Bonjour,
J’aimerai avoir quelques astuces pour vérifier que mon serveur est bien sécurisé. J’ai suivi des tutos comme celui proposé par OpenClassRoom en installant fail2ban et en configurant correctement mon firewall. J’utilise aussi rkhunter et portsentry.
Le problème est que lorsque je consulte mes logs et notamment le fichier mail.warn j’ai ceci :
[quote]May 21 05:52:53 de1345 postfix/smtpd[1411]: warning: 95.9.39.164: hostname 95.9.39.164.static.ttnet.c$
May 21 05:52:53 /usr/lib/plesk-9.0/psa-pc-remote[1073]: Message aborted.
May 21 05:52:53 /usr/lib/plesk-9.0/psa-pc-remote[1073]: Message aborted.
May 21 06:23:20 plesk_saslauthd[1476]: Invalid mail address 'everest@'
May 21 06:23:20 postfix/smtpd[1473]: warning: s15433869.onlinehome-server.com[74.208.72.28]: S$
May 21 06:55:57 plesk_saslauthd[1554]: Invalid mail address 'falcon@'
May 21 06:55:57 postfix/smtpd[1551]: warning: s15433869.onlinehome-server.com[74.208.72.28]: S$
May 21 07:28:37 plesk_saslauthd[1626]: Invalid mail address 'fax@'
May 21 07:28:37 postfix/smtpd[1623]: warning: s15433869.onlinehome-server.com[74.208.72.28]: S$
May 21 08:01:00 plesk_saslauthd[1695]: Invalid mail address 'ftpuser@'
May 21 08:01:00 postfix/smtpd[1692]: warning: s15433869.onlinehome-server.com[74.208.72.28]: S$
May 21 08:33:17 plesk_saslauthd[1762]: Invalid mail address 'fujitsu@'
May 21 08:33:17 postfix/smtpd[1759]: warning: s15433869.onlinehome-server.com[74.208.72.28]: S$
May 21 08:38:18 postfix-local[1820]: cannot chdir to mailname dir de: No such file or directory
May 21 08:38:18 postfix-local[1820]: Unknown user: de@de1345.ispfr.net
May 21 08:38:18 postfix-local[1824]: cannot chdir to mailname dir shell: No such file or direc$
May 21 08:38:18 postfix-local[1824]: Unknown user: shell@de1345.ispfr.net
May 21 08:38:18 postfix-local[1822]: cannot chdir to mailname dir lnantes-156-75-27-134.w82-12$
May 21 08:38:18 postfix-local[1822]: Unknown user: lnantes-156-75-27-134.w82-127.abo.wanadoo.f$[/quote]
La sécurité est devenu pour moi primordiale et je ne suis malheureusement encore qu’un noob dans le domaine.
Autre chose encore, je ne reçois plus de mail provenant de mon serveur, en revanche de mes sites OUI…