From owner-freebsd-ports@FreeBSD.ORG Mon Sep 8 13:18:29 2008 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A90891065672; Mon, 8 Sep 2008 13:18:29 +0000 (UTC) (envelope-from david@vizion2000.net) Received: from dns1.vizion2000.net (77-99-36-42.cable.ubr04.chap.blueyonder.co.uk [77.99.36.42]) by mx1.freebsd.org (Postfix) with ESMTP id 6A8068FC14; Mon, 8 Sep 2008 13:18:29 +0000 (UTC) (envelope-from david@vizion2000.net) Received: by dns1.vizion2000.net (Postfix, from userid 1007) id 20AA41CC32; Mon, 8 Sep 2008 06:42:28 -0700 (PDT) From: David Southwell Organization: Voice and Vision To: Jeremy Chadwick Date: Mon, 8 Sep 2008 06:42:27 -0700 User-Agent: KMail/1.9.10 References: <200809080510.27779.david@vizion2000.net> <20080908130726.GA69142@icarus.home.lan> In-Reply-To: <20080908130726.GA69142@icarus.home.lan> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200809080642.27904.david@vizion2000.net> Cc: freebsd-ports@freebsd.org Subject: Re: Mail services checking - URGENT X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 08 Sep 2008 13:18:29 -0000 On Monday 08 September 2008 06:07:26 Jeremy Chadwick wrote: > On Mon, Sep 08, 2008 at 05:10:27AM -0700, David Southwell wrote: > > I have had a series of attacks on a system which resulted in a hijack of > > our mail system. > > Also, one other point I forgot to make: > > This **should not** have gone to freebsd-ports, as the issue has > absolutely nothing to do with ports. > > This should have gone to freebsd-isp, freebsd-security, or possibly > freebsd-questions. I am sure you are right.. I was just hoping there might have been a port which would do something like.. trap all outgoing mail from the server - irrespective of the mta pas it through a filer and dump it in a file until you have had a chance to inspect it. Bearing in mind mail can come from multiple sources such a port would have been useful. Apologies for generating too much traffic david