exim сошёл с ума...

Тема в разделе "Администрирование серверов", создана пользователем Горбушка, 4 июл 2013.

Статус темы:
Закрыта.
Модераторы: mefish, stooper
  1. Горбушка

    Горбушка Ищу её...

    Регистр.:
    2 май 2008
    Сообщения:
    3.175
    Симпатии:
    2.195
    Вот кусок лога:
    Код:
    2013-07-04 03:39:48 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:49 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [98.138.112.37]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:50 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [66.196.118.36]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:51 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [98.138.112.38]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:51 1Uru55-00005M-RX ** kyziaq0197@inbox.ru R=dnslookup T=remote_smtp: SMTP error from remote mail server after end of data: host mxs.mail.ru [94.100.176.20]: 550 spam message discarded. Please visit http://help.mail.ru/notspam-support/id?c=ABV99hADIm9vFYJbCAQGDf6sHYCIxzz2DQAAAGhKAADMcpgr or  report details to abuse@corp.mail.ru. Error code: F67D15006F2203105B82156F0D060408801DACFEF63CC788. ID: 0000000D00004A682B9872CC.
    2013-07-04 03:39:51 1Uru55-00005M-RX ** macirinka@inbox.ru R=dnslookup T=remote_smtp: SMTP error from remote mail server after end of data: host mxs.mail.ru [94.100.176.20]: 550 spam message discarded. Please visit http://help.mail.ru/notspam-support/id?c=ABV99hADIm9vFYJbCAQGDf6sHYCIxzz2DQAAAGhKAADMcpgr or  report details to abuse@corp.mail.ru. Error code: F67D15006F2203105B82156F0D060408801DACFEF63CC788. ID: 0000000D00004A682B9872CC.
    2013-07-04 03:39:51 1Uru55-00005M-RX ** kuznetsova2011@inbox.ru R=dnslookup T=remote_smtp: SMTP error from remote mail server after end of data: host mxs.mail.ru [94.100.176.20]: 550 spam message discarded. Please visit http://help.mail.ru/notspam-support/id?c=ABV99hADIm9vFYJbCAQGDf6sHYCIxzz2DQAAAGhKAADMcpgr or  report details to abuse@corp.mail.ru. Error code: F67D15006F2203105B82156F0D060408801DACFEF63CC788. ID: 0000000D00004A682B9872CC.
    2013-07-04 03:39:51 1UtPCu-0005ti-H6 SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [66.196.118.33]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:51 1UuWeN-0002fu-Au <= <> R=1Uru55-00005M-RX U=Debian-exim P=local S=2583 from <> for webmaster@studiodev.ru
    2013-07-04 03:39:51 1UuWeN-0002fu-Au ** webmaster@studiodev.ru R=disabled_domains: Domain disabled
    2013-07-04 03:39:51 1UuWeN-0002fu-Au Frozen (delivery error message)
    2013-07-04 03:39:51 1Uru55-00005M-RX Completed
    2013-07-04 03:39:51 1UtPCu-0005ti-H6 SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.138.112.32]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:52 1Ushnp-0004wV-Nv SMTP error from remote mail server after RCPT TO:<reclama@ssr-realty.ru>: host MX01.NICMAIL.ru [194.85.88.238]: 451 You are in bl.spamcop.net RBL. Sorry...
    2013-07-04 03:39:52 1UsHx6-0002WN-2G Remote host mta5.am0.yahoodns.net [66.196.118.36] closed connection in response to HELO q-host.su
    2013-07-04 03:39:53 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [98.138.112.32]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:54 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [98.138.112.37]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:54 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [66.196.118.35]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:55 1UtPCu-0005ti-H6 SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.136.216.26]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:55 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [98.138.112.34]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:55 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:55 1UtPCu-0005ti-H6 Remote host mta7.am0.yahoodns.net [66.196.118.36] closed connection in response to HELO q-host.su
    2013-07-04 03:39:55 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta6.am0.yahoodns.net [98.138.112.35]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:56 1UrSn2-0002io-VH Remote host mta7.am0.yahoodns.net [98.138.112.32] closed connection in response to HELO q-host.su
    2013-07-04 03:39:56 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta5.am0.yahoodns.net [66.196.118.33]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:56 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [63.250.192.45]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:59 1UtPCu-0005ti-H6 SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [63.250.192.45]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:59 1UtPCu-0005ti-H6 == rawson_choco48@yahoo.com R=dnslookup T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [63.250.192.45]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:59 1UrSn2-0002io-VH SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.138.112.38]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:39:59 1UsjbI-0006TY-0k SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [66.196.118.37]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:00 1UsjbI-0006TY-0k SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.136.216.26]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:00 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [66.196.118.37]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:00 1UsjbI-0006TY-0k SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [66.196.118.36]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:00 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.136.216.26]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:00 1UrSn2-0002io-VH Remote host mta7.am0.yahoodns.net [66.196.118.33] closed connection in response to HELO q-host.su
    2013-07-04 03:40:00 1UsjbI-0006TY-0k SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.138.112.37]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:01 1UsjbI-0006TY-0k SMTP error from remote mail server after initial connection: host mta7.am0.yahoodns.net [98.138.112.38]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:02 1UuWeX-0002gs-Qj <= www-data@q-host.su U=www-data P=local S=629 from <www-data@q-host.su> for www-data
    2013-07-04 03:40:02 1UuWeX-0002gs-Qj ** www-data@q-host.su R=dnslookup T=remote_smtp: retry time not reached for any host after a long failure period
    2013-07-04 03:40:02 1UuWeY-0002hK-51 <= <> R=1UuWeX-0002gs-Qj U=Debian-exim P=local S=1462 from <> for www-data@q-host.su
    2013-07-04 03:40:02 1UuWeX-0002gs-Qj Completed
    2013-07-04 03:40:02 1UuWeY-0002hK-51 ** www-data@q-host.su R=dnslookup T=remote_smtp: retry time not reached for any host after a long failure period
    2013-07-04 03:40:02 1UuWeY-0002hK-51 Frozen (delivery error message)
    2013-07-04 03:40:02 1UsDHP-0001az-0K SMTP error from remote mail server after initial connection: host mta6.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
    2013-07-04 03:40:03 H=v6373.vps.masterhost.ru [90.156.212.103] F=<> rejected RCPT <webmaster@studiodev.ru>: Domain disabled
    2013-07-04 03:40:03 1UsHx6-0002WN-2G SMTP error from remote mail server after initial connection: host mta6.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 31.184.228.11 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html


