Spammers

As some of you might have noticed, we had some downtime yesterday. This is due to some gentlemanly folk who decided to use the server to send out spam. I thought I had configured the mail server well, but apparently some things can go wrong. For example, the fact that the root account doesn't have a password set doesn't mean that people can't log in. Apparently my SASL service thought that by "no password" I meant "log people in with whatever", and allowed people to log in anyway.

If you are running postfix with SASL, be aware that "no password" (or blank password) means that people can still log in by using the username, so if root has a blank password nobody will be able to log in through ssh, the console, or most other ways, but with SASL they can just use root/root and they're golden.

I'm pretty sure this is a security hole, but I've just locked the account now and hopefully everything is fine. I hope you haven't been greatly inconvenienced.

πολύ ενδιαφέρον site

γειά,

εδώ νίκος βασιλάκος ψηφιακή ελλάδα.

www.youtube.com/psifiakiellada
www.eexi.gr
www.internetnow.gr
www.nikosvasilakos.gr
ndigital.in.gr

Κάνεις ενδιαφέροντα πράγματα. Όταν μιλάω σε σχολεία στέλνω τα παιδιά στο site σου για να μάθουν python.

Στείλε mail επικοινωνίας, ή καλύτερα πρόσθεσε με σε facebook ή hi5.

Χάρηκα, γειά.

Submitted by vasilakos on Sat, 06/12/2008 - 15:30.
spammers

Don't worry... we don't blame you... :P

Submitted by Chefarov on Sun, 07/12/2008 - 16:13.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Ads