apitsos
Verified User
Hi there,
Yesterday I had an issue with my web server. A client contacted me and he told me that his email were not delivered, even if in outlook they were in sent folder (IMAP connected). I tried to send a test message and I realized that he was right. Then I connected on DA control panel and I went to "Mail Queue Administration", where I saw 27 pages of emails in a queue list!
I tried to restart dovecot service, but I saw that the list were growing up instead of reducing! I rebooted the server and after reboot I tried to clear that queue list by checking the emails (page by page) and clicking "retry".
After an hour or something I cleared the list and everything seemed that was working fine.
Today afternoon I had again the same issues. I tried to find a solution but I couldn't I spent several hours, but nothing. Restarting the services of exim and dovecot couldn't give a solution. After several hours I make it to clear the list with retries.
What I notice is that the system produces decades of emails per minute! The strange is that the sender is empty and the recipient is the root user! I am placing here the header, the body and the log of one of these emails.
Header
Body Chunk
Log
I would appreciate if someone could help me with it! I strongly believe that something is wrong with my system the last two days and I need your help!
Kind regards,
Angelos Pitsos
Yesterday I had an issue with my web server. A client contacted me and he told me that his email were not delivered, even if in outlook they were in sent folder (IMAP connected). I tried to send a test message and I realized that he was right. Then I connected on DA control panel and I went to "Mail Queue Administration", where I saw 27 pages of emails in a queue list!
I tried to restart dovecot service, but I saw that the list were growing up instead of reducing! I rebooted the server and after reboot I tried to clear that queue list by checking the emails (page by page) and clicking "retry".
After an hour or something I cleared the list and everything seemed that was working fine.
Today afternoon I had again the same issues. I tried to find a solution but I couldn't I spent several hours, but nothing. Restarting the services of exim and dovecot couldn't give a solution. After several hours I make it to clear the list with retries.
What I notice is that the system produces decades of emails per minute! The strange is that the sender is empty and the recipient is the root user! I am placing here the header, the body and the log of one of these emails.
Header
Code:
1TTyBc-0002vR-QC-H
mail 8 12
<>
1351789448 0
-ident mail
-received_protocol local
-body_linecount 161
-max_received_linelength 93
-allow_unqualified_recipient
-allow_unqualified_sender
-deliver_firsttime
-localerror
XX
1
[email protected]
146P Received: from mail by manage.pla.net.gr with local (Exim 4.72)
id 1TTyBc-0002vR-QC
for [email protected]; Thu, 01 Nov 2012 19:04:08 +0200
038 Date: Thu, 01 Nov 2012 19:04:08 +0200
