psyncho
December 18th, 2008, 12:58 PM
Hi, Comcast recently shut down my port 25 saying spam was emanating from my network. I think they're wrong, but was compelled to scan all my machines anyway.
For my Ubuntu server I have postfix, looked at all the logs, didn't find anything but system messages sent to root. I did a tcpdump and am looking over all traffic with wireshark and see pretty much no smtp other than those same system messages. I also did a clamav scan for kicks and found nothing.
Just wanted to get opinions/advice on what other folks might recommend looking at - or if there is a more practical/methodical approach recommendations I can use to hone my own trouble shooting skills.
thanks
For my Ubuntu server I have postfix, looked at all the logs, didn't find anything but system messages sent to root. I did a tcpdump and am looking over all traffic with wireshark and see pretty much no smtp other than those same system messages. I also did a clamav scan for kicks and found nothing.
Just wanted to get opinions/advice on what other folks might recommend looking at - or if there is a more practical/methodical approach recommendations I can use to hone my own trouble shooting skills.
thanks