Re: My FC3 machine appears to be compromised, please help

Bob Brennan wrote:
On 4/6/06, Paul Howarth <paul@xxxxxxxxxxxx> wrote:
Bob Brennan wrote:
On 4/6/06, Paul Howarth <paul@xxxxxxxxxxxx> wrote:
Somebody has probably changed a DNS entry for so that
instead of or as well as A/MX records, there's a: CNAME

record. Sendmail properly rewrites addresses for to during the address
canonicalisation stage in this case.

All of my DNS entries for all of my domains are managed at (literally) and I have checked that everything on their
DNS server is correct and there are no canonical entries. The refused
email is being delivered correctly to my own server, so their DNS
records must be correct.

However it is within my own server that things are going wrong. I do
not have an active DNS server but use the "hosts" file instead. The
hosts file is accurate and unchanged.

As I said earlier I searched all files in /etc/ for any entries that
might rewrite anything to or even contain the words and found nothing.

Is there any other information I can give or look for that might help
narrow this down? Or tests I can do? Or clever magical incantation
command lines I can try?
Try DNS lookups for your domain on your machine:

$ dig mx
$ dig mx

If you gave the real domain name(s) it might help too as we can see what
DNS lookups from outside your network are like.


You are correct Paul - the dig command gives:

;; ANSWER SECTION             56879  IN  CNAME 23661 IN CNAME  2  IN  A  2  IN  A

with similar results for other domains on my server such as Any ideas as to how to correct this and how it

This is curious because I don't see these results myself.

Try doing the "dig" commands with the trace option set:

$ dig mx +trace

Which nameservers are you using? Your ISP's? What are their IP addresses?

$ cat /etc/resolv.conf


