IP Black listing problem

samuel dinakar sama samuel.dinakar at gmail.com
Thu Aug 7 11:22:40 UTC 2008


HI all,

Straight to the  problem I am facing in my organization.  I am maintaining
mail server Sendmail (fedora) .we  have a recurring problem , Public IP
(internet gateway s/m) is getting black listed because of Spam.. I couldn't
trace anything , How Trojan spam generated ? How to provide the security ?

For this problem I have been changing the public IP , but it not a solution
..



The below message is  thrown  by CBL.abuse.org for black listing :

*ATTENTION: **This IP is infected with, or NATting for a computer infected
with a high volume spam sending trojan - it is participating in a botnet. *

*This is the Srizbi BOT *

*You need to patch your system and then fix/remove the trojan. Do this
before delisting, or you're most likely to be listed again almost
immediately. *

*If this IP is a NAT firewall/gateway, you MUST configure the NAT to prevent
outbound port 25 connections to the Internet except from your real mail
servers. *

Any suggestion for me to give in IPtables or selinux. Your suggestions or
any input for this problem is very much appreciated.



Thanks & Regards,

*Samuel*



More information about the redhat-list mailing list