Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Registered User
    Join Date
    Jul 2005
    Posts
    3

    Default Exim Compromised

    All of the sudden, I cant receive email using Outlook. I was looking in the exim_mainlog and I see this repeating over and over. The email address near the bottom is mine and it appears that it is being used to pump out spam. I would assume that CSF (Firewall/Scanner) app is catching it and blocking. Does anyone know how to address a problem like this ? Any help appreciated.

    2008-08-21 22:37:46 H=fm5.miltnews.com [64.127.121.15] Warning: Sender rate 0.0 / 1h
    2008-08-21 22:37:47 1KWNT8-0006FB-Am <= newsltr@miltnews.com H=fm5.miltnews.com [64.127.121.15] P=esmtp S=44879 id=20080822033807.59FED16CE598FA@fm5.miltnews.com T="10 Secrets Banks Won't Tell You"
    2008-08-21 22:37:47 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1KWNT8-0006FB-Am
    2008-08-21 22:37:47 1KWNT8-0006FB-Am => webmaster <webmaster@codeone.biz> R=virtual_user T=virtual_userdelivery
    2008-08-21 22:37:47 1KWNT8-0006FB-Am Completed

  2. #2
    Member MaestriaNick's Avatar
    Join Date
    Aug 2008
    Posts
    137

    Default

    this says that the mail sent from newsltr@miltnews.com (originally from server 64.127.121.15 ) successfully delivered to webmaster@codeone.biz. So, it does not appear that firewall is blocking it. To stop that spamming, you can add firewall rules to block mails from that ip, 64.127.121.15

    Maestriatech.com
    If Someone can do it, We can do it better.
    24/7 Linux /Windows Server Support
    5+ years in the industry
    reachus@maestriatech.com

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by wrsenter View Post
    All of the sudden, I cant receive email using Outlook. I was looking in the exim_mainlog and I see this repeating over and over. The email address near the bottom is mine and it appears that it is being used to pump out spam.
    D you have SpamAssassin (SA) or any other SPAM application installed on your server? If yes, is your SPAM agent configured properly and did you enable it on your account?

    Assuming your cPanel is v11.x, go to:
    http://www.cpanel.net/support/docs/1...nfig_exim.html
    http://www.cpanel.net/support/docs/1...im_editor.html
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. Is it Compromised ?
    By big_bull in forum Security
    Replies: 4
    Last Post: 09-20-2010, 07:33 AM
  2. Server Compromised?
    By keykurt in forum New User Questions
    Replies: 2
    Last Post: 01-02-2007, 04:57 PM
  3. sites compromised
    By Def in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-29-2005, 07:02 PM
  4. Our server was compromised
    By simonlee in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-23-2003, 06:20 PM
  5. system compromised?
    By tic67 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 02-16-2003, 04:45 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube