![]() |
| Le forum de référence en programmation et développement. Articles, cours et tutoriels du débutant au chef de projet et DBA confirmé. | |||||||
|
|||||||
| Autres Autres distributions : Gentoo, Slackware, Knoppix, Kaella, Dsl, ... |
![]() |
|
|
Outils de la discussion |
|
|
#1 (permalink) |
|
Membre régulier
![]() Date d'inscription: mai 2005
Messages: 118
|
Bonjour,
Je ne reçois plus les e-mails ni ne peut en envoyer sur notre serveur dédié gentoo release 2 ovh, il y a 161 e-mails depuis hier en attente et je n'arrive pas à savoir comment les débloquer, pouvez-vous m'aider svp ? Code :
# /var/qmail/bin/qmail-qstat messages in queue: 161 messages in queue but not yet preprocessed: 161Les logs disent : Code :
clamdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem |
|
|
|
|
|
#2 (permalink) |
|
Membre régulier
![]() Date d'inscription: mai 2005
Messages: 118
|
ça a remarché mais nous sommes vraiment infestés de spams...
Code :
tail -f current @4000000047e916a22af9750c CHKUSER accepted rcpt: from <´_°·¨®¶¤@yahoo.com.br::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <voca1234922@yahoo.com.tw> : found existing recipient @4000000047e916a3192a40cc CHKUSER accepted rcpt: from <´_°·¨®¶¤@yahoo.com.br::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <iamdumm2003@yahoo.com.tw> : found existing recipient @4000000047e916a62107f49c CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <sskang541201@yahoo.com.tw> : found existing recipient @4000000047e916a709ad592c CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <coldyo727@yahoo.com.tw> : found existing recipient @4000000047e916a7313501fc CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <a0223520723@yahoo.com.tw> : found existing recipient @4000000047e916a917b88c44 CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <redingot168@yahoo.com.tw> : found existing recipient @4000000047e916aa03389f84 CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <toyota.t2@yahoo.com.tw> : found existing recipient @4000000047e916aa25ad2e04 CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <dark05212000@yahoo.com.tw> : found existing recipient @4000000047e916ab1ac8dd6c CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <tinyamchan@yahoo.com.tw> : found existing recipient @4000000047e916ac048d0bf4 CHKUSER accepted rcpt: from <³¯®Ë´¼_@yahoo.com.tw::> remote <91.xxx.xx.x:unknown:58.61.75.114> rcpt <aaa091192004@yahoo.com.tw> : found existing recipient |
|
|
|
|
|
#3 (permalink) |
|
Membre régulier
![]() Date d'inscription: mai 2005
Messages: 118
|
Mon fichier /var/spool/qscan/qmail-queue.log se remplit vraiment très vite, dangereusement...
Ex : Code :
Tue, 25 Mar 2008 17:41:55 CET:20071: g_e_h: return-path='°k¤©«c@msn.com', recips='jsppck@yahoo.com.tw,furefughter@yahoo.com.tw,leepeiway@yahoo.com.tw,l58530023@yahoo.com.tw,arlinsna@yahoo.com.tw,story_yu@yahoo.com.tw,r6832vicky@yahoo.com.tw,king318is@yahoo.com.tw,rvd1283@yahoo.com.tw' Tue, 25 Mar 2008 17:41:55 CET:20071: from='"ÂÅ´f¯]" <°K¤©«C@msn.com>', subj='³Ì·s¹CÀ¸, °|½u¹q¼v, ¦UÃþ³nÅé, ¥þ·s¤W¬[wRkOALEN', via SMTP from 58.61.75.114 Tue, 25 Mar 2008 17:41:55 CET:20071: error_condition: X-Qmail-Scanner-2.01st: clamdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem - exit status 512/2 Tue, 25 Mar 2008 17:41:55 CET:20071: ------ Process 20071 finished. Total of 0.011999 secs Tue, 25 Mar 2008 17:41:55 CET:22903: w_c: Total time between DATA command and "." was 6.2e-05 secs Tue, 25 Mar 2008 17:41:55 CET:22903: w_c: elapsed time from start 8.4e-05 secs Tue, 25 Mar 2008 17:41:55 CET:22903: g_e_h: return-path='mwxppadwxrk@yahoo.com', recips='aiati@yahoo.com.tw,drpdb@yahoo.com.tw,bie1982@yahoo.com.tw' Tue, 25 Mar 2008 17:41:55 CET:22903: from='"shuang tung" <mwxppadwxrk@yahoo.com>', subj='¹CÀ¸¡B¼v*µ¡B±¡¦â VCD ±M½æ', via SMTP from 116.25.212.74 Tue, 25 Mar 2008 17:41:55 CET:22903: error_condition: X-Qmail-Scanner-2.01st: clamdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem - exit status 512/2 Tue, 25 Mar 2008 17:41:55 CET:22903: ------ Process 22903 finished. Total of 0.011946 secs |
|
|
|
|
|
#7 (permalink) |
|
Membre régulier
![]() Date d'inscription: mai 2005
Messages: 118
|
Je n'ai pas trouvé le fichier main.cf !
Comment réactiver l'antispam ?? je ne sais plus... Je crois qu'en août dernier, j'avais installé spamassassin mais je ne me rappelle plus de rien... Il est désactivé selon vous ? J'ai redémarré qmail, clamd et pour spamd, voici ce qu'ils marquent : Code :
# /etc/init.d/spamd restart
* Stopping spamd ... [ ok ]
* Starting spamd ...
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LANG = "fr_FR@euro"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
|
|
|
|
|
|
#8 (permalink) |
|
Membre régulier
![]() Date d'inscription: mai 2005
Messages: 118
|
Bonjour,
Ce matin, nos e-mails étaient encore bloqués ! Code :
# /var/qmail/bin/qmail-qstat messages in queue: 276 messages in queue but not yet preprocessed: 203 Plusieurs fichiers continuent à se remplir sans arrêt ! Code :
# du -s /var/spool/qscan/*| sort -rn 481440 /var/spool/qscan/qmail-queue.log 12188 /var/spool/qscan/quarantine Code :
Wed, 26 Mar 2008 09:10:59 CET:28357: +++ starting debugging for process 28357 (p pid=28446) by uid=508
Wed, 26 Mar 2008 09:10:59 CET:20190: SA: yup, this smells like SPAM - hits=25.3/ 5.0/5.1 - message deleted ...
Wed, 26 Mar 2008 09:10:59 CET:20190: SA: finished scan in 3.359068 secs - hits=2 5.3/5.0
Wed, 26 Mar 2008 09:10:59 CET:20190: ini_sc: finished scan of "/var/spool/qscan/ tmp/ns26252.ovh.net120651905576720190"...
Wed, 26 Mar 2008 09:10:59 CET:20190: ------ Process 20190 finished. Total of 3.3 75677 secs
Wed, 26 Mar 2008 09:11:00 CET:26769: +++ starting debugging for process 26769 (ppid=16408) by uid=508
Wed, 26 Mar 2008 09:11:00 CET:3718: +++ starting debugging for process 3718 (ppid=31757) by uid=508
Wed, 26 Mar 2008 09:11:00 CET:23902: +++ starting debugging for process 23902 (ppid=3598) by uid=508
Wed, 26 Mar 2008 09:11:00 CET:28357: w_c: Total time between DATA command and "." was 6.5e-05 secs
Wed, 26 Mar 2008 09:11:00 CET:28357: w_c: elapsed time from start 7.4e-05 secs
Wed, 26 Mar 2008 09:11:00 CET:28357: g_e_h: return-path='smjyjrven@yahoo.com', recips='vio-777@yahoo.com.tw,jwphd2088@yahoo.com.tw,nike8323912@yahoo.com.tw,sophie_liu_0702@yahoo.com.tw,ing0521@yahoo.com.tw,jacobliu44@yahoo.com.tw,cyeekenny@yahoo.com.tw,janesd4813@yahoo.com.tw,good_0108@yahoo.com.tw'
Wed, 26 Mar 2008 09:11:00 CET:28357: from='"hans chris" <smjyjrven@yahoo.com>', subj='¦n±d¬Û³ø¡A½ÐªY½à¤@¤U!', via SMTP from 116.7.21.38
Wed, 26 Mar 2008 09:11:00 CET:28357: clamdscan: finished scan in 0.004448 secs
Wed, 26 Mar 2008 09:11:00 CET:26769: w_c: Total time between DATA command and "." was 6e-05 secs
Wed, 26 Mar 2008 09:11:00 CET:26769: w_c: elapsed time from start 7.5e-05 secs
Wed, 26 Mar 2008 09:11:00 CET:26769: g_e_h: return-path='®l¤é¶§¥úªºd.@gmail.com', recips='pcmlam@yahoo.com.tw,cucei@yahoo.com.tw,vland@yahoo.com.tw,iiself@ms95.url.com.tw'
Wed, 26 Mar 2008 09:11:00 CET:26769: from='"¶¾µa¤¤" <®L¤é¶§¥úªºD.@gmail.com>', subj='¡¹³Ì·s¹CÀ¸¡D¹qµø¹CÀ¸¡DPSPµ{¦¡¡DÀ³¦³ºÉ¦³³á¡I¡IAAA6Q ', via SMTP from 116.30.246.36
Wed, 26 Mar 2008 09:11:00 CET:26769: clamdscan: finished scan in 0.004603 secs
Wed, 26 Mar 2008 09:11:00 CET:12632: SA: yup, this smells like SPAM - hits=24.5/5.0/5.1 - message deleted ...
Wed, 26 Mar 2008 09:11:00 CET:12632: SA: finished scan in 2.657502 secs - hits=24.5/5.0
Wed, 26 Mar 2008 09:11:00 CET:12632: ini_sc: finished scan of "/var/spool/qscan/tmp/ns26252.ovh.net120651905776712632"...
Wed, 26 Mar 2008 09:11:00 CET:12632: ------ Process 12632 finished. Total of 2.672851 secs
Wed, 26 Mar 2008 09:11:00 CET:6284: +++ starting debugging for process 6284 (ppid=22566) by uid=508
Wed, 26 Mar 2008 09:11:01 CET:23902: w_c: Total time between DATA command and "." was 6.2e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:23902: w_c: elapsed time from start 7.1e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:23902: g_e_h: return-path='wihvxfxuxss@yahoo.com', recips='moon.bebe@msa.hinet.net,jh.lin724@msa.hinet.net,battle.zone@msa.hinet.net,su.weijung@msa.hinet.net,hsifu73.lin@msa.hinet.net,tracy.jcm@msa.hinet.net'
Wed, 26 Mar 2008 09:11:01 CET:23902: from='"tsou laurent" <wihvxfxuxss@yahoo.com>', subj='°Ó°È³nÅé. ±M·~¾Ç²ß. ¥®±Ð³nÅé. ¦r«¬³nÅé', via SMTP from 116.25.131.67
Wed, 26 Mar 2008 09:11:01 CET:23902: clamdscan: finished scan in 0.004323 secs
Wed, 26 Mar 2008 09:11:01 CET:23283: SA: yup, this smells like SPAM - hits=22.0/5.0/5.1 - message deleted ...
Wed, 26 Mar 2008 09:11:01 CET:23283: SA: finished scan in 10.135155 secs - hits=22.0/5.0
Wed, 26 Mar 2008 09:11:01 CET:23283: ini_sc: finished scan of "/var/spool/qscan/tmp/ns26252.ovh.net120651905076723283"...
