la mise à mort final est là
Bonjour
En parcourant le forum, je suis un plus rassuré. Depuis 4 jours j'ai un traffic constant sur mon port 25.
J'ai bien lu que par défaut, et cela n'a pas été changé, que le SMTP de SME est bloqué depuis le net (ouf)
Mais lorsque je fais un tcpdump -i eth1 sur mon ipcop j'obtiens ceci:
- Code: Tout sélectionner
root@wrapcop:~ # tcpdump -i eth1
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
15:50:48.639937 IP mail29.bluewin.ch.50428 > SME.lan.smtp: . 3091581806:3091581807(1) ack 1398972982 win 0 <nop,nop,timestamp 475366314 27781816>
15:50:48.640103 IP SME.lan.smtp > mail29.bluewin.ch.50428: . ack 0 win 0 <nop,nop,timestamp 27785035 475366314>
15:50:49.859943 IP mail30.bluewin.ch.43450 > SME.lan.smtp: . 3316290953:3316290954(1) ack 1112364055 win 0 <nop,nop,timestamp 475357738 27779156>
15:50:49.860063 IP SME.lan.smtp > mail30.bluewin.ch.43450: . ack 0 win 0 <nop,nop,timestamp 27785157 475357738>
15:50:51.399943 IP mail30.bluewin.ch.43442 > SME.lan.smtp: . 2735534099:2735534100(1) ack 1107408932 win 0 <nop,nop,timestamp 475357892 27779310>
15:50:51.400066 IP SME.lan.smtp > mail30.bluewin.ch.43442: . ack 0 win 0 <nop,nop,timestamp 27785311 475357892>
15:50:51.649938 IP mail29.bluewin.ch.48486 > SME.lan.smtp: . 803935762:803935763(1) ack 779938167 win 0 <nop,nop,timestamp 475366615 27779336>
15:50:51.650041 IP SME.lan.smtp > mail29.bluewin.ch.48486: . ack 0 win 0 <nop,nop,timestamp 27785336 475366615>
15:50:53.949948 IP mail30.bluewin.ch.42696 > SME.lan.smtp: . 2699288868:2699288869(1) ack 798122393 win 0 <nop,nop,timestamp 475358147 27779565>
15:50:53.950089 IP SME.lan.smtp > mail30.bluewin.ch.42696: . ack 0 win 0 <nop,nop,timestamp 27785566 475358147>
15:50:55.389942 IP mail29.bluewin.ch.48492 > SME.lan.smtp: . 455515168:455515169(1) ack 779696547 win 0 <nop,nop,timestamp 475366989 27779710>
15:50:55.390064 IP SME.lan.smtp > mail29.bluewin.ch.48492: . ack 0 win 0 <nop,nop,timestamp 27785710 475366989>
15:51:23.199590 IP SME.lan.smtp > mail29.bluewin.ch.50428: . ack 0 win 0 <nop,nop,timestamp 27788491 475366314>
15:51:23.209926 IP mail29.bluewin.ch.50428 > SME.lan.smtp: . ack 1 win 0 <nop,nop,timestamp 475369770 27785035>
15:51:34.679939 IP mail30.bluewin.ch.42698 > SME.lan.smtp: . 2911366896:2911366897(1) ack 785936456 win 0 <nop,nop,timestamp 475362220 27783639>
15:51:34.680110 IP SME.lan.smtp > mail30.bluewin.ch.42698: . ack 0 win 0 <nop,nop,timestamp 27789639 475362220>
15:51:45.390238 arp who-has SME.lan tell 192.168.35.254
15:51:45.390352 arp reply SME.lan is-at 00:50:04:f4:9e:03
15:51:45.390418 IP mail29.bluewin.ch.50771 > SME.lan.smtp: S 1509017454:1509017454(0) win 32850 <mss 1412,nop,wscale 1,nop,nop,timestamp 475371988 0,nop,nop,sackOK>
15:51:45.390613 IP SME.lan.smtp > mail29.bluewin.ch.50771: S 1542999186:1542999186(0) ack 1509017455 win 5792 <mss 1460,sackOK,timestamp 27790710 475371988,nop,wscale 0>
15:51:45.399932 IP mail29.bluewin.ch.50771 > SME.lan.smtp: . ack 1 win 32900 <nop,nop,timestamp 475371989 27790710>
15:51:45.411941 IP SME.lan.smtp > mail29.bluewin.ch.50771: P 1:43(42) ack 1 win 5792 <nop,nop,timestamp 27790711 475371989>
15:51:45.419989 IP mail29.bluewin.ch.50771 > SME.lan.smtp: . ack 43 win 32900 <nop,nop,timestamp 475371991 27790711>
15:51:45.420405 IP mail29.bluewin.ch.50771 > SME.lan.smtp: P 1:25(24) ack 43 win 32900 <nop,nop,timestamp 475371991 27790711>
Et ceci par la suite...
- Code: Tout sélectionner
15:51:46.369591 IP SME.lan.56732 > 64.73.128.23.domain: 51516 A? campeole.com.multi.surbl.org. (46)
15:51:46.381289 IP SME.lan.13094 > a.gtld-servers.net.domain: 20800 NS? campeole.com. (30)
15:51:46.382199 IP SME.lan.42695 > 64-68-11-11.ip.elan.net.domain: 38720[|domain]
15:51:46.382951 IP SME.lan.61285 > 64-68-11-11.ip.elan.net.domain: 3084[|domain]
15:51:46.389600 IP SME.lan.19868 > ns7.njabl.org.domain: 2952 A? 33.131.167.217.combined.njabl.org. (51)
15:51:46.390347 IP SME.lan.natuslink > ns9.njabl.org.domain: 27731 A? 137.231.214.195.combined.njabl.org. (52)
15:51:46.391100 IP SME.lan.6986 > spamcopbl.dws0154.fast.net.domain: 54262 TXT? 33.131.167.217.bl.spamcop.net. (47)
15:51:46.391849 IP SME.lan.cft-4 > spamcop.velocitus.net.domain: 56852 TXT? 137.231.214.195.bl.spamcop.net. (48)
15:51:46.399922 IP SME.lan.52143 > spamcop.velocitus.net.domain: 26678 TXT? 21.19.186.195.bl.spamcop.net. (46)
15:51:46.400587 IP SME.lan.18482 > 64-68-11-11.ip.elan.net.domain: 57613[|domain]
15:51:46.401256 IP SME.lan.llm-pass > ns5.sorbs.net.domain: 50606 A? rbldns4.sorbs.net. (35)
15:51:46.401998 IP SME.lan.osdcp > ns3.mydyndns.org.domain: 11518 A? rbldns4.sorbs.net. (35)
15:51:46.410042 IP SME.lan.wap-push-http > 189-27-251-64.serverpronto.com.domain: 32707[|domain]
15:51:46.419601 IP SME.lan.40751 > ltns2.returnpath.net.domain: 23168[|domain]
15:51:46.420352 IP SME.lan.41704 > rs5s2.datacenter.cha.cantv.net.domain: 37059 A? 137.231.214.195.sbl-xbl.spamhaus.org. (54)
15:51:46.429600 IP SME.lan.12494 > mouth.voxel.net.domain: 23361 TXT? 70.18.186.195.list.dsbl.org. (45)
15:51:46.430351 IP SME.lan.42659 > mouth.voxel.net.domain: 830 TXT? 21.19.186.195.list.dsbl.org. (45)
15:51:46.431017 IP SME.lan.60056 > dsbl.bl.xs4all.nl.domain: 34462 TXT? 137.231.214.195.list.dsbl.org. (47)
15:51:46.431764 IP SME.lan.22312 > spamhaus2.vortechhosting.com.domain: 10442 A? 33.131.167.217.sbl-xbl.spamhaus.org. (53)
15:51:46.450008 IP dsbl.bl.xs4all.nl.domain > SME.lan.60056: 34462 NXDomain*- 0/1/0 (99)
15:51:46.500025 IP a.gtld-servers.net.domain > SME.lan.13094: 20800- 2/0/2 NS[|domain]
15:51:46.510027 IP spamcopbl.dws0154.fast.net.domain > SME.lan.6986: 54262 NXDomain*- 0/1/0 (100)
15:51:46.520019 IP 64.73.128.23.domain > SME.lan.56732: 51516 NXDomain*- 0/1/0 (89)
15:51:46.529714 IP ns7.njabl.org.domain > SME.lan.19868: 2952 NXDomain*- 0/1/0 (96)
15:51:46.530297 IP ns9.njabl.org.domain > SME.lan.natuslink: 27731 NXDomain*- 0/1/0 (97)
15:51:46.539988 IP mouth.voxel.net.domain > SME.lan.12494: 23361 ServFail- 0/0/0 (45)
15:51:46.540145 IP SME.lan.55159 > dsbl.zhwin.ch.domain: 31602 TXT? 70.18.186.195.list.dsbl.org. (45)
15:51:46.541207 IP mouth.voxel.net.domain > SME.lan.42659: 830 ServFail- 0/0/0 (45)
15:51:46.541360 IP SME.lan.52393 > 156.17.5.122.domain: 57634 TXT? 21.19.186.195.list.dsbl.org. (45)
15:51:46.550021 IP 189-27-251-64.serverpronto.com.domain > SME.lan.wap-push-http: 32707 NXDomain*-[|domain]
15:51:46.560031 IP dsbl.zhwin.ch.domain > SME.lan.55159: 31602 NXDomain*- 0/1/0 (97)
15:51:46.570065 IP ltns2.returnpath.net.domain > SME.lan.40751: 23168 NXDomain*- 0/1/0 (103)
15:51:46.570573 IP spamhaus2.vortechhosting.com.domain > SME.lan.22312: 10442 NXDomain*- 0/1/0 (117)
15:51:46.571170 IP 64-68-11-11.ip.elan.net.domain > SME.lan.42695: 38720 NXDomain*-[|domain]
15:51:46.571706 IP 64-68-11-11.ip.elan.net.domain > SME.lan.61285: 3084 NXDomain*-[|domain]
15:51:46.589996 IP 64-68-11-11.ip.elan.net.domain > SME.lan.18482: 57613 NXDomain*-[|domain]
15:51:46.590750 IP ns3.mydyndns.org.domain > SME.lan.osdcp: 11518*- 1/8/7 A predator.sorbs.net (325)
79 packets captured
102 packets received by filter
0 packets dropped by kernel
Le traffic qui en résulte est 'quand même' de ~7ko/s en down et ~4ko/s en up
Je me sens bien impuissant fasse à toutes ces demandes sur mon port 25, et je ne vois pas comment bloquer ceci, sinon je ne recevrai plus rien du tout... ce qui n'est pas idéal non plus. De changer de nom dymanique, mais je me dis que les personnes qui ont une ip fixe doivent aussi avoir ce genre de soucis. Non ?
Ce que je peux assurer, c'est que lorsque j'ai capturé ces logs, personnes n'utilisait le mail sur SME. (si cela peut aider)
Merci.
^^