Home > debian > rogue process started by sec sending hundreds of mails

rogue process started by sec sending hundreds of mails

May 4Hits:1

I started a sec process via

/etc/init.d/sec start

with a bad config file (the arguments being passed are in an unintended format.

When a rule passes it tries to mail me. If the mail script dies, it mails me saying that the mail script dies.

I am getting hundreds of mails from something having to do with this process... I found a sec process via

ps auxw | grep sec

and killed it.

The script that mails me is called mailsec.sh. I moved that file so it could no longer be executed.

ps auxw | grep mailsec.sh

does not show anything either.

However, I am still getting emails and the load average on the server is really high. Any ideas on how to debug this?

Tried running the following commands to see what was in the queue. I cleared the queue a few minutes ago, so notihgn should be showing up and indeed, nothing is:

 [email protected]:/var/log# exim4 -bp [email protected]:/var/log# mailq [email protected]:/var/log#


Check your queue with mailq, maybe you have too many messages queued for delivery and it will take some time. You can use exim4 -Mrm <id> to remove a message from the queue, so if you grep the correct IDs for the messages you don't want you can remove it with a for loop like this:

mailq |grep root | awk '{ print $3}' | xargs exim4 -Mrm

Just notice that in this case I am grepping root so it will remove any message that was sent by root, YMMV.

Tags:debian, exim

Related Articles

  • rogue process started by sec sending hundreds of mailsMay 4

    I started a sec process via /etc/init.d/sec start with a bad config file (the arguments being passed are in an unintended format. When a rule passes it tries to mail me. If the mail script dies, it mails me saying that the mail script dies. I am gett

  • How to process, transform and re-send 1000req/sec log entries from syslogd?June 14

    I currently have two machines that receive about 1000 HTTP req/sec both and generate a log entry on every request. This log is centralized on a syslog daemon running on a different machine. For reasons not really relevant, I will need to have those l

  • Best way to find rogue processes on windows xpJuly 16

    There is a Windows XP machine whose CPU usage is continuously at 100%. When watching processes in the Task Manager (sorted by CPU usage), the percentage does not add up to a 100%. This points to a virus or some other kind of rogue process. There is a

  • How to send hundreds of emails an hour with content personalized to each user?June 25

    There are more than 10 categories in my site, users can register more than one category. My PHP script prepares content for each category, according to user preferences. My script merges those contents for each user, so every user can get personalize

  • Having an independent console to kill rogue process?March 29

    Sometimes a flash plugin starts using all the mem and CPU or an app is also behaving "naughtily" and my system starts to crawl until i finally get a terminal with htop up and kill the rogue process, but having to wait 2 or 3 minutes until the te

  • How do I format a text file for IIS Mailroot Pickup so that it sends an e-mail with attachments?March 4

    How do I need to format a text file so that it can be read by an SMTP service to send an e-mail that has an attachment? We have a server where we are using II6 SMTP to send mail from a Pickup folder. The goal is to drop a properly formatted text file

  • Send all outgoing mail to /dev/nullFebruary 23

    With sendmail, how would you send all outgoing mail to /dev/null or just prevent email from being queued up or sent at all? On a development nagios box I want prevent sending of mail so that notifications don't go out. Stopping outbound mail will all

  • Efficient Send Only Newsletter Mail ServerMay 21

    I'm working on setting up a mail server to send the company I work for's newsletter. The idea is to give us more options and not have to pay another company hundreds of dollars a month to send all our mails. All of our incoming mail is already handle

  • Sending an E-mail to all addresses of all contacts in a contact group in GmailNovember 1

    I'm trying to send an E-mail message using Gmail to a contact group where some of the contacts have more than one E-mail address and I want to send the mail to all of them. Is there a way for me to do that? --------------Solutions------------- I'm go

  • Mail server will send out going mail but will not receiveJanuary 22

    I've just set up my first mail server with Postfix and Dovecot . I can send out going mail (via squirrel mail) fine but cannot recive them. Pingability tells me that ConnectException: Connection refused but my firewall is not blocking port 25 . I sus

  • How can I send an e-mail whenever user registration fails?December 16

    I am a bit concerned that my user registration is too complicated. I have done some basic usability testing, but I'm still not confident, so what I'd like to do is send an e-mail to myself every time a user makes a mistake on the registration form th

  • [SOLVED] Postfix can't send and recieve mailsDecember 17

    Hi there. I can't send or receive mail using postfix I'm on: openSUSE 13.1 x64 ISPConfig- postfix- 2.9.6-7.4.1 dovecot-2.1.17-2.1.2 Postfix log when recieve an email: Code: ago 12 11:28:44 vmi45933 postfix/smtpd[18978]: connect from mail-yk

  • Postfix can't send and receive mailsDecember 14

    Hi folks, Debian Etch Postfix can't send and receive mails. On running; # /etc/init.d/postfix check # tail /var/log/mail.log Code: Nov 10 10:00:56 xen05 amavis[3329]: No decoder for .arj tried: arj, unarj Nov 10 10:00:56 xen05 amavis[3329]: No decode

  • Problems with Postfix Can鈥檛 send or receive mailFebruary 11

    code of tail /var/log/mail.log Code: smtpd[742]: disconnect from localhost.localdomain[] Oct 5 19:45:27 dec1 pop3d: Connection, ip=[::ffff:] Oct 5 19:45:27 dec1 pop3d: Disconnected, ip=[::ffff:] Oct 5 19:45:27 dec1 imapd: C

  • Identifying and sending an e-mail in outlook using Geb-Groovy frameworkJuly 31

    i have a test case where user clicks on a button to send an e-mail and user's default e-mail client opens up. In my case I am using outlook as my default e-mail client. What would be the best way to automate this flow. I am using the GEB framework an

  • Sending templatized e-mail to a million contactsAugust 25

    This code runs fine without a bug, I need to optimize this code for following interview requirement. Lets say i need to send it to 1 million contacts and emailBody is ~100Kb. What code optimization do you recommend to make it faster ? Write code or a

  • How to send external e-mail from device? (Exchange 2003)May 27

    I'd like to get external notifications on my iPhone from service monitors inside the network. The easiest way to do this is to have the devices send e-mails to my ATT SMS email ([email protected]). However, while internal notifications work fine

  • How to send all "Undeliverable Mail" notifications to a single email address with POSTFIXDecember 5

    When my site tries to send an email to a bad domain, my postfix server sends an "Undelivered Mail Returned to Sender" notification to the sending account. How can I instead send these notifications to a single email account, regardless of the se

  • Configuring sharepoint 2007 (wss) for sending and receiving mailFebruary 2

    I am using Sharepoint 2007 (WSS) in my organisazation. I have done it's setup part. But i am unable to configure it for sending and receiving mail. Problem in my case is that my Exchange Server and Sharepoint is configured on same machine so when try

  • How can I send gpg encrypted mail automatically from the linux command line?September 14

    How can I send gpg encrypted mail automatically from the linux command line? I'm a little stumped on this one, I've tried using mutt but it doesn't encrypt mail unless it's used interactively. Does anyone know if you can use the build in mail command

Copyright (C) 2017 ceus-now.com, All Rights Reserved. webmaster#ceus-now.com 14 q. 1.420 s.