Wed, 26 Mar 2008 09:11:01 CET:23283: ------ Process 23283 finished. Total of 10.150963 secs
Wed, 26 Mar 2008 09:11:01 CET:11053: SA: yup, this smells like SPAM - hits=22.9/5.0/5.1 - message deleted ...
Wed, 26 Mar 2008 09:11:01 CET:11053: SA: finished scan in 4.240208 secs - hits=22.9/5.0
Wed, 26 Mar 2008 09:11:01 CET:11053: ini_sc: finished scan of "/var/spool/qscan/tmp/ns26252.ovh.net120651905676711053"...
Wed, 26 Mar 2008 09:11:01 CET:11053: ------ Process 11053 finished. Total of 4.256832 secs
Wed, 26 Mar 2008 09:11:01 CET:6284: w_c: Total time between DATA command and "." was 6.7e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:6284: w_c: elapsed time from start 7.3e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:6284: g_e_h: return-path='´é±ö_@xuite.net', recips='76.10.10@yahoo.com.tw,tenso@yahoo.com.tw,chin_chen168@ms94.url.com.tw,jjwc@yahoo.com.tw,chin78599@ms93.url.com.tw,compp@ms47.url.com.tw'
Wed, 26 Mar 2008 09:11:01 CET:6284: from='"¤ý²Q§g" <´é±ö_@xuite.net>', subj='³nÅé¶°¤¤Àç¥Ø¿ý§ó·s³qª¾jlTgAF', via SMTP from 116.30.246.36
Wed, 26 Mar 2008 09:11:01 CET:6284: clamdscan: finished scan in 0.00413 secs
Wed, 26 Mar 2008 09:11:01 CET:3718: w_c: Total time between DATA command and "." was 6.1e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:3718: w_c: elapsed time from start 7.3e-05 secs
Wed, 26 Mar 2008 09:11:01 CET:3718: g_e_h: return-path='_ªl¨}¥ç@xuite.net', recips='rufer@yahoo.com.tw,cross320@yahoo.com.tw,ivant@yahoo.com.tw,cutiepuppy18@yahoo.com.tw'
Wed, 26 Mar 2008 09:11:01 CET:3718: from='"§õ«T¥°" <_ªL¨}¥ç@xuite.net>', subj='À³¦³ºÉ¦³!! ºô¸ô¤W³Ì»ô¥þ³Ì«K©y³nÅéºô!!tbUrO', via SMTP from 116.30.246.36
Wed, 26 Mar 2008 09:11:01 CET:3718: clamdscan: finished scan in 0.004183 secs
Wed, 26 Mar 2008 09:11:01 CET:73: SA: yup, this smells like SPAM - hits=22.0/5.0/5.1 - message deleted ...
Wed, 26 Mar 2008 09:11:01 CET:73: SA: finished scan in 3.632248 secs - hits=22.0/5.0
Wed, 26 Mar 2008 09:11:01 CET:73: ini_sc: finished scan of "/var/spool/qscan/tmp/ns26252.ovh.net120651905776773"...
Wed, 26 Mar 2008 09:11:01 CET:73: ------ Process 73 finished. Total of 3.649366 secs
Code :
# du -s /home/log/*| sort -rn 571260 /home/log/mail.log 404588 /home/log/mail.info 87648 /home/log/mail.warn 84188 /home/log/xferlog 76876 /home/log/mail.err 47088 /home/log/httpd 29580 /home/log/qmail 29404 /home/log/qmailsmtp Nous avons trouvé 2 adresses IP principalement, mais comment les bloquer SVP ??? Il doit bien y avoir un moyen de bloquer l'adresse IP SMTP Linux d'un spammeur sur qmail de notre dédié ?... SVP, HELP !!! |
|
|
|
![]() |
![]() |
||
Problème Gentoo Qmail in Queue
|
||
| Outils de la discussion | |
|
|