Home > Ask the Enterprise Linux Experts > Security Questions & Answers > Locking down open relays
Ask The Enterprise Linux Expert: Questions & Answers
EMAIL THIS

Locking down open relays

James Turnbull EXPERT RESPONSE FROM: James Turnbull

Pose a Question
Other Enterprise Linux Categories
Meet all Enterprise Linux Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 08 May 2007
I am using Linux as gateway server for LAN to access the Internet. All the mail I send from my gateway are going to spam. Some hackers are using my system for SMTP. How can I disable them so they don't access my server?

>

I am not sure what exactly the problem is here, but let's work through some of the options. Is all the mail you are sending being marked as spam by receivers, and hence your user's mail is not going through? If so, there are a few things you need to ascertain and fix. Find out why the email is being marked as spam -- most likely your IP address range was used by a spammer in the past and has been added to one or more spam blacklists. If this is so, you'll need to contact the blacklists to remove your IP addresses from the list.

If the email being generated is spam from (or through) your mail server or your hosts, then you could be in one of two situations -- either your host is an open relay or one of your hosts has been compromised and is being used to disseminate spam. In the first instance, an open relay is a mail server that allows anyone on the Internet to send mail through it. Check your mail server's logs to confirm this. You can also test if your mail servers are an open relay by using tools like mail relay testing or the SMTP open relay test. If you are an open relay, then you'll need to consult your mail server's documentation to determine how to change this.

In the second instance, you'll need to review your mail server's logs to determine which of your hosts has been compromised. Then, shut down that host or hosts and follow your standard incident or forensic processes to determine how the compromise occurs and what you need to do to fix those hosts. If you don't feel confident to do this yourself you may want to consider engaging a third-party IT security consultancy or organization.

By the way, If one of your hosts has been compromised, you might find that you have also been added to some spam blacklists. You'll need to check and confirm this and then work with the blacklists to remove yourself. Be mindful that dealing with some of these blacklists can be complicated and time-consuming.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Linux Migration Advice: Unix-to-Linux, Windows-to-Linux
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts