Mail Server Hacker Attack SMTP Relay Mail Queue Overload Paypal Phishing
I've been doing everything I can think of over the last 48 hours to try to stop a Mail Server attack against a malicious hacker / cracker who has found a way load up thousands of eBay & Paypal Phishing emails into my Mail Queue with successful execution of hundreds of them before I caught the attack.
Luckily, I have a backup server for incidents like this, but I would much rather use my main server as my Mail Sever. I have completely turned off Mail Service on this one for the time being until I found out how to stop my Mail Queue being loaded up from 2a.m. to 6a.m. with this crap.
How can the hacker execute sending mail through a www user? I have every encryption possible loaded up into the Mail Server, including...
No SMTP Relay
CRAM-MD5 SMTP Authentication
How can these messages be going out through an unauthenticated www user?
I have read all of the related threads:
http://discussions.apple.com/thread.jspa?messageID=1486643�
I've searched my /var/tmp folder, however I don't see any suspicious files that would make me believe there is a trojan on my server.
Here is an SMTP log example:
Mar 21 13:12:57 www postfix/smtpd[2197]: connect from localhost[127.0.0.1]
Mar 21 13:12:57 www postfix/pickup[4873]: 0AFA7761FB2: uid=70 from=<www>
Mar 21 13:12:57 www postfix/cleanup[4562]: 0AFA7761FB2: message-id=<1307466449.1525@ebay.com>?
Mar 21 13:12:57 www postfix/qmgr[79]: 0AFA7761FB2: from=<www@www.MYSERVER.com>, size=37567, nrcpt=1 (queue active)
Mar 21 13:12:57 www postfix/pickup[4873]: 0F82A761FB3: uid=70 from=<www>
Mar 21 13:12:57 www postfix/cleanup[4942]: 0F82A761FB3: message-id=<1307466449.1511@ebay.com>?
Mar 21 13:12:57 www postfix/qmgr[79]: 0F82A761FB3: from=<www@www.MYSERVER.com>, size=37564, nrcpt=1 (queue active)
From this, they have loaded up the Mail Queue, and then go on to execute:
(earlier in the morning when the mails were actually being executed before I caught it)
Mar 21 07:01:27 www postfix/smtpd[21912]: 1CAAC74A7F7: client=omr-m06.mx.aol.com[64.12.138.18]
Mar 21 07:01:27 www postfix/smtp[21838]: 38F9D713AA9: to=<olav@eggendata.no>, relay=127.0.0.1[127.0.0.1], delay=14389, status=sent (250 2.6.0 Ok, id=21896-03, from MTA: 250 Ok: queued as E4F0674A7F3)
Mar 21 07:01:27 www postfix/qmgr[26107]: 38F9D713AA9: removed
Mar 21 07:01:27 www postfix/smtpd[21819]: connect from omr-m09.mx.aol.com[64.12.138.21]
Mar 21 07:01:27 www postfix/smtp[17655]: 7D17A6FD15A: to=<kekepania71@aol.com>, relay=mailin-04.mx.aol.com[64.12.138.152], delay=17174, status=sent (250 OK)
Mar 21 07:01:27 www postfix/qmgr[26107]: 7D17A6FD15A: removed
Mar 21 07:01:27 www postfix/smtpd[21819]: 4D04974A7F8: client=omr-m09.mx.aol.com[64.12.138.21]
Mar 21 07:01:27 www postfix/cleanup[21843]: 1CAAC74A7F7: message-id=<200603211301.IAC15100@rly-xm02.mx.aol.com>
Mar 21 07:01:27 www postfix/qmgr[26107]: 1CAAC74A7F7: from=, size=3994, nrcpt=1 (queue active)
Mar 21 07:01:27 www postfix/smtp[21710]: 7CC9873C83E: to=<ofcweb@netscape.net>, relay=mailin-03.mx.netscape.net[205.188.158.25], delay=3231, status=sent (250 OK)
Mar 21 07:01:27 www postfix/smtpd[21912]: disconnect from omr-m06.mx.aol.com[64.12.138.18]
Mar 21 07:01:27 www postfix/qmgr[26107]: 7CC9873C83E: removed
How is this guy able to relay through my localhost [127.0.0.1] without authenticating through the CRAM-MD5 process?
Am I missing something totally simple here?? I won't be offended.
Thanks for any help in advance.
G5 Dual 2Ghz Mac OS X (10.4.5) OSX Server