PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : qmail logs deuten: qmail-smtpd/current



skatetrash13
03.11.06, 17:39
nach einigen tests bin ich mir sicher das mein mailserver kein offenes relay ist, heute habe ich mir meine qmail logs mal ein bischen näher angesehen und folgende einträge in den qmail smtpd logs gefunden:

könnt ihr mir sagen was dieses genau bedeuted, vor allem die tcpserver meldungen die mit status ok abgezeichnet sind?

@40000000454a78080c39cc84 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to altop.winnifred@gmail.com
@40000000454a780823260624 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to skipgundlach.takethisout@gmail.com
@40000000454a780837aec89c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to tipsforbusymoms@gmail.com
@40000000454a780910c86cc4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to birain.addicted@gmail.com
@40000000454a780925a3a49c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to laracroft.tmk@gmail.com
@40000000454a78093a46636c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to kelle79@gmail.com
@40000000454a780a137ec2c4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to tuba@gmail.com
@40000000454a780a28214314 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to zodiac.pisces13@gmail.com
@40000000454a780b016137d4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to fyzza78@gmail.com
@40000000454a780b161651dc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to sallyenr@gmail.com
@40000000454a780b2ad33414 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to mroelstraete@gmail.com
@40000000454a780c03f52d0c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to mickeypicsfl@gmail.com
@40000000454a780c18b21afc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to diklalili2@gmail.com
@40000000454a780c2d6ef94c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to startredder@gmail.com
@40000000454a780d068931e4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to eddienji@gmail.com
@40000000454a780d1b49968c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to almasi.vanna@gmail.com
@40000000454a780d3002d714 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to allen476@gmail.com
@40000000454a780e0924ace4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to freecatalunya@gmail.com
@40000000454a780e1ec37ef4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to behnam10@gmail.com
@40000000454a780e3368ce04 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to alfonsi.wan@gmail.com
@40000000454a780f0c8786f4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to jorge655@gmail.com
@40000000454a780f214090cc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to hamiltonaction@gmail.com
@40000000454a780f3617966c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to ericslaughter@gmail.com
@40000000454a78100f71f0fc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to tcebanks@gmail.com
@40000000454a7810248cba44 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to hdkorea@gmail.com
@40000000454a7810394942a4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to needpop@gmail.com
@40000000454a78111285b8dc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to monidcaklusha@gmail.com
@40000000454a7811273e7c64 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to sussqy@gmail.com
@40000000454a781200592a2c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to thefarbers@gmail.com
@40000000454a78121514d7cc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to terrikhz@gmail.com
@40000000454a781229d6616c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to buyviagraonline-547@gmail.com
@40000000454a781302f83b24 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to leplom@gmail.com
@40000000454a781317b16c0c qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to oczwgu@gmail.com
@40000000454a78132c6acfbc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to davina.rauf@gmail.com
@40000000454a781405902be4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to ass-parade@gmail.com
@40000000454a78141a7dc2dc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to nfqupuuj@gmail.com
@40000000454a78142f3768f4 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to acf71989@gmail.com
@40000000454a781508249264 qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to christinicencen@gmail.com
@40000000454a78151cfb26bc qmail-smtpd: Attempted relay from dimethyl@classifiedtoday.com at 88.241.167.113 to prettyugly06@gmail.com
@40000000454a7815326ae604 tcpserver: end 8606 status 0
@40000000454a7815326aedd4 tcpserver: status: 0/40
@40000000454b03202a87a83c tcpserver: status: 1/40
@40000000454b03202a87b3f4 tcpserver: pid 10395 from 127.0.0.1
@40000000454b032030ce9f0c tcpserver: ok 10395 localhost:127.0.0.1:25 :127.0.0.1::1976
@40000000454b03253ae7a4ac tcpserver: end 10395 status 0
@40000000454b03253ae7b44c tcpserver: status: 0/40
@40000000454b36db07948b4c tcpserver: status: 1/40
@40000000454b36db07985024 tcpserver: pid 10959 from 61.216.250.43
@40000000454b36dc098c05ec tcpserver: ok 10959 :192.168.1.5:25 61-216-250-43.dynamic.hinet.net:61.216.250.43::4512
@40000000454b36dc0bd18d04 tcpserver: end 10959 status 256
@40000000454b36dc0bd194d4 tcpserver: status: 0/40
@40000000454b50563578e184 tcpserver: status: 1/40
@40000000454b50563578ed3c tcpserver: pid 11191 from 194.25.134.80
@40000000454b505702416674 tcpserver: ok 11191 :192.168.1.5:25 mailout01.sul.t-online.com:194.25.134.80::40022
@40000000454b505f005d9ae4 tcpserver: end 11191 status 0
@40000000454b505f005da69c tcpserver: status: 0/40
@40000000454b5edb1f068334 tcpserver: status: 1/40
@40000000454b5edb1f068eec tcpserver: pid 11342 from 222.122.179.234
@40000000454b5edb386848e4 tcpserver: ok 11342 :192.168.1.5:25 :222.122.179.234::1583
@40000000454b5edc1e6bba34 tcpserver: end 11342 status 256
@40000000454b5edc1e6bc5ec tcpserver: status: 0/40
@40000000454b601e246da53c tcpserver: status: 1/40
@40000000454b601e246db0f4 tcpserver: pid 11355 from 222.122.179.234
@40000000454b601e27dd19dc tcpserver: ok 11355 :192.168.1.5:25 :222.122.179.234::2260
@40000000454b601f2c07cc14 qmail-smtpd: Attempted relay from atmpXXlt@dslb-082-083-247-219.pools.arcor-ip.net at 222.122.179.234 to rexm5hjz@gmail.com
@40000000454b602004045bc4 tcpserver: end 11355 status 256
@40000000454b602004046394 tcpserver: status: 0/40

derRichard
03.11.06, 18:12
hallo!

das hat nichts mit qmail zu tun. das sind tcpserver-sachen. :D

jedenfalls schreibt tcpserver immer "ok" wenn er eine neue verbindung aufgebaut hat.
sachen wie "status 1/40" heissen, dass derzeit eine von 40 verbindungsslots verwendet werden.

hth,
//richard

skatetrash13
03.11.06, 18:31
hallo!

das hat nichts mit qmail zu tun. das sind tcpserver-sachen. :D

jedenfalls schreibt tcpserver immer "ok" wenn er eine neue verbindung aufgebaut hat.
sachen wie "status 1/40" heissen, dass derzeit eine von 40 verbindungsslots verwendet werden.

hth,
//richard

hmm okay, danke für die info.
aber warum wird das dann in qmail-smtpd mitgelogt?

was sagt mir das hier:

@40000000454b505702416674 tcpserver: ok 11191 :192.168.1.5:25 mailout01.sul.t-online.com:194.25.134.80::40022
sind wahrscheinlich relay versuche durch diverse scripts aus dem netz oder?

derRichard
03.11.06, 18:36
hallo!

qmail-smtpd loggt eigentlich überhaupt nichts. die logs die man als smptd-logs kennt sind alle von tcpserver.

die zeile
@40000000454b505702416674 tcpserver: ok 11191 :192.168.1.5:25 mailout01.sul.t-online.com:194.25.134.80::40022
heisst, dass um 2006-11-03 15:21:01 eine verbindung von 194.25.134.80 angenommen wurde und tcpserver den qmail-smtpd kindprozess mit der pid 11191 gestartet hat.
überhaupt nichts besonderes. wenn diese langweiligen infos von tcpserver nicht willst, dann starte ihn ohne das "-v" flag.

hth,
//richard