Someone used my postfix smtp (port 25) to send spam mails to me

Posted by Andreas on Server Fault See other posts from Server Fault or by Andreas
Published on 2012-11-22T16:53:23Z Indexed on 2012/11/22 17:00 UTC
Read the original article Hit count: 186

Filed under:
|
|
|
|

This week, someone started to send spam-mails through my postfix-smtp access (I verified by logging in through telnet from an arbitrary pc and sending mails with any ids myself) on my server, with recipient and target being [email protected]. Since I have a catchall and mail-fowarding to my google account, I received all those (many) mails.

After a lot of configuration (I lost track of what change did what, going through dozends of topics here and over the net) that hole seems fixed. Still, what hapened?

Does port 25 need to be open and accepting for my catchall to work?

What configuration did I do wrong?

I remember the first thing I changed (that had an effect) was the inet_interface setting in main.cf, only later to find out that if this does not say "all", my mail to mydomain.com does not get forwarded any more.

© Server Fault or respective owner

Related posts about debian

Related posts about postfix