Open relay or what?
I have a customer that manages his own box. He keeps a fairly tight reign on the box and is the only user with ftp access. He contacted me last night and asked if I could help him get rid of all the spam he was seeing. I looked around his system and took care of spam going to him and thought that I closed off the open relay he had on the box.Unfortunately, 12 hours later, his box is apparently still sending out GOBS of emails. I have looked all over and can't find out where they are coming from. He doesn't send email from the box so I set the sendmail relay to localhost.
Here is just a small snippet from his maillog. Can anyone offer any suggestions? He is running a server on EV1 and they refuse to help in any way.
Code:
Mar 8 14:22:58 ensim sendmail[5738]: j28KMwP05736: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=52369, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05740 Message accepted for delivery) Mar 8 14:22:58 ensim sendmail[5744]: j28KMwP05744: from=<>, size=22783, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:58 ensim sendmail[5742]: j28KMwP05740: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=52576, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05744 Message accepted for delivery) Mar 8 14:22:58 ensim sendmail[5748]: j28KMwP05748: from=<>, size=22990, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:58 ensim sendmail[5746]: j28KMwP05744: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=52783, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05748 Message accepted for delivery) Mar 8 14:22:58 ensim sendmail[5752]: j28KMwP05752: from=<>, size=23197, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:58 ensim sendmail[5750]: j28KMwP05748: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=52990, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05752 Message accepted for delivery) Mar 8 14:22:58 ensim sendmail[5756]: j28KMwP05756: from=<>, size=23404, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:58 ensim sendmail[5754]: j28KMwP05752: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=53197, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05756 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5760]: j28KMwP05760: from=<>, size=23611, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5758]: j28KMwP05756: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:01, xdelay=00:00:01, mailer=esmtp, pri=53404, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMwP05760 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5764]: j28KMxP05764: from=<>, size=23818, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5762]: j28KMwP05760: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:01, xdelay=00:00:00, mailer=esmtp, pri=53611, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05764 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5768]: j28KMxP05768: from=<>, size=24025, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5766]: j28KMxP05764: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=53818, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05768 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5772]: j28KMxP05772: from=<>, size=24232, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5770]: j28KMxP05768: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=54025, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05772 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5776]: j28KMxP05776: from=<>, size=24439, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5774]: j28KMxP05772: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=54232, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05776 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5780]: j28KMxP05780: from=<>, size=24646, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5778]: j28KMxP05776: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=54439, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05780 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5784]: j28KMxP05784: from=<>, size=24853, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5782]: j28KMxP05780: to=<kqptikkhyacvk@animalhouse.com>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=54646, relay=mail.animalhouse.com. [127.0.0.1], dsn=2.0.0, stat=Sent (j28KMxP05784 Message accepted for delivery) Mar 8 14:22:59 ensim sendmail[5788]: j28KMxP05788: from=<>, size=25060, class=0, nrcpts=1, msgid=<200503082022.j28KMuP05687@ensim.duckcalls.net>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1] Mar 8 14:22:59 ensim sendmail[5788]: j28KMxP05788: SYSERR(root): Too many hops 26 (25 max): from <> via localhost.localdomain, to <kqptikkhyacvk@animalhouse.com>