Re: Have I been cracked?

Top Page
Attachments:
Message as email
+ (text/plain)
Delete this message
Reply to this message
Author: Bob Holtzman
Date:  
To: plug-discuss
Subject: Re: Have I been cracked?
On Fri, 20 Aug 2004, Jeremy C. Reed wrote:

> On Fri, 20 Aug 2004, Bob Holtzman wrote:
>
> > I just got logwatch fired up and I'm seeing entries such as:
> >
> > --------------------- sendmail Begin ------------------------
> >
> > 1161352 bytes transferred
> > 267 messages sent
> > ---------------------- sendmail End -------------------------
> >
> > If this refers to outgoing messages from my box, I have a problem, true?
> > I'm running RH 7.3 and checked medium security level when I installed.
> > Any other information required?
>
> Not enough information to know if you have a problem.
>
> Have a look at the real log that logwatch analyzed. Maybe it is
> /var/log/maillog or /var/log/mail.log or similar. (See /var/log/mail* and
> also "grep mail /etc/syslog.conf".)
>
> What do your logs show you about the outgoing mails? What generated them
> and/or who are the senders?


Very interesting. No outgoing mail listed in /var/log/maillog except the
incoming ones relayed to me from sendmail. these are marked: stat=Sent.
Even the outgoing messages I know I sent (checked by date and time) are
not listed.

>
> I wrote a sendmail log analyzer. It might be useful for you.
> http://www.reedmedia.net/software/sendmail_stats/


I'll test this out as soon as I get some time.

Any more info needed?
Thanks.

--
Bob Holtzman
"If you think you're getting free lunch,
......check the price of the beer!"

---------------------------------------------------
PLUG-discuss mailing list -
To subscribe, unsubscribe, or to change you mail settings:
http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss