tankistua, скажи плз, по каким критериям можно найти то, откуда пришло мыло? я пытался делать поиск назад по конструкциям вида "1KWUA0-0006Xj-7z" и иже с ними - ничего указывающего на ip в момент появления таких конструкция в логе не нашёл. пытался искать e-mail-адреса, которые фигурируют в строках с конструкциями "C="250 EAA27370 Message accepted for delivery" - не нашёл... подскажи плз, ничего другого на ум не приходит, может я очевидную вещь упускаю из-за отсутствия опыта... (
сделал "/etc/init.d/exim4 force-stop", убедился что в gnome-system-monitor не висит ни одного exim4, "/etc/init.d/exim4 start". сорри за большой размер, но иначе боюсь, что уберу что-нить нужное.
---
[more]2008-08-28 23:50:45 [28427] exim 4.69 daemon started: pid=28427, -q30m, listening for SMTP on [192.168.1.99]:25
2008-08-28 23:50:45 [28429] Start queue run: pid=28429
2008-08-28 23:50:46 [28441] 1KYiXT-0003EC-Nc SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 421 Message from (84.52.116.106) temporarily deferred - 4.16.50. Please refer to
http://help.yahoo.com/help/us/mail/defer/defer-06.html 2008-08-28 23:50:47 [28441] 1KYiXT-0003EC-Nc SMTP error from remote mail server after initial connection: host mx2.mail.tw.yahoo.com [203.188.197.10]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-28 23:50:47 [28440] 1KYiXT-0003EC-Nc == muniu@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx2.mail.tw.yahoo.com [203.188.197.10]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-28 23:50:47 [28443] 1KYi1J-0000xW-Ir Message is frozen
2008-08-28 23:50:50 [28444] 1KXtIk-0002c1-TP ** aa.lu@gmail.com F=<> P=<> R=dnslookup T=remote_smtp: SMTP error from remote mail server after RCPT TO:<aa.lu@gmail.com>: host gmail-smtp-in.l.google.com [209.85.129.27]: 550-5.1.1 The email account that you tried to reach does not exist. Please\n550-5.1.1 try double-checking the recipient's email address for typos\n550-5.1.1 or unnecessary spaces. Learn more at\n550 5.1.1
http://mail.google.com/support/bin/answer.py?answer=6596 22si1139188fkr.4
2008-08-28 23:50:50 [28444] 1KXtIk-0002c1-TP aa.lu@gmail.com: error ignored
2008-08-28 23:50:51 [28444] 1KXtIk-0002c1-TP Completed QT=2d12h1m33s
2008-08-28 23:54:00 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.133]:25 Connection timed out
2008-08-28 23:56:10 [28427] SMTP connection from [189.47.159.124]:58258 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-28 23:56:12 [28486] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:58258 I=[192.168.1.99]:25 F=<mzlos@ur.sk> rejected RCPT <finance@nwlt.ru>: Unrouteable address
2008-08-28 23:56:13 [28486] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:58258 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <mzlos@ur.sk>
2008-08-28 23:56:13 [28486] unexpected disconnection while reading SMTP command from 189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:58258 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-28 23:57:09 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.134]:25 Connection timed out
2008-08-29 00:00:18 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.130]:25 Connection timed out
2008-08-29 00:00:25 [28427] SMTP connection from [189.47.159.124]:59040 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:00:26 [28550] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59040 I=[192.168.1.99]:25 F=<mzlos@ur.sk> rejected RCPT <finance@nwlt.ru>: Unrouteable address
2008-08-29 00:00:28 [28550] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59040 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <mzlos@ur.sk>
2008-08-29 00:00:28 [28550] unexpected disconnection while reading SMTP command from 189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59040 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:01:46 [28427] SMTP connection from [213.231.127.239]:32799 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:01:51 [28579] ident connection to 213.231.127.239 timed out
2008-08-29 00:01:54 [28579] H=213.231.127.239.dyn.user.ono.com (particul-c347f4) [213.231.127.239]:32799 I=[192.168.1.99]:25 F=<teoswjyevsq@frasershipyards.com> rejected RCPT <finance@nwlt.ru>: Unrouteable address
2008-08-29 00:01:55 [28579] H=213.231.127.239.dyn.user.ono.com (particul-c347f4) [213.231.127.239]:32799 I=[192.168.1.99]:25 incomplete transaction (QUIT) from <teoswjyevsq@frasershipyards.com>
2008-08-29 00:01:55 [28579] SMTP connection from 213.231.127.239.dyn.user.ono.com (particul-c347f4) [213.231.127.239]:32799 I=[192.168.1.99]:25 closed by QUIT
2008-08-29 00:02:07 [28427] SMTP connection from [189.47.159.124]:59315 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:02:08 [28601] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59315 I=[192.168.1.99]:25 F=<mzlos@ur.sk> rejected RCPT <finance@nwlt.ru>: Unrouteable address
2008-08-29 00:02:10 [28601] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59315 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <mzlos@ur.sk>
2008-08-29 00:02:10 [28601] unexpected disconnection while reading SMTP command from 189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59315 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:03:16 [28427] SMTP connection from [189.47.159.124]:59546 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:03:17 [28606] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59546 I=[192.168.1.99]:25 F=<mzlos@ur.sk> rejected RCPT <finance@nwlt.ru>: Unrouteable address
2008-08-29 00:03:18 [28606] H=189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59546 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <mzlos@ur.sk>
2008-08-29 00:03:18 [28606] unexpected disconnection while reading SMTP command from 189-47-159-124.dsl.telesp.net.br (mailgate.sovereign-publications.com) [189.47.159.124]:59546 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:03:27 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.135]:25 Connection timed out
2008-08-29 00:06:36 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.129]:25 Connection timed out
2008-08-29 00:09:45 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.181]:25 Connection timed out
2008-08-29 00:12:54 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.132]:25 Connection timed out
2008-08-29 00:16:03 [28449] 1KWUA0-0006Xj-7z msa-mx5.hinet.net [168.95.6.131]:25 Connection timed out
2008-08-29 00:19:12 [28449] 1KWUA0-0006Xj-7z msa-mx6.hinet.net [168.95.6.138]:25 Connection timed out
2008-08-29 00:19:48 [28427] SMTP connection from [98.141.74.167]:3582 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:19:50 [28760] H=dynamic-98-141-74-167.dsl.cavtel.net (T4S2G2.cavtel.net) [98.141.74.167]:3582 I=[192.168.1.99]:25 F=<dfgrgcoyivsg@boddy-ryerson.com> rejected RCPT <glavbux@nwlt.ru>: Unrouteable address
2008-08-29 00:19:51 [28760] H=dynamic-98-141-74-167.dsl.cavtel.net (T4S2G2.cavtel.net) [98.141.74.167]:3582 I=[192.168.1.99]:25 incomplete transaction (QUIT) from <dfgrgcoyivsg@boddy-ryerson.com>
2008-08-29 00:19:51 [28760] SMTP connection from dynamic-98-141-74-167.dsl.cavtel.net (T4S2G2.cavtel.net) [98.141.74.167]:3582 I=[192.168.1.99]:25 closed by QUIT
2008-08-29 00:20:45 [28765] Start queue run: pid=28765
2008-08-29 00:20:46 [28767] 1KYiXT-0003EC-Nc SMTP error from remote mail server after initial connection: host mx2.mail.tw.yahoo.com [203.188.197.10]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:20:47 [28767] 1KYiXT-0003EC-Nc SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:20:47 [28766] 1KYiXT-0003EC-Nc == muniu@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:20:52 [28770] 1KYk0O-0000fH-65 => ab-ko@umail.hinet.net F=<> P=<> R=dnslookup T=remote_smtp S=3591 H=umaila.hinet.net [168.95.5.98]:25 C="250 EAA27370 Message accepted for delivery" QT=4h15m DT=4s
2008-08-29 00:20:52 [28770] 1KYk0O-0000fH-65 Completed QT=4h15m
2008-08-29 00:20:53 [28778] 1KYnVl-0007If-NZ => cj-pc@umail.hinet.net F=<> P=<> R=dnslookup T=remote_smtp S=2408 H=umaila.hinet.net [168.95.5.98]:25* C="250 EAA27466 Message accepted for delivery" QT=30m24s DT=1s
2008-08-29 00:20:53 [28778] 1KYnVl-0007If-NZ Completed QT=30m24s
2008-08-29 00:20:54 [28783] 1KReI3-00080t-CB == carl-ku@umail.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<kvwucjqiqktaymeaz@osh3.osha.gov> SIZE=2369: host umaila.hinet.net [168.95.5.98]: 451 <kvwucjqiqktaymeaz@osh3.osha.gov>... Sender domain must exist
2008-08-29 00:20:55 [28787] 1KReI3-00080t-CB ms37a.hinet.net [168.95.5.37]:25 Connection refused
2008-08-29 00:20:55 [28783] 1KReI3-00080t-CB == choumili@ms37.hinet.net R=dnslookup T=remote_smtp defer (111): Connection refused
2008-08-29 00:21:04 [28788] 1KReI3-00080t-CB Remote host ms13a.hinet.net [168.95.5.13] closed connection in response to initial connection
2008-08-29 00:21:04 [28783] 1KReI3-00080t-CB == dougkelly@ms13.hinet.net R=dnslookup T=remote_smtp defer (-18): Remote host ms13a.hinet.net [168.95.5.13] closed connection in response to initial connection
2008-08-29 00:21:04 [28783] 1KReI3-00080t-CB ** dougkelly@ms13.hinet.net: retry timeout exceeded
2008-08-29 00:21:04 [28783] 1KReI3-00080t-CB ** choumili@ms37.hinet.net: retry timeout exceeded
2008-08-29 00:21:04 [28793] 1KYnzM-0007UP-M6 <= <> R=1KReI3-00080t-CB U=Debian-exim P=local S=2241 from <> for kvwucjqiqktaymeaz@osh3.osha.gov
2008-08-29 00:21:04 [28794] 1KYnzM-0007UP-M6 ** kvwucjqiqktaymeaz@osh3.osha.gov F=<>: Unrouteable address
2008-08-29 00:21:04 [28794] 1KYnzM-0007UP-M6 Frozen (delivery error message)
2008-08-29 00:21:04 [28795] 1KYnzM-0007UR-S9 <= <> R=1KReI3-00080t-CB U=Debian-exim P=local S=1540 from <> for kvwucjqiqktaymeaz@osh3.osha.gov
2008-08-29 00:21:05 [28796] 1KYnzM-0007UR-S9 ** kvwucjqiqktaymeaz@osh3.osha.gov F=<>: Unrouteable address
2008-08-29 00:21:05 [28796] 1KYnzM-0007UR-S9 Frozen (delivery error message)
2008-08-29 00:21:05 [28797] 1KYUgK-0004xM-TI Message is frozen
2008-08-29 00:21:08 [28798] 1KVsxx-00036D-HS => ks-alan@umail.hinet.net F=<> P=<> R=dnslookup T=remote_smtp S=2690 H=umaila.hinet.net [168.95.5.98]:25 C="250 EAA18235 Message accepted for delivery" QT=1w1d1h17m35s DT=3s
2008-08-29 00:21:08 [28798] 1KVsxx-00036D-HS Completed QT=1w1d1h17m35s
2008-08-29 00:21:10 [28803] 1KVxbs-0007yN-GZ => angel-ken@umail.hinet.net F=<> P=<> R=dnslookup T=remote_smtp S=8616 H=umaila.hinet.net [168.95.5.98]:25* C="250 EAA18350 Message accepted for delivery" QT=1w20h20m6s DT=2s
2008-08-29 00:21:10 [28803] 1KVxbs-0007yN-GZ Completed QT=1w20h20m6s
2008-08-29 00:21:10 [28808] 1KRqzP-0002Fq-5S == pclvs@ms7.hinet.net routing defer (-51): reusing SMTP connection skips previous routing defer
2008-08-29 00:21:10 [28808] 1KRqzP-0002Fq-5S == odille@ms1.hinet.net routing defer (-51): reusing SMTP connection skips previous routing defer
2008-08-29 00:21:10 [28808] 1KRqzP-0002Fq-5S == or@ms7.hinet.net routing defer (-51): reusing SMTP connection skips previous routing defer
2008-08-29 00:21:21 [28808] 1KRqzP-0002Fq-5S == pearl-wayne@umail.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host umaila.hinet.net [168.95.5.98]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:21:30 [28813] 1KRqzP-0002Fq-5S Remote host ms65a.hinet.net [168.95.5.65] closed connection in response to initial connection
2008-08-29 00:21:30 [28808] 1KRqzP-0002Fq-5S == oics@ms65.hinet.net R=dnslookup T=remote_smtp defer (-18): Remote host ms65a.hinet.net [168.95.5.65] closed connection in response to initial connection
2008-08-29 00:21:46 [28808] 1KRqzP-0002Fq-5S == pcsjlgwa@ms45.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host ms45a.hinet.net [168.95.5.45]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:22:21 [28449] 1KWUA0-0006Xj-7z msa-mx6.hinet.net [168.95.6.140]:25 Connection timed out
2008-08-29 00:22:24 [28808] 1KRqzP-0002Fq-5S == phoenixm@ms55.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host ms55a.hinet.net [168.95.5.55]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:22:34 [28427] SMTP connection from [200.178.193.226]:53128 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:22:39 [28842] no host name found for IP address 200.178.193.226
2008-08-29 00:22:40 [28842] H=(mx.rci.rutgers.edu) [200.178.193.226]:53128 I=[192.168.1.99]:25 F=<michael@thebluff.net> rejected RCPT <hr@nwlt.ru>: Unrouteable address
2008-08-29 00:22:40 [28842] H=(mx.rci.rutgers.edu) [200.178.193.226]:53128 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <michael@thebluff.net>
2008-08-29 00:22:40 [28842] unexpected disconnection while reading SMTP command from (mx.rci.rutgers.edu) [200.178.193.226]:53128 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:22:41 [28808] 1KRqzP-0002Fq-5S == o0302@ms27.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host ms27a.hinet.net [168.95.5.27]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:24:22 [28427] SMTP connection from [41.249.64.95]:55735 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:24:27 [28850] ident connection to 41.249.64.95 timed out
2008-08-29 00:24:32 [28850] no host name found for IP address 41.249.64.95
2008-08-29 00:24:32 [28850] H=(cm1a.hinet.net) [41.249.64.95]:55735 I=[192.168.1.99]:25 F=<www.info@airdatec.com> rejected RCPT <direktor@nwlt.ru>: Unrouteable address
2008-08-29 00:24:32 [28850] H=(cm1a.hinet.net) [41.249.64.95]:55735 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <www.info@airdatec.com>
2008-08-29 00:24:32 [28850] unexpected disconnection while reading SMTP command from (cm1a.hinet.net) [41.249.64.95]:55735 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:24:38 [28427] SMTP connection from [190.135.54.121]:58023 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:24:43 [28857] ident connection to 190.135.54.121 timed out
2008-08-29 00:24:44 [28427] SMTP connection from [200.178.193.226]:53840 I=[192.168.1.99]:25 (TCP/IP connection count = 2)
2008-08-29 00:24:45 [28857] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58023 I=[192.168.1.99]:25 F=<rimio2001@fw.com> rejected RCPT <dir@nwlt.ru>: Unrouteable address
2008-08-29 00:24:45 [28857] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58023 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <rimio2001@fw.com>
2008-08-29 00:24:45 [28857] unexpected disconnection while reading SMTP command from r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58023 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:24:49 [28859] no host name found for IP address 200.178.193.226
2008-08-29 00:24:50 [28859] H=(mx.rci.rutgers.edu) [200.178.193.226]:53840 I=[192.168.1.99]:25 F=<michael@thebluff.net> rejected RCPT <hr@nwlt.ru>: Unrouteable address
2008-08-29 00:24:50 [28859] H=(mx.rci.rutgers.edu) [200.178.193.226]:53840 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <michael@thebluff.net>
2008-08-29 00:24:50 [28859] unexpected disconnection while reading SMTP command from (mx.rci.rutgers.edu) [200.178.193.226]:53840 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:25:30 [28449] 1KWUA0-0006Xj-7z msa-mx6.hinet.net [168.95.6.141]:25 Connection timed out
2008-08-29 00:25:50 [28846] 1KRqzP-0002Fq-5S ms11a.hinet.net [168.95.5.11]:25 Connection timed out
2008-08-29 00:25:50 [28808] 1KRqzP-0002Fq-5S == olympia@ms11.hinet.net R=dnslookup T=remote_smtp defer (110): Connection timed out
2008-08-29 00:25:53 [28868] 1KRqzP-0002Fq-5S SMTP error from remote mail server after end of data: host mx2.mail.tw.yahoo.com [203.188.197.10]: 451 Message temporarily deferred - [90]
2008-08-29 00:25:54 [28427] SMTP connection from [200.178.193.226]:54243 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:25:54 [28868] 1KRqzP-0002Fq-5S SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == ovia77@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == ogogov6@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == onen92002@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == pg22223@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == oedipus0514@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == o0_fat_0o@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == oetd@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == peggy530217@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == papaxxxx1122@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == peichin3@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:54 [28808] 1KRqzP-0002Fq-5S == pade1234@yahoo.com.tw R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx1.mail.tw.yahoo.com [203.188.197.9]: 453 Mail from 84.52.116.106 not allowed - [90]
2008-08-29 00:25:59 [28870] no host name found for IP address 200.178.193.226
2008-08-29 00:26:00 [28870] H=(mx.rci.rutgers.edu) [200.178.193.226]:54243 I=[192.168.1.99]:25 F=<michael@thebluff.net> rejected RCPT <hr@nwlt.ru>: Unrouteable address
2008-08-29 00:26:00 [28870] H=(mx.rci.rutgers.edu) [200.178.193.226]:54243 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <michael@thebluff.net>
2008-08-29 00:26:00 [28870] unexpected disconnection while reading SMTP command from (mx.rci.rutgers.edu) [200.178.193.226]:54243 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:26:12 [28808] 1KRqzP-0002Fq-5S == pennyrich@ms12.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host ms12a.hinet.net [168.95.5.12]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:26:12 [28875] 1KRqzP-0002Fq-5S ms59a.hinet.net [168.95.5.59]:25 Connection refused
2008-08-29 00:26:12 [28808] 1KRqzP-0002Fq-5S == panasonic@ms59.hinet.net R=dnslookup T=remote_smtp defer (111): Connection refused
2008-08-29 00:26:28 [28427] SMTP connection from [41.249.64.95]:56325 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:26:28 [28808] 1KRqzP-0002Fq-5S == painful@ms54.hinet.net R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<henrygeorge@ms50.hinet.net> SIZE=8230: host ms54a.hinet.net [168.95.5.54]: 451 <henrygeorge@ms50.hinet.net>... Sender domain must exist
2008-08-29 00:26:33 [28882] ident connection to 41.249.64.95 timed out
2008-08-29 00:26:35 [28427] SMTP connection from [190.135.54.121]:58547 I=[192.168.1.99]:25 (TCP/IP connection count = 2)
2008-08-29 00:26:38 [28882] no host name found for IP address 41.249.64.95
