最近发现邮件服务器发过来日志提示发现好多病毒邮件,今天对/var进行了扫描结果如下:

217 ----------- SCAN SUMMARY -----------
218 Known viruses: 917742
219 Engine version: 0.97
220 Scanned directories: 1840
221 Scanned files: 13178
222 Infected files: 85
223 Data scanned: 733.18 MB
224 Data read: 1130.25 MB (ratio 0.65:1)
225 Time: 57.434 sec (0 m 57 s)


/var/virusmails/virus-ChN4JJc2wb6k: BC.Heuristic.Trojan.SusPacked.BF-6.A FOUND
40 /var/virusmails/virus-Cah2EzBcSPJ0: Suspect.Trojan.Generic.FD-1 FOUND
41 /var/virusmails/virus-VPyQKXUNv+ki: Suspect.Trojan.Generic.FD-1 FOUND
42 /var/virusmails/virus-mvUUG97RWXhq: Trojan.Zbot-12527 FOUND
43 /var/virusmails/virus-h-Qy6RRAs5ma: Trojan.Downloader-52360 FOUND
44 /var/virusmails/spam-V-5RHSNfr0EH.gz: HTML.Phishing.Bank-502 FOUND
45 /var/virusmails/banned-lcChsLnWpswl: Trojan.Spy.SpyEyes-103 FOUND
46 /var/virusmails/virus-hycQwWo+xFN7: Trojan.Delf-10167 FOUND
47 /var/virusmails/banned-vlyEWVG2otoQ: Suspect.Bredozip-zippwd-11 FOUND
48 /var/virusmails/banned-ctkt8qrIlmWD: Trojan.Spyeye-1 FOUND
49 /var/virusmails/banned-hjqYxwU3XiuW: Trojan.Spy.SpyEyes-103 FOUND
50 /var/virusmails/virus-oDR3OO6enCtZ: BC.Heuristic.Trojan.SusPacked.BF-6.A FOUND
51 /var/virusmails/banned-ZxdWnEcBdhpz: Suspect.Bredozip-zippwd-11 FOUND
52 /var/virusmails/virus-Z3yca4bZM2c0: Trojan.Generic.Bredolab-2 FOUND
53 /var/virusmails/badh-2NJlnxoTQ1FL: Heuristics.Phishing.Email.SpoofedDomain FOUND
54 /var/virusmails/virus-eja3sk8yRik8: Suspect.Trojan.Generic.FD-1 FOUND
55 /var/virusmails/virus-7pCpYAMyh9hD: BC.Heuristic.Trojan.SusPacked.BF-6.A FOUND
56 /var/virusmails/banned-QaZG9llOUFef: Suspect.Bredozip-zippwd-11 FOUND
57 /var/virusmails/virus-xKskhgnxaxsu: BC.Heuristic.Trojan.SusPacked.BF-6.A FOUND
58 /var/virusmails/banned-gxb6OIm7UT3z: Suspect.Bredozip-zippwd-11 FOUND
59 /var/virusmails/banned-VVSobbFiJm4r: Suspect.Bredozip-zippwd-11 FOUND
60 /var/virusmails/virus-3delhYiozm8f: Trojan.Generic.Bredolab-2 FOUND
61 /var/virusmails/banned-UQ0rbZ3ODPyH: Trojan.Spyeye-1 FOUND
62 /var/virusmails/virus-hFzmziy+2Tpu: BC.Heuristic.Trojan.SusPacked.BF-6.A FOUND
63 /var/virusmails/banned-0UIm1Vb7zoRy: Suspect.Bredozip-zippwd-11 FOUND

请问/var/virusmails/下面的的所有文件可以删除吗,删除对邮件服务器会不会有影响,请知道的人帮助一下,谢谢!

最近二周来每天都会收到发过来的日志邮件提示发现病毒,这种情况怕不怕呀,真担心服务器给挂了。谢!A virus was found: Suspect.Bredozip-zippwd-2Scanner detecting a virus: ClamAV-clamdContent type: VirusInternal reference code for the message is 11241-07/gszvrzWxX0v2First upstream SMTP client IP address: [88.11.6.128] According to a 'Received:' trace, the message apparently originated at:  [88.11.6.128], dhl.com unknown [88.11.6.128]Return-Path: <federal.no.5641@dhl.com>From:

brucemioo 写道:

最近域内的很多用户反映他们的邮件帐户经常收到邮件服务器发“发送失败”的邮件,邮件的主题基本都是“发送给hao的金蛋”,但实际用户根本没有发送过那些邮件,发送日志和历史记录中也没有发送到任何记录。

下面是其中一封失败邮件的内容:
This is the mail system at host rojao.cn.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<ouchaoyi@21cn.com>: host mta.21cn.com[59.36.102.50] said: 550
    (ID:10.27.2.3-1287555615-51245-AB/11-16399-F1A8EBC4) No such user on
    Inbound SMTP server 233! (in reply to RCPT TO command)

很多类似的邮件,只是收件人不同。

各位大侠,这是怎么回事呢?系统被黑了吗?

