이렇게나와요
root 22790 1 0 11:27 ? 00:00:00 sendmail: accepting connections
root 22791 22790 0 11:27 ? 00:00:00 sendmail: KAA21558 mx03.earthlin
root 22817 1 0 11:28 ? 00:00:00 sendmail: LAA22815 mx06.earthlin
root 22822 1 0 11:28 ? 00:00:00 sendmail: LAA22818 mx09.earthlin
root 22825 1 0 11:28 ? 00:00:00 sendmail: LAA22823 mx04.earthlin
root 22828 1 0 11:28 ? 00:00:00 sendmail: LAA22826 mx06.earthlin
root 22833 1 0 11:28 ? 00:00:00 sendmail: LAA22831 mx03.earthlin
root 22838 1 0 11:28 ? 00:00:00 sendmail: LAA22834 mx03.earthlin
root 22846 1 0 11:28 ? 00:00:00 sendmail: LAA22839 mx02.earthlin
root 22853 1 0 11:28 ? 00:00:00 sendmail: LAA22847 mx11.earthlin
root 22862 1 0 11:28 ? 00:00:00 sendmail: LAA22854 mx11.earthlin
root 22869 1 0 11:28 ? 00:00:00 sendmail: LAA22863 mx09.earthlin
root 22899 1 0 11:29 ? 00:00:00 sendmail: LAA22897 mx11.earthlin
root 22902 1 0 11:29 ? 00:00:00 sendmail: LAA22900 mx03.earthlin
root 22905 1 0 11:29 ? 00:00:00 sendmail: LAA22903 mx01.earthlin
root 22910 1 0 11:30 ? 00:00:00 sendmail: LAA22908 mx08.earthlin
root 22913 1 0 11:30 ? 00:00:00 sendmail: LAA22911 mx09.earthlin
root 22946 1 0 11:32 ? 00:00:00 sendmail: LAA22943 mx04.earthlin
root 22950 1 0 11:32 ? 00:00:00 sendmail: LAA22947 mx11.earthlin
root 22954 1 0 11:32 ? 00:00:00 sendmail: LAA22951 mx05.earthlin
root 22958 1 0 11:32 ? 00:00:00 sendmail: LAA22955 mx08.earthlin
root 22961 1 0 11:32 ? 00:00:00 sendmail: LAA22959 mx08.earthlin
root 22964 1 0 11:32 ? 00:00:00 sendmail: LAA22962 mx01.earthlin
root 22967 1 0 11:32 ? 00:00:00 sendmail: LAA22965 mx04.earthlin
root 22970 1 0 11:32 ? 00:00:00 sendmail: LAA22968 mx06.earthlin
root 22973 1 0 11:32 ? 00:00:00 sendmail: LAA22971 mx00.earthlin
root 22976 1 0 11:32 ? 00:00:00 sendmail: LAA22974 mx01.earthlin
root 22979 1 0 11:32 ? 00:00:00 sendmail: LAA22977 mx01.earthlin
프로세스 하나에 메일이 한번 보내지는게 맞다면
지금 누군가 저희 서버를 이용해서 스팸보내고 있는거 같습니다.
지금 sendmail 을 죽였다가 다시 살렸거든요..
1분사이에 저렇게나 많이 돌고있다는게 ( 사실 위에건 1/3 만 카피한겁니다 )
이해가 되질 않아요..
sendmail.cf 에서 Realy denied 부분 전부 주석 뺐구요
access 에서
211.xxx.0 -tab- RELAY 한다음
makemap hash /etc/mail/access < /etc/mail/access
이렇게 했습니다.
저렇게 하면 211.xxx.0 에 속한 ip 에서만 메일을 보낼수 있는거 아닌가여?
그렇다면 해킹 당한거 맞나요?
어떡하죠...