050I Message-Id: <[email protected]>
044 X-Failed-Recipients: [email protected]
029 Auto-Submitted: auto-replied
061F From: Mail Delivery System <[email protected]>
027T To: [email protected]
059 Subject: Mail delivery failed: returning message to sender
Body Chunk
Code:
1TTyBc-0002vR-QC-D
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
[email protected]
retry timeout exceeded
------ This is a copy of the message, including all the headers. ------
Return-path: <[email protected]>
Received: from root by manage.pla.net.gr with local (Exim 4.72)
(envelope-from <[email protected]>)
id 1TTvlQ-0005l2-Pv
for [email protected]; Thu, 01 Nov 2012 16:28:56 +0200
Date: Thu, 01 Nov 2012 16:28:56 +0200
Message-Id: <[email protected]>
To: [email protected]
Subject: lfd on manage.pla.net.gr: Suspicious process running under user govisit
From: <[email protected]>
Time: Thu Nov 1 16:28:56 2012 +0200
PID: 21006
Account: govisit
Uptime: 128 seconds
Executable:
/usr/local/php5/bin/php-cgi
Command Line (often faked in exploits):
/usr/local/php5/bin/php-cgi
Network connections by the process (if any):
tcp: 127.0.0.1:37508 -> 127.0.0.1:21
Files open by the process (if any):
Memory maps by the process (if any):
00110000-00183000 r-xp 00000000 fd:03 24035460 /usr/local/lib/libfreetype.so.6.7.1
00183000-00187000 rwxp 00073000 fd:03 24035460 /usr/local/lib/libfreetype.so.6.7.1
00187000-00188000 rwxp 00187000 00:00 0
00188000-00192000 r-xp 00000000 fd:03 62489602 /lib/libnss_files-2.5.so
00192000-00193000 r-xp 00009000 fd:03 62489602 /lib/libnss_files-2.5.so
00193000-00194000 rwxp 0000a000 fd:03 62489602 /lib/libnss_files-2.5.so
00194000-00198000 r-xp 00000000 fd:03 62490542 /lib/libnss_dns-2.5.so
00198000-00199000 r-xp 00003000 fd:03 62490542 /lib/libnss_dns-2.5.so
00199000-0019a000 rwxp 00004000 fd:03 62490542 /lib/libnss_dns-2.5.so
0019a000-0019b000 rwxp 0019a000 00:00 0
0019b000-001a3000 r-xp 00000000 fd:03 24028410 /usr/lib/libkrb5support.so.0.1
001a3000-001a4000 rwxp 00007000 fd:03 24028410 /usr/lib/libkrb5support.so.0.1
001a4000-001a7000 rwxp 001a4000 00:00 0
001a7000-001a8000 r-xp 03425000 fd:03 24036482 /usr/lib/locale/locale-archive
001a8000-001a9000 r-xp 0085d000 fd:03 24036482 /usr/lib/locale/locale-archive
001a9000-001aa000 r-xp 02d67000 fd:03 24036482 /usr/lib/locale/locale-archive
001aa000-001ab000 r-xp 02edd000 fd:03 24036482 /usr/lib/locale/locale-archive
001af000-001b0000 rwxp 001af000 00:00 0
001b0000-001ed000 r-xp 00000000 fd:03 24031561 /usr/local/lib/libpcre.so.0.0.1
001ed000-001ee000 rwxp 0003c000 fd:03 24031561 /usr/local/lib/libpcre.so.0.0.1
001ee000-00229000 r-xp 00000000 fd:03 62490523 /lib/libsepol.so.1
00229000-0022a000 rwxp 0003b000 fd:03 62490523 /lib/libsepol.so.1
0022a000-00234000 rwxp 0022a000 00:00 0
00234000-0026f000 r-xp 01013000 fd:03 24036482 /usr/lib/locale/locale-archive
0026f000-00291000 r-xp 01be0000 fd:03 24036482 /usr/lib/locale/locale-archive
00291000-002ac000 r-xp 01cd9000 fd:03 24036482 /usr/lib/locale/locale-archive
