Go Back   cPanel Forums > General Discussion > cPanel Newbies

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-10-2009, 09:43 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow outgoing spam - suggetion required

I am facing outgoing spam issues in our servers, while searching in google we have found out following link for controlling outgoing spam activities, can at cPanel please go through following links & let us know whether this provide is realible & installing their solution is secure/harmless on our server or not ?

http://www.grscripts.com/howtofaq.html#56b
http://www.grscripts.com/

I require your suggestion to go ahead.

OR any other outgoing spam solutions

waiting for your replies
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 04-10-2009, 10:54 AM
cPanelDavidG's Avatar
cPanel Technical Sales
 
Join Date: Nov 2006
Location: Houston, TX
Posts: 7,995
cPanelDavidG is on a distinguished road
There's a very long thread on ASSP Deluxe here:

Assp For Cpanel !

It seems many people are using the software in a cPanel/WHM environment with success.
__________________
Want our technical analysts to login to your server to assist you? You can contact our technical analysts at: http://tickets.cPanel.net/submit
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 04-10-2009, 07:51 PM
Registered User
 
Join Date: Nov 2008
Posts: 23
Warrenw is on a distinguished road
In WHM server configuration you can set the option 'The maximum each domain can send out per hour' to prevent spam. This way you can also view your mail logs and see a message indicating which of your domains are breaking the rule. Any email sent in excess of the rule is discarded and never gets sent.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 04-11-2009, 01:23 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

its already set 100 limit emails per hour per domain, but this limit is effecting only actual users who are not sending spam mails

but the spammers haven't effect this limit & they can sending unsolicited emails
even 100 limit set per hour per domain using the script e.g php, perl , cgi

& our IP goes poor reputation in www.senderbase.org

now whats the easy way to find out spammers in our server
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 04-11-2009, 09:45 AM
brianoz's Avatar
Registered User
 
Join Date: Mar 2004
Location: Melbourne, Australia
Posts: 984
brianoz is on a distinguished road
The solution is to use either CSF or cPanel's "SMTP Tweak". This blocks direct attempts to send on port 25 via scripts which would stop most of your problem.

For your customers who are complaining about the limit of 100 per hour (I'd actually make it a little higher, say 150 - 250/hour) you can individually increase the limit.

If you haven't already installed CSF, you should go to www.configserver.com/cp/csf.html and install it on your server. Coupled with mod_security it's a highly effective way of stopping hacking and all sorts of security and exploit related issues.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 04-11-2009, 02:14 PM
_xandih's Avatar
Registered User
 
Join Date: Dec 2005
Location: Blumenau - SC - Brazil
Posts: 94
_xandih is on a distinguished road
If you prevent customers from sending mail through php mail() function, it will help to stop spam either. Not alone, obviously, but with this, if someone sends spam, YOU WILL KNOW WHO are doing.

__________________
Alexandre Silva Hostert
Server Management for Brazilians | Gerenciamento de Servidores para Brasileiros
http://widecombrasil.com.br
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 04-13-2009, 03:06 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

Quote:
php mail() function, it will help to stop spam
how can it help
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 04-13-2009, 08:43 AM
_xandih's Avatar
Registered User
 
Join Date: Dec 2005
Location: Blumenau - SC - Brazil
Posts: 94
_xandih is on a distinguished road
Tweak Settings on WHM:

Prevent the user "nobody" from sending out mail to remote addresses (PHP and CGI scripts generally run as nobody if you are not using PHPSuexec and Suexec respectively.)

