmail[9466]: XAA09466: ruleset=check_rcpt,
arg1=<csbeing at hotmail.com>, relay=[61.154.230.76], reject=550
<csbeing at hotmail.com>... Relaying denied

Does this imply that someone was trying to use sendmail on our server to
send spam mail?  Should I contact the postmaster at hotmail.com, or should I
send an email to the domain contact in China for 61.154.230.76 which I
think is hostmaster at ns.chinanet.cn.net, by a whois search of
whois.ripe.net.  I've not had any response at all from any contacts I've
sent to China for people portscanning.  Anyone ever have any response from
that country?

Any suggestions to other things I should do for our server in question?
It is redhat 6.1 with sendmail-8.9.3-15 rpm.

\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\
Gordon Ante Vrdoljak                           	      Electron Microscope Lab
ICQ 23243541   http://nature.berkeley.edu/~gvrdolja   26 Giannini Hall
gvrdolja at nature.berkeley.edu                          UC Berkeley
phone (510) 642-2085                                  Berkeley CA 94720-3330
fax   (510) 643-6207 cell (510) 290-6793





More information about the svlug mailing list