002ac000-002bf000 r-xp 00000000 fd:03 24035472 /usr/local/lib/libz.so.1.2.3
002bf000-002c0000 rwxp 00012000 fd:03 24035472 /usr/local/lib/libz.so.1.2.3
002d3000-002d4000 rwxp 002d3000 00:00 0
00323000-0036f000 r-xp 00000000 fd:03 24035459 /usr/local/lib/libcurl.so.4.2.0
0036f000-00371000 rwxp 0004b000 fd:03 24035459 /usr/local/lib/libcurl.so.4.2.0
003a8000-003a9000 r-xp 003a8000 00:00 0 [vdso]
003a9000-00463000 r-xp 00000000 fd:03 24641577 /usr/local/ioncube/ioncube_loader_lin_5.2.so
00463000-00468000 rwxp 000b9000 fd:03 24641577 /usr/local/ioncube/ioncube_loader_lin_5.2.so
00468000-00469000 rwxp 00468000 00:00 0
00482000-004c6000 r-xp 00000000 fd:03 62489599 /lib/libssl.so.0.9.8e
004c6000-004ca000 rwxp 00043000 fd:03 62489599 /lib/libssl.so.0.9.8e
004ca000-0054b000 rwxp 004ca000 00:00 0
0055c000-00577000 r-xp 00000000 fd:03 62488764 /lib/ld-2.5.so
00577000-00578000 r-xp 0001a000 fd:03 62488764 /lib/ld-2.5.so
00578000-00579000 rwxp 0001b000 fd:03 62488764 /lib/ld-2.5.so
005b1000-005b2000 rwxp 005b1000 00:00 0
005b2000-006a7000 r-xp 00000000 fd:03 24035538 /usr/local/lib/libiconv.so.2.5.0
006a7000-006a8000 rwxp 000f5000 fd:03 24035538 /usr/local/lib/libiconv.so.2.5.0
006ba000-006bb000 rwxp 006ba000 00:00 0
006d6000-006d9000 r-xp 00000000 fd:03 62488820 /lib/libdl-2.5.so
006d9000-006da000 r-xp 00002000 fd:03 62488820 /lib/libdl-2.5.so
006da000-006db000 rwxp 00003000 fd:03 62488820 /lib/libdl-2.5.so
006dd000-006f2000 r-xp 00000000 fd:03 62490528 /lib/libpthread-2.5.so
006f2000-006f3000 r-xp 00015000 fd:03 62490528 /lib/libpthread-2.5.so
006f3000-006f4000 rwxp 00016000 fd:03 62490528 /lib/libpthread-2.5.so
006f4000-006f6000 rwxp 006f4000 00:00 0
006f8000-0071f000 r-xp 00000000 fd:03 62490526 /lib/libm-2.5.so
0071f000-00720000 r-xp 00026000 fd:03 62490526 /lib/libm-2.5.so
00720000-00721000 rwxp 00027000 fd:03 62490526 /lib/libm-2.5.so
00723000-0072a000 r-xp 00000000 fd:03 62490529 /lib/librt-2.5.so
0072a000-0072b000 r-xp 00007000 fd:03 62490529 /lib/librt-2.5.so
0072b000-0072c000 rwxp 00008000 fd:03 62490529 /lib/librt-2.5.so
0072e000-00744000 r-xp 00000000 fd:03 62490524 /lib/libselinux.so.1
00744000-00746000 rwxp 00015000 fd:03 62490524 /lib/libselinux.so.1
00790000-00799000 r-xp 00000000 fd:03 62490530 /lib/libcrypt-2.5.so
00799000-0079a000 r-xp 00008000 fd:03 62490530 /lib/libcrypt-2.5.so
0079a000-0079b000 rwxp 00009000 fd:03 62490530 /lib/libcrypt-2.5.so
0079b000-007c2000 rwxp 0079b000 00:00 0
007c4000-007d9000 r-xp 00000000 fd:03 62490532 /lib/libnsl-2.5.so
007d9000-007da000 r-xp 00014000 fd:03 62490532 /lib/libnsl-2.5.so
007da000-007db000 rwxp 00015000 fd:03 62490532 /lib/libnsl-2.5.so
007db000-007dd000 rwxp 007db000 00:00 0
0087f000-0088f000 r-xp 00000000 fd:03 62489477 /lib/libresolv-2.5.so
0088f000-00890000 r-xp 0000f000 fd:03 62489477 /lib/libresolv-2.5.so
00890000-00891000 rwxp 00010000 fd:03 62489477 /lib/libresolv-2.5.so
00891000-00893000 rwxp 00891000 00:00 0
008c7000-008ee000 r-xp 00000000 fd:03 24035539 /usr/local/lib/libmcrypt.so.4.4.8