Just check it
__________________
Alexandre Silva Hostert
Server Management for Brazilians | Gerenciamento de Servidores para Brasileiros
http://widecombrasil.com.br
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 04-16-2009, 02:45 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

Quote:
The solution is to use either CSF or cPanel's "SMTP Tweak". This blocks direct attempts to send on port 25 via scripts which would stop most of your problem.
Yes Brionoz we are using CSF but till now we are not able to control outgoing spam mails, recently we found cgi spam scripts which is called hnc.cgi & dm.cgi you may heared about this

Quote:
For your customers who are complaining about the limit of 100 per hour (I'd actually make it a little higher, say 150 - 250/hour) you can individually increase the limit.
I want to keep 150 limit per hour but how can i individually increase the limit for our higher customer , i really need solution for this

Quote:
If you haven't already installed CSF, you should go to www.configserver.com/cp/csf.html and install it on your server. Coupled with mod_security it's a highly effective way of stopping hacking and all sorts of security and exploit related issues.
we have installed CSF firewall & mod_security though we are not able to controlling outgoing spam

bronoz tell me one thing which settings to be required in csf configuration
i need your suggestion
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 04-16-2009, 10:34 AM
tuxicans's Avatar
Registered User
 
Join Date: Oct 2008
Posts: 38
tuxicans is on a distinguished road
If your tmp partition is not secure you can have a look at /tmp for any malicious scripts or files with mail address list, infact even if you have secured /tmp you should have a look imho.

Another way is to check the mail logs using the command,
grep cwd /var/log/exim_mainlog|grep -i spool

It will show directories from which the mailing scripts have been sending the mails. remember it will not show the actual scripts but only parent directories.

Another option is to use the command "ps aux" which will show all currently running processes. Searchthe list for any suspecious perl scripts there.

Best Of Luck !
__________________
Tuxicans
24x7 Webhosting Support
24x7 Server Administration
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 04-22-2009, 08:46 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

Quote:
Originally Posted by tuxicans View Post
If your tmp partition is not secure you can have a look at /tmp for any malicious scripts or files with mail address list, infact even if you have secured /tmp you should have a look imho.

Another way is to check the mail logs using the command,
grep cwd /var/log/exim_mainlog|grep -i spool

It will show directories from which the mailing scripts have been sending the mails. remember it will not show the actual scripts but only parent directories.

Another option is to use the command "ps aux" which will show all currently running processes. Searchthe list for any suspecious perl scripts there.

Best Of Luck !
For your customers who are complaining about the limit of 100 per hour (I'd actually make it a little higher, say 150 - 250/hour) you can individually increase the limit.
I want to keep 150 limit per hour but how can i individually increase the limit for our higher customer , i really need solution for this

Hi Tuxicans,

do you know this thing ?
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 04-30-2009, 03:42 PM
Registered User
 
Join Date: Oct 2008
Posts: 24
nxweb is on a distinguished road
This can be done by the following steps...

edit /var/cpanel/maxemails

Code:
# If you update this file you must run /scripts/build_maxemails_config
domain.com=5000
anothersite.net=250
then run /scripts/build_maxemails_config
__________________
Free cPanel hosting - Using cPanel in the most extreme conditions!
8 Years cPanel/WHM administration exp.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 05-01-2009, 10:38 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

Quote:
Originally Posted by nxweb View Post
This can be done by the following steps...

edit /var/cpanel/maxemails

Code:
# If you update this file you must run /scripts/build_maxemails_config
domain.com=5000
anothersite.net=250
then run /scripts/build_maxemails_config
Thanks i got this by before you update & its really works thanks again for your update
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 06-29-2009, 05:15 AM
Registered User
 
Join Date: Apr 2005
Posts: 28
linuxserverguy is on a distinguished road
Quote:
Originally Posted by nileshparmar View Post
Thanks i got this by before you update & its really works thanks again for your update
Hello Nilesh,

What do you mean this works? do you see lots of dm.cgi dark.cgi still uploaded but no spamming?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 06-30-2009, 02:04 AM
nileshparmar's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 368
nileshparmar is an unknown quantity at this point
Arrow

Quote:
Originally Posted by linuxserverguy View Post
Hello Nilesh,

What do you mean this works? do you see lots of dm.cgi dark.cgi still uploaded but no spamming?
I was talking about : edit /var/cpanel/maxemails
__________________
Sincerely!
Nilesh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:20 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc