[qmailtoaster] Dummy email was compromised - Now analyzing all my logs and need help

2015-04-10 Thread Richard Baxant
Hello, I had a dummy email with a rather simple password. I've since deleted that account however it sent out 70,000+ spam emails in a 24 hour period according to my service provider. Running the following: tail -f /var/log/qmail/current | tai64nlocal I get the following output every 2

Re: [qmailtoaster] Dummy email was compromised - Now analyzing all my logs and need help

2015-04-10 Thread Eric Broch
Hi Richard, Yes, I've had this happen before. It really is quite a drag. You might want to check if your domain is blacklisted also, here http://mxtoolbox.com/blacklists.aspx. What is the log file you're looking at? I'm fairly sure it's not /var/log/qmail/current, maybe

[qmailtoaster] question about tlsciphers

2015-04-10 Thread Fabian Santiago
is it possible to define: smtp smtp-ssl and have each honor a different cipher list such as the control file tlsserverciphers? if i can simply pass the environment variable tlsciphers, how do i do that exactly and does it in fact take precedence over the standard control file tlsserverciphers?

Re: [qmailtoaster] Dummy email was compromised - Now analyzing all my logs and need help

2015-04-10 Thread Richard Baxant
Hi Eric, Sorry it is the following that i'm monitoring: tail -f /var/log/qmail/smtp/current | tai64nlocal I've used mxtoolbox to do that check and still have green check marks I will give those a try. Is there anything else I should be looking for? TIA Richard On Fri, Apr 10, 2015 at 9:21

Re: [qmailtoaster] Dummy email was compromised - Now analyzing all my logs and need help

2015-04-10 Thread Richard Baxant
This is what I get when I run those commands: [root@mail smtp]# qmHandle -l Messages in local queue: 0 Messages in remote queue: 0 [root@mail smtp]# qmailctl queue messages in queue: 0 messages in queue but not yet preprocessed: 0 On Fri, Apr 10, 2015 at 9:47 PM, Richard Baxant

Re: [qmailtoaster] Dummy email was compromised - Now analyzing all my logs and need help

2015-04-10 Thread Eric Broch
I think I'd block that ip (206.228.154.18) on my firewall. If someone else has a better ideal, I'm all ears. On 4/10/2015 7:47 PM, Richard Baxant wrote: Hi Eric, Sorry it is the following that i'm monitoring: tail -f /var/log/qmail/smtp/current | tai64nlocal I've used mxtoolbox to do