免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 2795 | 回复: 4
打印 上一主题 下一主题

[Mail] 关于qmail健康状况日志分析failure notice [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2004-10-27 11:09 |只看该作者 |倒序浏览
各位仁兄qmail系统日志如下:
-----------------------------------
Hi. This is the qmail-send program at winnet.com
I tried to deliver a bounce message to this address, but the bounce bounced!

<anonymous@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is the original bounce.

Return-Path: <>;
Received: (qmail 18610 invoked for bounce); 8 Oct 2004 20:02:54 -0000
Date: 8 Oct 2004 20:02:54 -0000
Wrom: XOEAIJJPHSCRTNHGSWZIDREX
To: anonymous@winnet.com
Subject: failure notice

Hi. This is the qmail-send program at winnet.com
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<root@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: <anonymous@winnet.com>;
Received: (qmail 18606 invoked by uid 0); 8 Oct 2004 20:02:54 -0000
Date: 8 Oct 2004 20:02:16 -0000
Message-ID: <20041008200216.18393.qmail@winnet.com>;
Wrom: CAXZOWCONEUQZAAFXISHJEXXIMQZUI
To: root@winnet.com
Subject: Cron run-parts /etc/cron.daily
X-Cron-Env:
X-Cron-Env:
X-Cron-Env:
X-Cron-Env:
X-Cron-Env:

/etc/cron.daily/00webalizer:

Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field
Warning: Truncating oversized request field

刚开始好像是用户不存在,但后面的 Warning: Truncating oversized request field  请求失败 ? 下面的就更厉害啦!非法访问!垃圾邮件?!
-------------------------------------------------------------------------------------
Hi. This is the qmail-send program at winnet.com
I tried to deliver a bounce message to this address, but the bounce bounced!

<root@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is the original bounce.

Return-Path: <>;
Received: (qmail 24213 invoked for bounce); 9 Oct 2004 20:02:12 -0000
Date: 9 Oct 2004 20:02:12 -0000
Wrom: VOTQNQEMSFDULHPQQWOYIYZUNNYCG
To: root@winnet.com
Subject: failure notice

Hi. This is the qmail-send program at winnet.com
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<root@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: <root@winnet.com>;
Received: (qmail 24205 invoked by uid 0); 9 Oct 2004 20:02:12 -0000
Date: 9 Oct 2004 20:02:12 -0000
Message-ID: <20041009200212.24204.qmail@winnet.com>;
Wrom: PKYLEJGDGVCJVTL
To: root@winnet.com
Subject: LogWatch for mail.pspharm.com.cn


################### LogWatch 4.3.1 (01/13/03) ####################
Processing Initiated: Sun Oct 10 04:02:01 2004
Date Range Processed: yesterday
Detail Level of Output: 0
Logfiles for Host: mail.pspharm.com.cn
################################################################

--------------------- pam_unix Begin ------------------------

sshd:
Authentication Failures:
root (210.118.75.247 ): 1 Time(s)
root (211.216.165.148 ): 3 Time(s)


---------------------- pam_unix End -------------------------


--------------------- qmail Begin ------------------------


Remote Server Responses:
Deferral(443) - 60 Time(s)
Failure(511) - 7 Time(s)
Failure(550) - 5 Time(s)
Success(250) - 28 Time(s)

Percentage(s):
Deferral - 60.00 %
Failure - 12.00 %
Success - 28.00 %

---------------------- qmail End -------------------------


--------------------- SSHD Begin ------------------------


Failed logins from these:
root/password from 210.118.75.247: 1 Time(s)
root/password from 211.216.165.148: 3 Time(s)

**Unmatched Entries**
Illegal user test from 211.216.165.148
Illegal user guest from 211.216.165.148
Illegal user admin from 211.216.165.148
Illegal user admin from 211.216.165.148
Illegal user user from 211.216.165.148
Illegal user test from 211.216.165.148
Illegal user test from 210.118.75.247
Illegal user guest from 210.118.75.247
Illegal user admin from 210.118.75.247
Illegal user admin from 210.118.75.247
Illegal user user from 210.118.75.247

---------------------- SSHD End -------------------------

--------------------- vpopmail Begin ------------------------


Password Failures:
luc@winnet.com - 2 Time(s)
test@winnet.com - 12 Time(s)
zl@winnet.com - 3 Time(s)
zln@winnet.com- 4 Time(s)

No Such User Found:
admin@winnet.com- 28 Time(s)
backup@winnet.com - 28 Time(s)
data@winnet.com- 28 Time(s)
master@winnet.com - 28 Time(s)
oracle@winnet.com - 28 Time(s)
pass@winnet.com- 28 Time(s)
passwd@winnet.com- 28 Time(s)
password@winnet.com- 28 Time(s)
root@winnet.com- 28 Time(s)
server@winnet.com- 28 Time(s)
steven@winnet.com- 28 Time(s)
stevenfamily@winnet.com- 28 Time(s)
sybase@winnet.com 28 Time(s)
user@winnet.com - 28 Time(s)
web@winnet.com - 28 Time(s)
webmaster@winnet.com - 28 Time(s)

---------------------- vpopmail End -------------------------


###################### LogWatch End #########################

------------------------------------------------------------------------------------

红色部分更是可怕的信号,非法访问连接。后面还有大量的垃圾邮件!不知道有没有一种方法让qmail不要接受系统中不存在的用户的邮件呀??另外如果系统中存在这些垃圾邮件(用户不存在),我应该如何处理呢?!!
针对目前这种状况不知各位仁兄有何良策呀???!!
在此一并谢过!!!!

论坛徽章:
0
2 [报告]
发表于 2004-10-27 11:17 |只看该作者

关于qmail健康状况日志分析failure notice

Hi. This is the qmail-send program at winnet.com
I tried to deliver a bounce message to this address, but the bounce bounced!

<root@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is the original bounce.

Return-Path: <>;
Received: (qmail 31571 invoked for bounce); 25 Oct 2004 20:02:02 -0000
Date: 25 Oct 2004 20:02:02 -0000
Wrom: NVWWCUFPEGAUTFJMVRESKPNKM
To: root@winnet.com
Subject: failure notice

Hi. This is the qmail-send program at winnet.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<root@winnet.com>;:
Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: <root@winnet.com>;
Received: (qmail 31563 invoked by uid 0); 25 Oct 2004 20:02:02 -0000
Date: 25 Oct 2004 20:02:02 -0000
Message-ID: <20041025200202.31562.qmail@winnet.com>;
Wrom: BIPBARHDMNNSKVF
To: root@winnet.com
Subject: LogWatch for mail.winnet.com


################### LogWatch 4.3.1 (01/13/03) ####################
Processing Initiated: Tue Oct 26 04:02:02 2004
Date Range Processed: yesterday
Detail Level of Output: 0
Logfiles for Host:
mail.winnet.com
################################################################

--------------------- pam_unix Begin ------------------------

sshd:
Authentication Failures:
apache (202.66.8.210 ): 1 Time(s)
operator (202.66.8.210 ): 1 Time(s)
mysql (202.66.8.210 ): 1 Time(s)
root (202.66.8.210 ): 59 Time(s)
adm (202.66.8.210 ): 2 Time(s)
nobody (202.66.8.210 ): 1 Time(s)


---------------------- pam_unix End -------------------------


--------------------- qmail Begin ------------------------


Remote Server Responses:
Deferral(421) - 1 Time(s)
Deferral(443) - 37 Time(s)
Deferral(451) - 1 Time(s)
Failure(511) - 5 Time(s)
Failure(550) - 1 Time(s)
Success(250) - 58 Time(s)

Percentage(s):
Deferral - 37.86 %
Failure - 5.83 %
Success - 56.31 %

---------------------- qmail End -------------------------


--------------------- SSHD Begin ------------------------


Failed logins from these:
adm/password from 202.66.8.210: 2 Time(s)
apache/password from 202.66.8.210: 1 Time(s)
mysql/password from 202.66.8.210: 1 Time(s)
nobody/password from 202.66.8.210: 1 Time(s)
operator/password from 202.66.8.210: 1 Time(s)
root/password from 202.66.8.210: 59 Time(s)

**Unmatched Entries**
Illegal user patrick from 202.66.8.210
Illegal user patrick from 202.66.8.210
Illegal user rolo from 202.66.8.210
Illegal user iceuser from 202.66.8.210
Illegal user horde from 202.66.8.210
Illegal user cyrus from 202.66.8.210
Illegal user www from 202.66.8.210
Illegal user wwwrun from 202.66.8.210
Illegal user matt from 202.66.8.210
Illegal user test from 202.66.8.210
Illegal user test from 202.66.8.210
Illegal user test from 202.66.8.210
Illegal user test from 202.66.8.210
Illegal user www-data from 202.66.8.210
Illegal user irc from 202.66.8.210
Illegal user irc from 202.66.8.210
Illegal user jane from 202.66.8.210
Illegal user pamela from 202.66.8.210
Illegal user cosmin from 202.66.8.210
Illegal user cip52 from 202.66.8.210
Illegal user cip51 from 202.66.8.210
Illegal user noc from 202.66.8.210
Illegal user webmaster from 202.66.8.210
Illegal user data from 202.66.8.210
Illegal user user from 202.66.8.210
Illegal user user from 202.66.8.210
Illegal user user from 202.66.8.210
Illegal user web from 202.66.8.210
Illegal user web from 202.66.8.210
Illegal user oracle from 202.66.8.210
Illegal user sybase from 202.66.8.210
Illegal user master from 202.66.8.210
Illegal user account from 202.66.8.210
Illegal user backup from 202.66.8.210
Illegal user server from 202.66.8.210
Illegal user adam from 202.66.8.210
Illegal user alan from 202.66.8.210
Illegal user frank from 202.66.8.210
Illegal user george from 202.66.8.210
Illegal user henry from 202.66.8.210
Illegal user john from 202.66.8.210
Illegal user test from 202.66.8.210

---------------------- SSHD End -------------------------


--------------------- vpopmail Begin ------------------------


Password Failures:
liyanxi@winnet.com- 4 Time(s)
shenjie@winnet.com - 9 Time(s)
zhuolin@winnet.com- 1 Time(s)

No Such User Found:
winnet.com@winnet.com- 1 Time(s)
webmaster@winnet.com- 1 Time(s)

---------------------- vpopmail End -------------------------


###################### LogWatch End #########################

论坛徽章:
0
3 [报告]
发表于 2004-10-27 11:23 |只看该作者

关于qmail健康状况日志分析failure notice

qmail不会接受系统中不存在的用户的邮件,
红色部分更不用担心,因为网络上的扫描和尝试登陆无时无刻都存在

论坛徽章:
0
4 [报告]
发表于 2004-10-27 11:32 |只看该作者

关于qmail健康状况日志分析failure notice

原帖由 "liusn2000" 发表:
qmail不会接受系统中不存在的用户的邮件,
红色部分更不用担心,因为网络上的扫描和尝试登陆无时无刻都存在


多谢你的回复!!!

另外,以下一些警告信息,不知是什么原因造成?连接请求过多?

/etc/cron.daily/00webalizer:

Warning: Truncating oversized request field
Warning: Truncating oversized request field

论坛徽章:
0
5 [报告]
发表于 2004-10-27 11:49 |只看该作者

关于qmail健康状况日志分析failure notice

没见过,也不清楚,你去linux版本问下,不过非请求失败...
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP