1. Please take a little time for this simple survey! Thank you for participating!
    Dismiss Notice

Strange qmail processes?

Discussion in 'Plesk for Linux - 8.x and Older' started by rbhaydon, Dec 15, 2004.

  1. rbhaydon

    rbhaydon Guest

    0
     
    Suffering the same problem with outgoing email taking forever, I did a "ps -aux" to show all the running processes. I got the following:

    qmailr 8215 0.0 0.1 3284 948 ? S 14:31 0:00 qmail-remote svolkov.com michael@a-teleport.com ebanner@svol
    qmailr 8403 0.0 0.1 3280 948 ? S 14:33 0:00 qmail-remote lovemail.com misha@kharkov.com tyrannosaurus_re
    qmailr 8677 0.0 0.1 3280 964 ? S 14:37 0:00 qmail-remote sco.com victoria@gala.net md@sco.com
    qmailr 9523 0.0 0.1 3288 940 ? S 14:41 0:00 qmail-remote aport.ru inna@fm.com.ua a_tgor_v@aport.ru
    qmailr 9535 0.0 0.1 3284 936 ? S 14:41 0:00 qmail-remote aport.ru denis@infomania.com.ua planeta_tour@ap
    qmailr 9543 0.0 0.1 3280 932 ? S 14:41 0:00 qmail-remote thgas.dn.ua jura@zeos.net igor@thgas.dn.ua
    qmailr 9561 0.0 0.1 3280 932 ? S 14:41 0:00 qmail-remote format.org.ua valera@torba.com admin@format.org
    qmailr 9586 0.0 0.1 3284 936 ? S 14:42 0:00 qmail-remote bashprom.com elena@torba.com rapoport@bashprom.
    qmailr 9594 0.0 0.1 3284 936 ? S 14:42 0:00 qmail-remote mcbn.ru roma@kharkov.com centr@mcbn.ru
    root 9605 0.0 0.0 1452 452 ? S 14:42 0:00 tcp-env /var/qmail/bin/relaylock /var/qmail/bin/qmail-smtpd
    qmailr 9621 0.0 0.1 3280 928 ? S 14:42 0:00 qmail-remote lnmz.sumy.ua mihail@paco.net natasha@lnmz.sumy.
    qmailr 9622 0.0 0.1 3280 932 ? S 14:42 0:00 qmail-remote omen.ru mihail@paco.net fiere@omen.ru
    qmailr 9623 0.0 0.1 3280 932 ? S 14:42 0:00 qmail-remote chuvashia.ru mihail@paco.net nostalgi@chuvashia
    qmailr 9634 0.2 0.1 3280 928 ? S 14:42 0:00 qmail-remote ite.cv.ua tech@torba.com slavik@ite.cv.ua
    qmailr 9635 0.0 0.1 3284 936 ? S 14:42 0:00 qmail-remote newmail.net eugen@ternopil.net albaross@newmail
    qmailr 9637 0.2 0.1 3288 936 ? S 14:42 0:00 qmail-remote uanet.com.ua eugen@ternopil.net lev@uanet.com.u
    qmailr 9639 0.3 0.1 3280 924 ? S 14:42 0:00 qmail-remote uagunix.gdl.uag.mx eugen@ternopil.net gvillanu@
    qmailr 9643 0.0 0.1 3284 960 ? S 14:42 0:00 qmail-remote zt.ukrtel.net maria@gala.net buh.tv@zt.ukrtel.n
    qmailr 9645 0.0 0.1 3288 928 ? S 14:42 0:00 qmail-remote snf.e-mail.com maria@gala.net glaettli@snf.e-ma

    What on earth are these? I recognize none of these addresses...anyone have any guess as to what is going on?

    Are these spammers? unauthorized relayers?

    Thanks,
    Bruce
     
  2. etan

    etan Guest

    0
     
    someone on your system running a mailing list, doing a mail out ?
     
  3. rbhaydon

    rbhaydon Guest

    0
     
    My Plesk server is an OPEN RELAY!

    I figured out what the problemis - despite having it set otherwise in the control panel, it appears my PLESK server is an open relay....

    QMAIL is letting anyone pass stuff through...that's why I've got all these processes... It's all spam.


    Does anyone have any fixes for this? Urgent!

    Bruce
     
  4. RexAdmin

    RexAdmin Guest

    0
     
    Open relay? Plesk Panel should allow you to re-set this, if it doesn't work you need to do it your self (hope you have administrator skills).

    OTOH, you should check for php scripts (forms, phpNuke exploits), you should harden /tmp directory)

    Good luck.
     
  5. rbhaydon

    rbhaydon Guest

    0
     
    Plesk 7.5.1 fixed it...

    PLESK 7.5.1. fixed all the problems with SMTP Authorization not working.
     
Loading...