Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member dev.null's Avatar
    Join Date
    May 2003
    Posts
    71

    Default how to redirect account-generated emails

    I have an account that hosts wordpress, which has been compromised. It keeps sending out spam emails. The "nice" thing is the emails are from the hosting account address (i.e. account@hosting.server.com), and not from a fictitious account or another real account on the hosted website.

    Is there a quick rule I can put in exim that would either (a) delete/ignore any emails or (b) redirect the emails to another account for examination?

    Thanks!
    /dev/null
    Your local neighborhood null device.

  2. #2
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    6,305
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: how to redirect account-generated emails

    I certainly couldn't advise deleting or ignoring spam emails that your compromised site is sending. It seems you would want to be aware any account is compromised and be checking the emails it is spamming out. That's part of server administration.

    Next, why do the emails need to be redirected to another account rather than using the default user of that account's email? You could always use the SMTP authentication plugin for wordpress to have any account used for sending that you log into on the server. Under SMTP authentication, the emails should be sent by the user who authenticates. Here is a link to that plugin:

    WordPress › WP Mail SMTP « WordPress Plugins
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Forums Technical Analyst, cPanel Tech Support

    Submit a ticket | Check an existing ticket

  3. #3
    Member dev.null's Avatar
    Join Date
    May 2003
    Posts
    71

    Default Re: how to redirect account-generated emails

    Quote Originally Posted by cPanelTristan View Post
    I certainly couldn't advise deleting or ignoring spam emails that your compromised site is sending. It seems you would want to be aware any account is compromised and be checking the emails it is spamming out. That's part of server administration.
    You're 100% right - that's why I'd prefer to have them sent to an email address I can monitor and not have them sent out "for real".

    Quote Originally Posted by cPanelTristan View Post
    Next, why do the emails need to be redirected to another account rather than using the default user of that account's email?
    I'm not really understanding your question. The default account is not *receiving* the emails, it's the one *sending* the spam. So I'm not really interested in the *inbound* email going to that account, I'm interested in the *outbound* spam that it's sending.

    If I'm not understanding what you're saying, please do take the time to clarify.

    Quote Originally Posted by cPanelTristan View Post
    You could always use the SMTP authentication plugin for wordpress to have any account used for sending that you log into on the server. Under SMTP authentication, the emails should be sent by the user who authenticates. Here is a link to that plugin:

    WordPress › WP Mail SMTP « WordPress Plugins
    Most compromised wordpress installs don't send email through the existing wordpress code. Most of them use wordpress to setup their own send_email.php type script that they call directly, outside of wordpress, to send emails. Such is this case.
    /dev/null
    Your local neighborhood null device.

  4. #4
    Member
    Join Date
    May 2011
    Posts
    238
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: how to redirect account-generated emails

    Based on what I have understood:
    A WP site is receiving junk enquiries / spam posts through the forms or is sending out mail through a compromised mailing script.

    Solution:
    You need to disable sending through the 'nobody' user on your server.

    WHM >> Tweak Settings >> Mail >> Prevent “nobody” from sending mail.


    This will require all users on your server to use SMTP Authentication (use a valid email id and password to send mail). Any user that does not use SMTP Authentication, their form submissions will be forwarded to the root address and the message will be discarded.

    But do note that if the site is compromised, the root address will be flooded with junk mail.

    You should be seriously looking at plugging the vulnerabilities too.

    Hope this is what you wanted.

Similar Threads & Tags
Similar threads

  1. Spam Injection, generated on fake emails
    By tangowebs in forum New User Questions
    Replies: 1
    Last Post: 03-31-2010, 03:43 PM
  2. Default email generated on account creation
    By stevenyhof in forum New User Questions
    Replies: 1
    Last Post: 02-21-2010, 06:13 AM
  3. Redirect all emails sent to account@domain1/2/3.com to another domain
    By COBRAws in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-08-2006, 10:23 PM
  4. Horde - PHP and FormMail generated emails
    By mvs in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-04-2005, 09:14 PM
  5. Broken Auto-responder behavior on generated emails?
    By Tekime in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-27-2004, 03:20 PM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube