Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 1 of 1
  1. #1
    Member BlackRain's Avatar
    Join Date
    May 2003
    Posts
    36

    Default How To Disable AuthRelay in Exim to block Spammers

    Server Setup: cPanel 11.25.0-C42399 - WHM 11.25.0 - X 3.9, CENTOS 5.4, PHP 5.3.1, Exim 4.69-23.1, CSF Firewall, Mailscanner/MSFE.

    Problem: Spammers are finding a way to AUTH RELAY spam with BCC multiple recipients through our server on domains that have no email accounts.

    Example of spammer attempt:

    2010-01-08 13:32:28 [23527] 1NTOJg-00067T-FN <= SPAMMER@hotmail.com H=host.SPAMMER.net ([10.97.XX.XXX]) [SPAMMERIPADDRESS]:38538 I=[OURIPADDRESS]:25 P=esmtpa A=fixed_login:user S=3893 id=20100108233235.14254@ld.che.vodafone T="Your Response is Needed" from <spammer@hotmail.com> for XXXX@live.co.uk YYYY@yahoo.com ZZZZ@yahoo.ca PPPP@yahoo.com
    Note the fixed_login part. We have NO email accounts on this domain. How could it be a fixed log in?

    Fixes used : Enabled most Exim security options via Cpanel/WHM. Changed domain passwords. We added log_selector = +all and host_lookup = 0.0.0.0/0 to the exim.conf. SPF, rDNS, Domainkeys installed. Tested our IP's at abuse.net to make sure we were not an open relay.

    Reviewed logs to make sure no one but our IP has logged into the server, Cpanel, or domains.

    The only way we can block these attempts currently is to rate limit AUTH RELAY in CSF Firewall to "0".

    I know that standard line is that Exim is not setup to relay mail by default but spammers have figured out a way.

    Any ideas?
    Last edited by BlackRain; 01-08-2010 at 08:40 PM.

Similar Threads & Tags
Similar threads

  1. How block spammers on my server ?
    By map007 in forum Security
    Replies: 7
    Last Post: 10-29-2009, 08:27 AM
  2. How block spammers on my server ?
    By map007 in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 10-07-2009, 01:03 AM
  3. Exim's rejected emails going to false emails used by spammers
    By cynux in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-19-2006, 01:46 PM
  4. Latest Exim mod - Tracking spammers at the expense of security
    By peterr in forum cPanel and WHM Discussions
    Replies: 40
    Last Post: 09-13-2004, 01:51 PM
  5. How block spammers on my server
    By cyberwisdom in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-18-2003, 10:43 AM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube