compromised mail server

2014-08-21 Thread Charles Richard
Hi, I have inherited a postfix 2.6 mail server which also uses Dovecot 1.1.14 . This is basically a legacy mail server that can't be shutoff because it is now used only to forward the emails sent to a few mailboxes to the new email addresses now being used. This email server has been

Re: compromised mail server

2014-08-21 Thread Wietse Venema
Charles Richard: Hi, I have inherited a postfix 2.6 mail server which also uses Dovecot 1.1.14 . This is basically a legacy mail server that can't be shutoff because it is now used only to forward the emails sent to a few mailboxes to the new email addresses now being used. This email

Re: compromised mail server

2014-08-21 Thread DTNX Postmaster
On 21 Aug 2014, at 14:54, Charles Richard charle...@thelearningbar.com wrote: I have inherited a postfix 2.6 mail server which also uses Dovecot 1.1.14 . This is basically a legacy mail server that can't be shutoff because it is now used only to forward the emails sent to a few mailboxes to

Re: compromised mail server

2014-08-21 Thread Charles Richard
Hi, See inline. Thank you! On Thu, Aug 21, 2014 at 10:02 AM, Wietse Venema wie...@porcupine.org wrote: Charles Richard: Hi, I have inherited a postfix 2.6 mail server which also uses Dovecot 1.1.14 . This is basically a legacy mail server that can't be shutoff because it is now

Re: compromised mail server

2014-08-21 Thread Wietse Venema
Charles Richard: Before you can stop the spam, you must find out how it enters Postfix. You will have to examine the maillog (mail.log, or whatever) file to find out if it enters via smtpd (network) or via pickup (local submission). It if arrives from the network, perhaps a user account

Re: compromised mail server

2014-08-21 Thread li...@rhsoft.net
Am 21.08.2014 um 15:43 schrieb Charles Richard: How can I tell if it enters via smtpd or via pickup? The first message is see starts in the following manner: Aug 21 09:59:49 servername postfix/qmgr[28270]: 158335F: from=x...@x.com mailto:x...@x.com, size=2151, nrcpt=14 (queue