#12480 closed Bug/Something is broken (fixed)

mx1 sending spam - using old laneta.apc.org logins

Reported by: https://id.mayfirst.org/jamie Owned by:
Priority: Urgent Component: Tech
Keywords: mx1.mayfirst.org Cc:
Sensitive: no

Description

Since laneta.apc.org has been moved off of mx1 these should all be delete-able.

Change History (4)

comment:1 Changed 23 months ago by https://id.mayfirst.org/jamie

This particular compromise is: gamina@laneta.apc.org

comment:2 Changed 23 months ago by https://id.mayfirst.org/jamie

I just took the following steps to disable sending from any laneta user name:

cd /etc/postfix/vhcs2/
cp sender-access sender-access.pre.lanteta.purge
cat sender-access.pre.lanteta.purge | grep -v @laneta.apc.org > sender-access
postmap sender-access

And here's a check to ensure there are no more messages send from @laneta.apc.org addresses sending email after this change went into affect at 9:00 Mexico City time:

0 mx1:/etc/postfix/vhcs2# grep "sasl_username=.*@laneta.apc.org" /var/log/mail.log |tail
Feb  1 08:58:29 mx1 postfix/smtpd[7091]: 07DA42948D: client=zvh41.mirohost.net[89.184.73.18], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:58:47 mx1 postfix/smtpd[6011]: EF309295D3: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:58:48 mx1 postfix/smtpd[7091]: 3894A295EF: client=zvh41.mirohost.net[89.184.73.18], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:19 mx1 postfix/smtpd[9149]: 9B11929611: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:19 mx1 postfix/smtpd[9150]: 01B9C2961F: client=zvh41.mirohost.net[89.184.73.18], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:26 mx1 postfix/smtpd[9149]: B0F6B294A6: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:34 mx1 postfix/smtpd[9150]: EA701295EA: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:39 mx1 postfix/smtpd[9149]: B92DC29697: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 08:59:59 mx1 postfix/smtpd[9150]: 8C606296DF: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
Feb  1 09:00:41 mx1 postfix/smtpd[9149]: 864B6292E4: client=dns24445.phdns8.es[185.92.244.45], sasl_method=LOGIN, sasl_username=sysmx@laneta.apc.org
0 mx1:/etc/postfix/vhcs2#

comment:3 Changed 23 months ago by https://id.mayfirst.org/jamie

Still deleting 27K+ messages from mailq...

comment:4 Changed 23 months ago by https://id.mayfirst.org/jamie

  • Resolution set to fixed
  • Status changed from new to closed

all messages deleted.

Please login to add comments to this ticket.

Note: See TracTickets for help on using tickets.