我的邮件服务器也出现这个情况了,大概有一周了,我也没有太去注意它,那现在得注意一下看看!楼主使用的是那个版本的iredmail呢?

我的邮件服务器是centos的系统,装的是iredmail.0.3.2的版本,用得很稳定就一直没有升级,最近升级php软件包出现错误提示:
Finished Dependency Resolution
php-eaccelerator-5.1.6_0.9.5.2-4.el5.rf.x86_64 from installed has depsolving problems
  --> Missing Dependency: php = 5.1.6 is needed by package php-eaccelerator-5.1.6_0.9.5.2-4.el5.rf.x86_64 (installed)
Error: Missing Dependency: php = 5.1.6 is needed by package php-eaccelerator-5.1.6_0.9.5.2-4.el5.rf.x86_64 (installed)
You could try using --skip-broken to work around the problem
You could try running: package-cleanup --problems
                        package-cleanup --dupes
                        rpm -Va --nofiles --nodigest

请问这个问题怎么解决呀,把php-eaccelerator包卸载掉是不是就可以了呀,会不会出问题呀?谢谢!

只是邮件的域名是在美国申请的,邮件服务器是放在香港的,用的是iredmail搭建的,我还在使用0.3.2的版本,一直用得很稳定。只是最近跟国外的邮件多了,就发现上面的问题了。

eddiechen 写道:

对于邮件的反向解析,不是在dns那里做的,而是你服务器托管的地方,帮你做反向解析的。

在国内做ip地址的反向解析是比较复杂,需要收费,国外的vps,基本都提供反向解析。

采用反向解析来拒绝邮件的,一个都是国外的服务器。

我们的邮件都是发国外比较多,回头联系一下国外的服务商看他们能否帮助解决!
谢谢你让我知道是怎么回事了!非常谢谢!

eddiechen 写道:

这就是国外的邮件服务商,要求你的机器提供反向解析。要做反向解析,就必须找你服务器托管的地方,让运营商帮你做才行。这个在国内还是很麻烦的。


我们的邮件都是发国外比较多,回头联系一下国外的服务商看他们能否帮助解决!
谢谢你让我知道是怎么回事了!非常谢谢!

iredmail 经常有些邮件提示发不出去,查看日志提示“The Reverse DNS lookup for your IP address is failing”,请问怎么样可以解决这个问题呀?

我们邮箱的域名是在美国申请,然后登录域名提供商的域名控制面板把邮箱域名指向我们的iredmail服务器IP,我们的iredmail服务器是装在cnentos系统上,装上iredmail后都是默认设置,很多邮件在队例里面看到就是这样的提示:The Reverse DNS lookup for your IP address is failing 。这样应该是我们的邮件服务器的设置有问题吗?

请帮助,谢!

Hostname validation errors: 1 Message(s), 211 Time(s)

**Unmatched Entries**

910F61DE067C: host mx2a.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
4CA251DE069C: host mx1.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
C364F1DE0688: host mx1a.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
12E2A1DE0689: host mx1.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
A05FC1DE066C: host mx1b.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
4CA251DE069C: host mx2.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
12E2A1DE0689: host mx2b.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
A05FC1DE066C: host mx2a.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
910F61DE067C: host mx1a.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
C364F1DE0688: host mx1b.comcast.net[76.96.62.116] refused to talk to me: 554 imta17.westchester.pa.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
12E2A1DE0689: host mx2a.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
A05FC1DE066C: host mx2b.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR
910F61DE067C: host mx2b.comcast.net[76.96.30.116] refused to talk to me: 554 imta20.emeryville.ca.mail.comcast.net comcast 220.241.233.244 Comcast requires that all mail servers must have a PTR record with a valid Reverse DNS entry. Currently your mail server does not fill that requirement. For more information, refer to: http://help.comcast.net/content/faq/PTR

各位老大这个提示是那里出问题了,需要怎么样解决呀。最近的邮件有很多这样的提示,不知道怎么样解决,谢谢!

