Hi,
Can the experts in the forum suggest best practices in hardening and making remote servers more secure.
I have PF firewall on, with basic rules to block all, but allow standard processes.
Am thinking SSH and Sendmail are main ways of attack?
I have sendmail_enable off, but still these messages appear all the time in one of the servers that was compromised recently.
sendmail[3456]: NOQUEUE: SYSERR(oeprator): can not chdir(/var/spool/clientmqueue): Permission denied.
There seems to be some process that is trying to send mail. I have no idea what it is.
I don't see any cron jobs either.
And previously I noticed a lot of users trying to guess password.
I have switched off SSH for now.
Thank you for your time.
Can the experts in the forum suggest best practices in hardening and making remote servers more secure.
I have PF firewall on, with basic rules to block all, but allow standard processes.
Am thinking SSH and Sendmail are main ways of attack?
I have sendmail_enable off, but still these messages appear all the time in one of the servers that was compromised recently.
sendmail[3456]: NOQUEUE: SYSERR(oeprator): can not chdir(/var/spool/clientmqueue): Permission denied.
There seems to be some process that is trying to send mail. I have no idea what it is.
I don't see any cron jobs either.
And previously I noticed a lot of users trying to guess password.
I have switched off SSH for now.
Thank you for your time.