    Собственно вот таких логов создаётся порядка 2-3 Мб в минуту. Что эта за херь и как с ней бороться? И как вычислить автора этого "презента"?

    Debian 6
    ISPmanager 4
    exim 4
     
  2. Kenny

    Kenny newbie

    Регистр.:
    17 авг 2006
    Сообщения:
    462
    Симпатии:
    150
    Это ваш IP адрес 31.184.228.11 ?
     
  3. Горбушка

    Горбушка Ищу её...

    Регистр.:
    2 май 2008
    Сообщения:
    3.175
    Симпатии:
    2.195
    Да, в том числе...
     
  4. parfentiy

    parfentiy Создатель

    Регистр.:
    30 май 2013
    Сообщения:
    15
    Симпатии:
    4
    я тут нашел 2 проблемы.

    1. mail.ru пишет, что вы в блэк листе - 451 You are in bl.spamcop.net RBL. Sorry..

    2. Yahoo вас футболит и предлагает прочитать правила Перейти по ссылке, где можно узнать о том, что они вас блокируют по причине аномального потока писем на их сервер.

    Судя по всему вас сервер все-же настойчиво игнорирует отказы и пытается и дальше пропихивать свое письмо.

    Думаю надо сначала смотреть в конфиге exim'a параметры повторных попыток отправления писем. Секция "retry".
    Попробуй добавить
    * * F,2h,15m; G,16h,1h,1.5; F,5d,8h
    По крайнем мере оно сделает таймауты на отправку и разгрузит сервак.
     
  5. Горбушка

    Горбушка Ищу её...

    Регистр.:
    2 май 2008
    Сообщения:
    3.175
    Симпатии:
    2.195
    Может кто-нибудь эту проблему решить за WMZ, естественно? Из бек-листов то я вылезу - не проблема, а вот спам с сервера надо убрать. К сожалению, в логах не нашёл кто автор писем и из-за кого нас забанили.
     
  6. Bezhev

    Bezhev

    Регистр.:
    26 дек 2012
    Сообщения:
    363
    Симпатии:
    124
    пройдись по логам, посмотри от кого больше всего писем уходит, там пишутся ящики. Можно конечно заюзать cat + sort, чтобы вывел топ самых ярых :)
     
  7. Горбушка

    Горбушка Ищу её...

    Регистр.:
    2 май 2008
    Сообщения:
    3.175
    Симпатии:
    2.195
    Уже сами решили проблему, всем спасибо.
     
Статус темы:
Закрыта.