2008-08-29 00:26:38 [28882] H=(cm1a.hinet.net) [41.249.64.95]:56325 I=[192.168.1.99]:25 F=<www.info@airdatec.com> rejected RCPT <direktor@nwlt.ru>: Unrouteable address
2008-08-29 00:26:38 [28882] H=(cm1a.hinet.net) [41.249.64.95]:56325 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <www.info@airdatec.com>
2008-08-29 00:26:38 [28882] unexpected disconnection while reading SMTP command from (cm1a.hinet.net) [41.249.64.95]:56325 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:26:40 [28888] ident connection to 190.135.54.121 timed out
2008-08-29 00:26:41 [28888] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58547 I=[192.168.1.99]:25 F=<rimio2001@fw.com> rejected RCPT <dir@nwlt.ru>: Unrouteable address
2008-08-29 00:26:41 [28888] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58547 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <rimio2001@fw.com>
2008-08-29 00:26:41 [28888] unexpected disconnection while reading SMTP command from r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58547 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:26:55 [28427] SMTP connection from [200.178.193.226]:54640 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:27:01 [28895] no host name found for IP address 200.178.193.226
2008-08-29 00:27:01 [28895] H=(mx.rci.rutgers.edu) [200.178.193.226]:54640 I=[192.168.1.99]:25 F=<michael@thebluff.net> rejected RCPT <hr@nwlt.ru>: Unrouteable address
2008-08-29 00:27:02 [28895] H=(mx.rci.rutgers.edu) [200.178.193.226]:54640 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <michael@thebluff.net>
2008-08-29 00:27:02 [28895] unexpected disconnection while reading SMTP command from (mx.rci.rutgers.edu) [200.178.193.226]:54640 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:28:00 [28427] SMTP connection from [41.249.64.95]:56773 I=[192.168.1.99]:25 (TCP/IP connection count = 1)
2008-08-29 00:28:00 [28427] SMTP connection from [190.135.54.121]:58914 I=[192.168.1.99]:25 (TCP/IP connection count = 2)
2008-08-29 00:28:05 [28913] ident connection to 41.249.64.95 timed out
2008-08-29 00:28:05 [28914] ident connection to 190.135.54.121 timed out
2008-08-29 00:28:06 [28914] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58914 I=[192.168.1.99]:25 F=<rimio2001@fw.com> rejected RCPT <dir@nwlt.ru>: Unrouteable address
2008-08-29 00:28:06 [28914] H=r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58914 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <rimio2001@fw.com>
2008-08-29 00:28:06 [28914] unexpected disconnection while reading SMTP command from r190-135-54-121.dialup.adsl.anteldata.net.uy (smtp.hw.com) [190.135.54.121]:58914 I=[192.168.1.99]:25 (error: Connection reset by peer)
2008-08-29 00:28:10 [28913] no host name found for IP address 41.249.64.95
2008-08-29 00:28:10 [28913] H=(cm1a.hinet.net) [41.249.64.95]:56773 I=[192.168.1.99]:25 F=<www.info@airdatec.com> rejected RCPT <direktor@nwlt.ru>: Unrouteable address
2008-08-29 00:28:10 [28913] H=(cm1a.hinet.net) [41.249.64.95]:56773 I=[192.168.1.99]:25 incomplete transaction (connection lost) from <www.info@airdatec.com>
2008-08-29 00:28:10 [28913] unexpected disconnection while reading SMTP command from (cm1a.hinet.net) [41.249.64.95]:56773 I=[192.168.1.99]:25 (error: Connection reset by peer)[/more]
---
кстати, в логах частенько попадаются сообщения вида:
"2008-08-28 20:05:26 [2484] 1KS0fw-00021u-6A Spool file is locked (another process is handling this message)"
это меня почему-то настораживает...
полазил в менеджере пакетов и в секции email удалил какой-то "bsd" user agent, только потом допёрло, что он тут ни при чём... )
мож я словил руткит?..
