M
masterkain
Guest
hi,
today one of my servers got hit hard, probably by an automatic worm that send tons of emails to yahoo.com users.
with the help of netstat I was able to track down the offender: 83.225.117.60 but the worst thing is that this must be an authenticated user since we do not relay (of course).
now, I'm not able to know who is he, and which email has, since qmail logs are pretty orrible and doesn't show any info.
I've tried searching maillogs for this ip, maybe to catch a login, but nothing.
is there a way to know who is this user and how damn to enable source ip address in qmail logs without recompiling and patching from source?
thanks.
today one of my servers got hit hard, probably by an automatic worm that send tons of emails to yahoo.com users.
with the help of netstat I was able to track down the offender: 83.225.117.60 but the worst thing is that this must be an authenticated user since we do not relay (of course).
now, I'm not able to know who is he, and which email has, since qmail logs are pretty orrible and doesn't show any info.
I've tried searching maillogs for this ip, maybe to catch a login, but nothing.
is there a way to know who is this user and how damn to enable source ip address in qmail logs without recompiling and patching from source?
thanks.