sendmail log question 2003-06-27 - By Gordon Bowersox
Back Found some odd log file entries while combating SOBIG.e
This first entry shows one instance of receiving the virus. It has both sendmail accepting the message and sendmail delivering the message. I also pasted the header of the message. Pretty normal.
---
Jun 25 18:05:42 mail sendmail[4918]: h5PM5dC04918: from=<20gail.kulbeth@(protected) .com>, size=111813, class=0, nrcpts=1, msgid=<200306252205.h5PM5dC04918@(protected) .com>, proto=ESMTP, daemon=MTA, relay=hv.domain.com [10.10.50.25]
Jun 25 18:05:42 mail sendmail[4942]: h5PM5dC04918: to=<luser@(protected)>, delay=00:00:03, xdelay=00:00:00, mailer=local, pri=141498, dsn=2.0.0, stat=Sent
Return-Path: <20gail.kulbeth@(protected)> Received: from 94X8JT (hv.domain.com [10.10.50.25]) by mail.domain.com (8.11.6/8.11.6) with ESMTP id h5PM5dC04918 for <luser@(protected)>; Wed, 25 Jun 2003 18:05:39 -0400 Message-Id: <200306252205.h5PM5dC04918@(protected)> From: <20gail.kulbeth@(protected)> To: <luser@(protected)> Subject: Re: Movie Date: Wed, 25 Jun 2003 17:05:34 --0500 Importance: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MSMail-Priority: Normal X-Priority: 3 (Normal) MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="CSmtpMsgPart123X456_000_018486FB"
-- ----
These entries do not have a log file entry for sendmail accepting the message for delivery. Only sendmail delivering the message. I included 1 header
-- ---- Jun 25 17:18:05 mail sendmail[2397]: h5PLI2C02352: to=<luser@(protected)>, delay=00:00:03, xdelay=00:00:01, mailer=local, pri=141498, dsn=2.0.0, stat=Sent
Jun 25 16:51:54 mail sendmail[15546]: h5PKpoC15537: to=<luser@(protected)>, delay=00:00:04, xdelay=00:00:01, mailer=local, pri=141498, dsn=2.0.0, stat=Sent
Return-Path: <taylorwright8@(protected)> Received: from MNELSON_LT (hv.domain.com [10.10.50.25]) by mail.domain.com (8.11.6/8.11.6) with ESMTP id h5PKpoC15537 for <luser@(protected)>; Wed, 25 Jun 2003 16:51:50 -0400 Message-Id: <200306252051.h5PKpoC15537@(protected)> From: <taylorwright8@(protected)> To: <luser@(protected)> Subject: Re: Movie Date: Wed, 25 Jun 2003 16:51:50 --0400 Importance: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MSMail-Priority: Normal X-Priority: 3 (Normal) MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="CSmtpMsgPart123X456_000_009B6ABD"
Jun 25 16:44:30 mail sendmail[9640]: h5PKiOC09573: to=<luser@(protected)>, delay=00:00:04, xdelay=00:00:02, mailer=local, pri=141498, dsn=2.0.0, stat=Sent
I tried grep the log file for the smtp id's in all instances. I sent mail from yahoo, my client, pine on the mail server and a machine that lived on the same subnet. All have two entries in the log file. Has anyone else seen the single entry in their logs? I also grep'ed -20 and looked at the lines nearby. The 10.10.50.25 is the firewall and shows if nothing else they came from the outside.
Thanks, Gordon Bowersox
<!doctype html public "-//w3c//dtd html 4.0 transitional//en"> <html>
<pre>Found some odd log file entries while combating SOBIG.e
This first entry shows one instance of receiving the virus. It has both sendmail accepting the message and sendmail delivering the message. I also pasted the header of the message. Pretty normal.
---
Jun 25 18:05:42 mail sendmail[4918]: h5PM5dC04918: from=<20gail.kulbeth @(protected)>, size=111813, class=0, nrcpts=1, msgid=<200306252205.h5PM5dC04918@(protected) .com>, proto=ESMTP, daemon=MTA, relay=hv.domain.com [10.10.50.25]
Jun 25 18:05:42 mail sendmail[4942]: h5PM5dC04918: to=<luser@(protected)>, delay=00:00:03, xdelay=00:00:00, mailer=local, pri=141498, dsn=2.0.0, stat=Sent </pre> Return-Path: <20gail.kulbeth@(protected)> <br>Received: from 94X8JT (hv.domain.com [10.10.50.25]) <br> by mail.domain.com (8.11.6/8.11 .6) with ESMTP id h5PM5dC04918 <br> for <luser@(protected)>; Wed, 25 Jun 2003 18:05:39 -0400 <br>Message-Id: <200306252205.h5PM5dC04918@(protected)> <br>From: <20gail.kulbeth@(protected)> <br>To: <luser@(protected)> <br>Subject: Re: Movie <br>Date: Wed, 25 Jun 2003 17:05:34 --0500 <br>Importance: Normal <br>X-Mailer: Microsoft Outlook Express 6.00.2600.0000 <br>X-MSMail-Priority: Normal <br>X-Priority: 3 (Normal) <br>MIME-Version: 1.0 <br>Content-Type: multipart/mixed; <br> boundary="CSmtpMsgPart123X456 _000_018486FB" <p>-- ---- <p>These entries do not have a log file entry for sendmail accepting the message for delivery. Only sendmail delivering the message. I included 1 header <p>-- ---- <br>Jun 25 17:18:05 mail sendmail[2397]: h5PLI2C02352: to=<luser@(protected)>, delay=00:00:03, xdelay=00:00:01, mailer=local, pri=141498, dsn=2.0.0, stat=Sent <p>Jun 25 16:51:54 mail sendmail[15546]: h5PKpoC15537: to=<luser@(protected)>, delay=00:00:04, xdelay=00:00:01, mailer=local, pri=141498, dsn=2.0.0, stat=Sent <p>Return-Path: <taylorwright8@(protected)> <br>Received: from MNELSON_LT (hv.domain.com [10.10.50.25]) <br> by mail.domain.com (8.11.6/8.11 .6) with ESMTP id h5PKpoC15537 <br> for <luser@(protected)>; Wed, 25 Jun 2003 16:51:50 -0400 <br>Message-Id: <200306252051.h5PKpoC15537@(protected)> <br>From: <taylorwright8@(protected)> <br>To: <luser@(protected)> <br>Subject: Re: Movie <br>Date: Wed, 25 Jun 2003 16:51:50 --0400 <br>Importance: Normal <br>X-Mailer: Microsoft Outlook Express 6.00.2600.0000 <br>X-MSMail-Priority: Normal <br>X-Priority: 3 (Normal) <br>MIME-Version: 1.0 <br>Content-Type: multipart/mixed; <br> boundary="CSmtpMsgPart123X456 _000_009B6ABD" <p>Jun 25 16:44:30 mail sendmail[9640]: h5PKiOC09573: to=<luser@(protected)>, delay=00:00:04, xdelay=00:00:02, mailer=local, pri=141498, dsn=2.0.0, stat=Sent <p>I tried grep the log file for the smtp id's in all instances. I sent mail from yahoo, my client, pine on the mail server and a machine that lived on the same subnet. All have two entries in the log file. Has anyone else seen the single entry in their logs? I also grep'ed -20 and looked at the lines nearby. The 10.10.50.25 is the firewall and shows if nothing else they came from the outside. <p>Thanks, <br>Gordon Bowersox</html>
|
|