008ee000-008f1000 rwxp 00027000 fd:03 24035539 /usr/local/lib/libmcrypt.so.4.4.8
008f1000-008f6000 rwxp 008f1000 00:00 0
009b2000-009f7000 r-xp 00000000 fd:03 24035671 /usr/local/lib/libmhash.so.2.0.1
009f7000-009f8000 rwxp 00044000 fd:03 24035671 /usr/local/lib/libmhash.so.2.0.1
00a41000-00a43000 r-xp 00000000 fd:03 62490525 /lib/libcom_err.so.2.1
00a43000-00a44000 rwxp 00001000 fd:03 62490525 /lib/libcom_err.so.2.1
00a46000-00a48000 r-xp 00000000 fd:03 62488901 /lib/libkeyutils-1.2.so
00a48000-00a49000 rwxp 00001000 fd:03 62488901 /lib/libkeyutils-1.2.so
00a8c000-00ab9000 r-xp 00000000 fd:03 24035672 /usr/lib/libgssapi_krb5.so.2.2
00ab9000-00aba000 rwxp 0002d000 fd:03 24035672 /usr/lib/libgssapi_krb5.so.2.2
00abc000-00b50000 r-xp 00000000 fd:03 24035669 /usr/lib/libkrb5.so.3.3
00b50000-00b53000 rwxp 00093000 fd:03 24035669 /usr/lib/libkrb5.so.3.3
00b55000-00b7b000 r-xp 00000000 fd:03 24031870 /usr/lib/libk5crypto.so.3.1
00b7b000-00b7c000 rwxp 00025000 fd:03 24031870 /usr/lib/libk5crypto.so.3.1
00b7c000-00ca6000 r-xp 00000000 fd:03 62489585 /lib/libcrypto.so.0.9.8e
00ca6000-00cb9000 rwxp 00129000 fd:03 62489585 /lib/libcrypto.so.0.9.8e
00cb9000-00cbd000 rwxp 00cb9000 00:00 0
00d68000-00d6d000 r-xp 00000000 fd:03 24035675 /usr/local/lib/libltdl.so.3.1.0
00d6d000-00d6e000 rwxp 00004000 fd:03 24035675 /usr/local/lib/libltdl.so.3.1.0
00d6e000-00dbf000 r-xp 00000000 fd:03 24035390 /usr/lib/libmysqlclient.so.15.0.0
00dbf000-00eba000 rwxp 00050000 fd:03 24035390 /usr/lib/libmysqlclient.so.15.0.0
00f66000-00fa0000 r-xp 00000000 fd:03 24032163 /usr/local/lib/libpng.so.3.1.2.44
00fa0000-00fa1000 rwxp 0003a000 fd:03 24032163 /usr/local/lib/libpng.so.3.1.2.44
00fa1000-010f4000 r-xp 00000000 fd:03 62488804 /lib/libc-2.5.so
010f4000-010f6000 r-xp 00153000 fd:03 62488804 /lib/libc-2.5.so
010f6000-010f7000 rwxp 00155000 fd:03 62488804 /lib/libc-2.5.so
010f7000-010fa000 rwxp 010f7000 00:00 0
0199c000-01ab5000 r-xp 00000000 fd:03 24035506 /usr/local/lib/libxml2.so.2.7.6
01ab5000-01aba000 rwxp 00118000 fd:03 24035506 /usr/local/lib/libxml2.so.2.7.6
01aba000-01abb000 rwxp 01aba000 00:00 0
05c0a000-05d51000 r-xp 00000000 fd:03 24035548 /usr/local/lib/ZendOptimizer_5.2.so
05d51000-05d63000 rwxp 00146000 fd:03 24035548 /usr/local/lib/ZendOptimizer_5.2.so
05d63000-05d67000 rwxp 05d63000 00:00 0
0637e000-0657e000 r-xp 00000000 fd:03 24036482 /usr/lib/locale/locale-archive
08048000-08602000 r-xp 00000000 fd:03 24742722 /usr/local/php5/bin/php-cgi
08602000-0862d000 rwxp 005ba000 fd:03 24742722 /usr/local/php5/bin/php-cgi
0862d000-08637000 rwxp 0862d000 00:00 0
088b9000-09369000 rwxp 088b9000 00:00 0 [heap]
bff17000-bff2f000 rwxp bffe6000 00:00 0 [stack]
Log
Code:
2012-11-01 19:04:08 Received from <> R=1TTvlQ-0005l2-Pv U=mail P=local S=9306 T="Mail delivery failed: returning message to sender"
I would appreciate if someone could help me with it! I strongly believe that something is wrong with my system the last two days and I need your help!
Kind regards,
Angelos Pitsos