好像我早就下载了呀,呵呵,好像是7月初下的。

我的也出现了楼主所说的问题了,我忘记改helo是在那里改了!
-------------------------------------------------------------------------------
May  3 02:09:15 mail postfix/smtpd[6316]: connect from unknown[202.108.3.166]
May  3 02:09:16 mail postfix/smtpd[6316]: NOQUEUE: reject: RCPT from unknown[202.108.3.166]: 554 5.7.1 <sina.com>: Helo command rejected: Go away, bad guy (sina.com).;

from=<yzmb826@sina.com> to=<lee@espowhk.com> proto=ESMTP helo=<sina.com>
May  3 02:09:16 mail postfix/smtpd[6316]: NOQUEUE: reject: RCPT from unknown[202.108.3.166]: 554 5.7.1 <sina.com>: Helo command rejected: Go away, bad guy (sina.com).;

from=<yzmb826@sina.com> to=<tao@espowhk.com> proto=ESMTP helo=<sina.com>
May  3 02:09:16 mail postfix/smtpd[6316]: disconnect from unknown[202.108.3.166]

cogoku 写道:

終於搞定了~~ 謝謝

写一下你的过程吧,让大家分享分享!

Last Status:
    WARNING: Your ClamAV installation is OUTDATED!
    WARNING: Local version: 0.95.3 Recommended version: 0.96
0.96的开始测试了没有呀?

iredmail 0.3.2的版本受影响不呀?

自从决定用iredmail到现在已经足足有一年多了,邮件服务器还是使用的是0.3.2的版本,邮件服务器一直在互联网上裸奔着,没有硬件防火墙,至今运行稳定。要是老出事,那得老跑香港,累都要累死人。那天挂了就换最新版的iredmail。iredmail好用,省心,省事。

使用iredmail已经有一年多了,iredmail工作一直非常稳定,服务器在互联网上裸奔还没有出现过什么大的问题,可见iredmail是非常稳定。
我还是使用的iredmail 0.3.2的版本,由于它的稳定我也一直没有更新它版本,今天看见iredmail的软件仓库dovecot有更新包了,不知道有谁还在用iredmail 0.3.2版有更新此包的没有,更新不知道会不会有问题?

因为服务器放在香港,要是更新有问题了的话,就会比较麻烦。希望大家能给点帮助!谢!

:L  等于没说

装了iredmail,可里面得policyd不会用呀,
版主能不能写两个列子,比如限制两个用户邮箱的大小不一样和限制两个用户一小时收发次数不一样

[ 本帖最后由 edit 于 2009-9-2 23:34 编辑 ]

:handshake  多谢bibby,正解呀!
是 $sa_mail_body_size_limit = 吧

[ 本帖最后由 edit 于 2009-7-14 13:12 编辑 ]

如果要让 Amavisd 对本地外发的邮件不做邮件内容过滤和病毒扫描,可以在 policy_bank 里增加参数:
文件: /etc/amavisd.conf

$policy_bank{'MYNETS'} = {   # mail originating from @mynetworks
  originating => 1,  # is true in MYNETS by default, but let's make it explicit
  os_fingerprint_method => undef,  # don't query p0f for internal clients

  #
  # 增加以下三个参数
  #
  bypass_spam_checks_maps   => [1],  # don't spam-check internal mail
  bypass_banned_checks_maps => [1],  # don't banned-check internal mail
  bypass_header_checks_maps => [1],  # don't header-check internal mail
};

hi bibby,这个设置后,感觉没作用,一个15M的附件,设置前和设置后的时间都是一样的

21

(4 篇回复,发表在 iRedMail 技术支持)

:lol  是的,现在又有问题
http://192.168.0.7/mail/
出现:
DATABASE ERROR: CONNECTION FAILED!
Unable to connect to the database!
Please contact your server-administrator.

22

(4 篇回复,发表在 iRedMail 技术支持)

iRedMail-0.4.0,装完后, 访问 http://IP/mail  ,出现

404 Not Found

--------------------------------------------------------------------------------

nginx/0.7.39
这是怎么回事,官方也没有详细的说明

23

(9 篇回复,发表在 iRedMail 技术支持)

安装iredmail好慢 :L
里面还要安装mysql。php、apache等

24

(9 篇回复,发表在 iRedMail 技术支持)

:handshake  多谢,我试一下

25

(9 篇回复,发表在 iRedMail 技术支持)

iRedOS好像下载不了,只能下载iRedmail