T
theladyboo
Guest
I first noticed when I couldn't ftp because the system was running out of memory. So I went in with ssh and poked around.
If I start qmail with plesk it dies. If I start it from the xinetd starup file from the command line it works fine except I don't get any mail.
I checked the apache logs for any scripts and nothing was unusual. I found a lot of strange things where people were trying, but getting 404 errors.
I tried turning off all the web servers and then turning on qmail through plesk, but the hits are still there according to netstat and the server is still brought down to a crawl. This was after I killed all the qmail processes and made sure it wasn't running.
I wanted to update qmail, but then in the process i had to go hunt down a patch tool because the server didn't have one and then I thought about it and wondered if please would even be compatible with the upgrade so I thought I'd ask here first.
An example would be:
65.116.31.17 - - [07/Apr/2007:11:28:19 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
65.116.31.17 - - [07/Apr/2007:11:28:20 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
24.172.195.8 - - [07/Apr/2007:11:50:59 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
24.172.195.8 - - [07/Apr/2007:11:51:00 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
207.151.97.218 - - [07/Apr/2007:11:52:55 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
207.151.97.218 - - [07/Apr/2007:11:52:56 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
206.165.199.101 - - [07/Apr/2007:12:07:37 -0500] "GET / HTTP/1.0" 200 14480 "-" "-"
206.165.199.101 - - [07/Apr/2007:12:07:54 -0500] "GET / HTTP/1.0" 200 14480 "-" "-"
and then I'll see seomthing like this which makes no sense because
59.10.167.48 - - [16/Sep/2006:14:28:42 -0700] "GET / HTTP/1.0" 200 4854 "http://www.openfos.com/supply/ALLIED-STEEL-CONSTRUCTION-CO-L-34270/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
Netstat:
netstat had a ton of processes similar to
tcp 0 1 ip-xxx-xx-xxx-xxx.ip.:33430 mx1.csbc.com:auth SYN_SENT
tcp 0 0 ip-xxx-xx-xxx-xxx.ip.s:smtp mx1.silcon.com:51502 ESTABLISHED
tcp 0 0 ip-xxx-xx-xxx-xxx.ip.s:smtp kos.kasamba.com:13020 TIME_WAIT
my qmail pids are similar to this (and there are a ton of them)
3778 ? Ss 0:00 /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
7395 ? Ss 0:00 tcp-env /var/qmail/bin/relaylock /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
422 ? Ss 0:00 /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
7177 ? S 0:00 qmail-send
7179 ? S 0:00 splogger qmail
7180 ? Z 0:00 [qmail-lspawn] <defunct>
7182 ? Z 0:00 [qmail-rspawn] <defunct>
7186 ? Z 0:00 [qmail-clean] <defunct>
(the above happened when I renamed the bin directory to stop)
18251 ? Ss 0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
18431 ? S 0:00 plugins/chkrcptto
I don't see any unusual processes active
If I start qmail using /etc/init.d/qmail start then the processes do not startup yet mail doesn't work.
If I start qmail using /etc/init.d/qmail start then the problem does not occur.
I've looked for php scripts in my apache error and access logs and nothing irregular has appeared.
When I turned on qmail through plesk I would get these in /usr/local/psa/var/log/maillog
Apr 7 11:40:36 ip-216-69-172-172 qmail: 1175964036.353178 alert: unable to opendir todo/0, sleeping...
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 71.16.41.208:18242 (mailgw.channelblade.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 69.10.230.29:57883 (webmail6.mhsmail.onx.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 66.148.195.190:1364 (66.148.195.190.nw.nuvox.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 141.20.1.74:53743 (suncom4.cms.hu-berlin.de)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 67.102.68.194:7980 (h-67-102-68-194.snfccasy.covad.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 86.64.52.71:4914 (71.52.64-86.rev.gaoland.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 83.206.128.2:41465 (ns3.cnce.caisse-epargne.fr)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 66.147.88.49:49436 (nsc66.147.88-49.newsouth.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 63.139.215.138:33132 (mail.dnlukems.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 85.33.97.170:12055 (host170-97-static.33-85-b.business.telecomitalia.it)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 64.65.207.202:29635 (rochester.wardsupply.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 81.223.16.242:18879 (mail.ic-vienna.at)
Apr 7 11:41:00 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 58.185.11.132:7781 (not defined)
Apr 7 11:41:00 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 192.116.223.134:6172 (owa.eyron.com)
The dates on the qmail files are normal, although that can be changed.
There were some log files missing in the system log.
Any ideas or information I've missed to tell you
My other option is reprovisioning the server and that will be a nightmare because I have a lot going on and ftp isn't the most reliable transfer for large data. If I miss something I'll be screwed.
Thanks for your help.
Rebecca
If I start qmail with plesk it dies. If I start it from the xinetd starup file from the command line it works fine except I don't get any mail.
