There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
UNIX/Linux
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > UNIX/Linux >
Help Understanding maillog


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
chuckf's Avatar
Junior Member with 15 posts.
 
Join Date: Oct 2002
21-Oct-2002, 05:12 PM #1
Help Understanding maillog
I have a few servers.. I just got a firewall, but its not installed yet.. but I believe people are using my server for spam. I have both a freebsd machine and just got a linux redhat 7.3 machine I use mostly for email.

I have a couple of questions.
1. If you wanted to track down who might be using a your server as a proxy for spam, how would you do it for the linux? I use qpopper btw.. if that helps.

2. Can you tell me what these entries in /var/log/maillog mean. I'm including a few different types of entries that have me confused.
(i replaced my server name with "anyserver")

Oct 21 05:00:44 anyserver sendmail[31814]: g9LC0ht31814: from=<admin37@host.goacom.com>, size=872, class=0, nrcp$

Oct 21 04:21:44 anyserver sendmail[31777]: g9LBLit31777: lost input channel from transport15c.azoogle.com [66.19$
$azoogle.com [66.197.140.87]


Oct 21 04:51:50 anyserver sendmail[31798]: g9J66xt18539: to=<bens@ndc.com.au>, ctladdr=<myname@anyserver.com > (50$.0, stat=Deferred: Connection refused by camtech.net.au.


Oct 21 09:14:11 anyserver sendmail[32099]: g9LGEAt32099: from=<approval7503@mail.ru>, size=422, class=0, nrcpts=$
$o=SMTP, daemon=MTA, relay=[212.150.165.16]
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 06:03 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.