приведу опять же часть конфига:
[more].ifndef MAIN_LOCAL_INTERFACES
MAIN_LOCAL_INTERFACES=192.168.1.99
.endif
.ifndef MAIN_PACKAGE_VERSION
MAIN_PACKAGE_VERSION=4.69-6
.endif
.ifndef MAIN_LOCAL_DOMAINS
MAIN_LOCAL_DOMAINS=@:localhost:nwlt.ru
.endif
.ifndef MAIN_RELAY_TO_DOMAINS
MAIN_RELAY_TO_DOMAINS=nwlt.ru
.endif
.ifndef ETC_MAILNAME
ETC_MAILNAME=nwlt.ru
.endif
.ifndef LOCAL_DELIVERY
LOCAL_DELIVERY=mail_spool
.endif
.ifndef MAIN_RELAY_NETS
MAIN_RELAY_NETS=127.0.0.1 : 192.168.1.0/24 : 84.52.116.106 : 127.0.0.1 : ::::1
.endif
.ifndef DCreadhost
DCreadhost=empty
.endif
.ifndef DCsmarthost
DCsmarthost=empty
.endif
.ifndef DC_eximconfig_configtype
DC_eximconfig_configtype=internet
.endif
.ifndef DCconfig_internet
DCconfig_internet=1
.endif
##############################################
domainlist local_domains = MAIN_LOCAL_DOMAINS
domainlist relay_to_domains = 'nwlt.ru'
hostlist relay_from_hosts = MAIN_RELAY_NETS
.ifndef MAIN_PRIMARY_HOSTNAME_AS_QUALIFY_DOMAIN
.ifndef MAIN_QUALIFY_DOMAIN
qualify_domain = ETC_MAILNAME
.else
qualify_domain = MAIN_QUALIFY_DOMAIN
.endif
.endif
.ifdef MAIN_LOCAL_INTERFACES
local_interfaces = MAIN_LOCAL_INTERFACES
.endif
.ifndef LOCAL_DELIVERY
LOCAL_DELIVERY=mail_spool
.endif
gecos_pattern = ^([^,:]*)
gecos_name = $1
.ifndef CHECK_RCPT_LOCAL_LOCALPARTS
CHECK_RCPT_LOCAL_LOCALPARTS = ^[.] : ^.*[@%!/|`#&?]
.endif
.ifndef CHECK_RCPT_REMOTE_LOCALPARTS
CHECK_RCPT_REMOTE_LOCALPARTS = ^[./|] : ^.*[@%!`#&?] : ^.*/\\.\\./
.endif
.ifndef MAIN_LOG_SELECTOR
MAIN_LOG_SELECTOR = +tls_peerdn
.endif
.ifndef MAIN_ACL_CHECK_MAIL
MAIN_ACL_CHECK_MAIL = acl_check_mail
.endif
acl_smtp_mail = MAIN_ACL_CHECK_MAIL
.ifndef MAIN_ACL_CHECK_RCPT
MAIN_ACL_CHECK_RCPT = acl_check_rcpt
.endif
acl_smtp_rcpt = MAIN_ACL_CHECK_RCPT
.ifndef MAIN_ACL_CHECK_DATA
MAIN_ACL_CHECK_DATA = acl_check_data
.endif
acl_smtp_data = MAIN_ACL_CHECK_DATA
.ifdef MESSAGE_SIZE_LIMIT
message_size_limit = MESSAGE_SIZE_LIMIT
.endif
.ifdef MAIN_ALLOW_DOMAIN_LITERALS
allow_domain_literals
.endif
.ifndef DC_minimaldns
.ifndef MAIN_HOST_LOOKUP
MAIN_HOST_LOOKUP = *
.endif
host_lookup = MAIN_HOST_LOOKUP
.endif
.ifdef MAIN_HARDCODE_PRIMARY_HOSTNAME
primary_hostname = MAIN_HARDCODE_PRIMARY_HOSTNAME
.endif
.ifdef MAIN_SMTP_ACCEPT_MAX_NOMAIL_HOSTS
smtp_accept_max_nonmail_hosts = MAIN_SMTP_ACCEPT_MAX_NOMAIL_HOSTS
.endif
.ifndef MAIN_FORCE_SENDER
local_from_check = false
local_sender_retain = true
untrusted_set_sender = *
.endif
.ifndef MAIN_IGNORE_BOUNCE_ERRORS_AFTER
MAIN_IGNORE_BOUNCE_ERRORS_AFTER = 2d
.endif
ignore_bounce_errors_after = MAIN_IGNORE_BOUNCE_ERRORS_AFTER
.ifndef MAIN_TIMEOUT_FROZEN_AFTER
MAIN_TIMEOUT_FROZEN_AFTER = 7d
.endif
timeout_frozen_after = MAIN_TIMEOUT_FROZEN_AFTER
.ifndef MAIN_FREEZE_TELL
MAIN_FREEZE_TELL = postmaster
.endif
freeze_tell = MAIN_FREEZE_TELL
.ifndef SPOOLDIR
SPOOLDIR = /var/spool/exim4
.endif
spool_directory = SPOOLDIR
.ifndef MAIN_TRUSTED_USERS
MAIN_TRUSTED_USERS = uucp
.endif
trusted_users = MAIN_TRUSTED_USERS
.ifdef MAIN_TRUSTED_GROUPS
trusted_groups = MAIN_TRUSTED_GROUPS
.endif
.ifdef MAIN_TLS_ENABLE
.ifndef MAIN_TLS_ADVERTISE_HOSTS
MAIN_TLS_ADVERTISE_HOSTS = *
.endif
.ifdef MAIN_TLS_CERTKEY
tls_certificate = MAIN_TLS_CERTKEY
.else
.ifndef MAIN_TLS_CERTIFICATE
MAIN_TLS_CERTIFICATE = /etc/ssl/certs/exim.pem
.endif
tls_certificate = MAIN_TLS_CERTIFICATE
.ifndef MAIN_TLS_PRIVATEKEY
MAIN_TLS_PRIVATEKEY = /etc/ssl/private/exim.pem
.endif
tls_privatekey = MAIN_TLS_PRIVATEKEY
.endif
.ifndef MAIN_TLS_VERIFY_CERTIFICATES
MAIN_TLS_VERIFY_CERTIFICATES = ${if exists{/etc/ssl/certs/ca-certificates.crt}\
{/etc/ssl/certs/ca-certificates.crt}\
{/dev/null}}
.endif
tls_verify_certificates = MAIN_TLS_VERIFY_CERTIFICATES
.ifdef MAIN_TLS_VERIFY_HOSTS
tls_verify_hosts = MAIN_TLS_VERIFY_HOSTS
.endif
.ifndef MAIN_TLS_TRY_VERIFY_HOSTS
MAIN_TLS_TRY_VERIFY_HOSTS = *
.endif
tls_try_verify_hosts = MAIN_TLS_TRY_VERIFY_HOSTS
[/more]
тут в MAIN_RELAY_NETS значение 84.52.116.106 - это собственно nwlt.ru, мой домен; добавил при попытке решить какую-то мелочь с нехождением почты, вроде помогло, сейчас думаю, мож убрать стоит?
строка вида:
---
MAIN_RELAY_NETS=127.0.0.1 : 192.168.1.0/24 : 84.52.116.106 : 127.0.0.1 : ::::1
---
не может являться причиной приёма почты от левых хостов?
так же есть конструкция:
---
local_from_check = false
local_sender_retain = true
untrusted_set_sender = *
---
возможно тоже небезопасная?.. описания параметров почитал, ничего подозрительного не нашёл.
крепнет ощущение, что я со своим почтовым сервером замахнулся на слишком многое сразу... так впадлу сносить exim и ставить заново......