I checked the apache logs for any scripts and nothing was unusual. I found a lot of strange things where people were trying, but getting 404 errors.
I tried turning off all the web servers and then turning on qmail through plesk, but the hits are still there according to netstat and the server is still brought down to a crawl. This was after I killed all the qmail processes and made sure it wasn't running.
I wanted to update qmail, but then in the process i had to go hunt down a patch tool because the server didn't have one and then I thought about it and wondered if please would even be compatible with the upgrade so I thought I'd ask here first.
An example would be:
65.116.31.17 - - [07/Apr/2007:11:28:19 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
65.116.31.17 - - [07/Apr/2007:11:28:20 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
24.172.195.8 - - [07/Apr/2007:11:50:59 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
24.172.195.8 - - [07/Apr/2007:11:51:00 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
207.151.97.218 - - [07/Apr/2007:11:52:55 -0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 404 12826 "-" "-"
207.151.97.218 - - [07/Apr/2007:11:52:56 -0500] "GET http://www.microsoft.com/ HTTP/1.0" 404 12826 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
206.165.199.101 - - [07/Apr/2007:12:07:37 -0500] "GET / HTTP/1.0" 200 14480 "-" "-"
206.165.199.101 - - [07/Apr/2007:12:07:54 -0500] "GET / HTTP/1.0" 200 14480 "-" "-"
and then I'll see seomthing like this which makes no sense because
59.10.167.48 - - [16/Sep/2006:14:28:42 -0700] "GET / HTTP/1.0" 200 4854 "http://www.openfos.com/supply/ALLIED-STEEL-CONSTRUCTION-CO-L-34270/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
Netstat:
netstat had a ton of processes similar to
tcp 0 1 ip-xxx-xx-xxx-xxx.ip.:33430 mx1.csbc.com:auth SYN_SENT
tcp 0 0 ip-xxx-xx-xxx-xxx.ip.s:smtp mx1.silcon.com:51502 ESTABLISHED
tcp 0 0 ip-xxx-xx-xxx-xxx.ip.s:smtp kos.kasamba.com:13020 TIME_WAIT
my qmail pids are similar to this (and there are a ton of them)
3778 ? Ss 0:00 /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
7395 ? Ss 0:00 tcp-env /var/qmail/bin/relaylock /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
422 ? Ss 0:00 /var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
7177 ? S 0:00 qmail-send
7179 ? S 0:00 splogger qmail
7180 ? Z 0:00 [qmail-lspawn] <defunct>
7182 ? Z 0:00 [qmail-rspawn] <defunct>
7186 ? Z 0:00 [qmail-clean] <defunct>
(the above happened when I renamed the bin directory to stop)
18251 ? Ss 0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
18431 ? S 0:00 plugins/chkrcptto
I don't see any unusual processes active
If I start qmail using /etc/init.d/qmail start then the processes do not startup yet mail doesn't work.
If I start qmail using /etc/init.d/qmail start then the problem does not occur.
I've looked for php scripts in my apache error and access logs and nothing irregular has appeared.
When I turned on qmail through plesk I would get these in /usr/local/psa/var/log/maillog
Apr 7 11:40:36 ip-216-69-172-172 qmail: 1175964036.353178 alert: unable to opendir todo/0, sleeping...
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 71.16.41.208:18242 (mailgw.channelblade.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 69.10.230.29:57883 (webmail6.mhsmail.onx.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 66.148.195.190:1364 (66.148.195.190.nw.nuvox.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 141.20.1.74:53743 (suncom4.cms.hu-berlin.de)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 67.102.68.194:7980 (h-67-102-68-194.snfccasy.covad.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 86.64.52.71:4914 (71.52.64-86.rev.gaoland.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 83.206.128.2:41465 (ns3.cnce.caisse-epargne.fr)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 66.147.88.49:49436 (nsc66.147.88-49.newsouth.net)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 63.139.215.138:33132 (mail.dnlukems.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 85.33.97.170:12055 (host170-97-static.33-85-b.business.telecomitalia.it)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 64.65.207.202:29635 (rochester.wardsupply.com)
Apr 7 11:40:59 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 81.223.16.242:18879 (mail.ic-vienna.at)
Apr 7 11:41:00 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 58.185.11.132:7781 (not defined)
Apr 7 11:41:00 ip-216-69-172-172 relaylock: /var/qmail/bin/relaylock: mail from 192.116.223.134:6172 (owa.eyron.com)
The dates on the qmail files are normal, although that can be changed.
There were some log files missing in the system log.
Any ideas or information I've missed to tell you
My other option is reprovisioning the server and that will be a nightmare because I have a lot going on and ftp isn't the most reliable transfer for large data. If I miss something I'll be screwed.
Thanks for your help.
Rebecca