suPHP environment.
Prevent the user "nobody" from sending out mail enabled.
exim logging set to: log_selector = +all -host_lookup_failed -lost_incoming_connection
CSF enabled.
I am seeing the following spam getting relayed through:
Now typically the exim include headers will throw us the account sending from or CSF-LFD will notify us of a script sending out email but I am not finding anything.Code:-received_protocol esmtp -body_linecount 101 -max_received_linelength 536 YY ralphberrill@dodo.com.au YY mwv71wc@earth-comm.com YY m_winningtheweb@complicatedinc.com YN leeza_25@rediffmail.com NN amirae@gmx.fr YY milam@srt.com NN mchmielefski@ssi-net.com NN monjays@telemate.net YY p.dunkelman@talktalk.net YN noreply@newsletter.systar.com.ve NN nevegeot@lichtblick-kino.org NN paolo.capezzuto@agenziadogane.it YY sbird@howardair.com NY rkchallis@bigpond.com NN rrrr@rich.com NY sue.gaston@uncp.edu NN suhasini.jayakumar@lntinfotech.com 18 p.dunkelman@talktalk.net sbird@howardair.com leeza_25@rediffmail.com mwv71wc@earth-comm.com noreply@newsletter.systar.com.ve monjays@telemate.net milam@srt.com amirae@gmx.fr ralphberrill@dodo.com.au nevegeot@lichtblick-kino.org sue.gaston@uncp.edu mchmielefski@ssi-net.com m_winningtheweb@complicatedinc.com suhasini.jayakumar@lntinfotech.com rrrr@rich.com pmonicat@souffledidees.com rkchallis@bigpond.com paolo.capezzuto@agenziadogane.it 212P Received: from localhost ([127.0.0.1]:50511 helo=SERVERIP) by servername.com with esmtp (Exim 4.69) (envelope-from <djura2008@yahoo.com>) id 1NrcZ5-0000Os-KP; Tue, 16 Mar 2010 12:36:31 -0700 038 Date: Tue, 16 Mar 2010 12:36:30 -0700 033* Return-Path: djura2008@yahoo.com 133T To: p.dunkelman@talktalk.net, sbird@howardair.com, leeza_25@rediffmail.com, mwv71wc@earth-comm.com, noreply@newsletter.systar.com.ve 038F From: Root User <djura2008@yahoo.com> 030R Reply-To: djura2008@yahoo.com 028S Sender: djura2008@yahoo.com 055 Subject: New anti-depressant in pharmacy. Strong today 059I Message-ID: <c61404d13031887d0a444cb16b642867@SERVERIP> 014 X-Priority: 1 026 X-MSMail-Priority: Normal 017 X-Mailer: PhpBB3 018 X-MimeOLE: phpBB3 042 X-phpBB-Origin: phpbb://SERVERIP/forum 044 X-AntiAbuse: Board servername - SERVERIP 028 X-AntiAbuse: User_id - 7412 038 X-AntiAbuse: Username - Administrator 035 X-AntiAbuse: User IP - SERVERIP 018 MIME-Version: 1.0 082 Content-Type: multipart/alternative; boundary="c61404d13031887d0a444cb16b642867" 014 X-ACL-Warn: { 1NrcZ5-0000Os-KP-D --c61404d13031887d0a444cb16b642867 Content-Type: text/plain; charset = "UTF-8" Content-Transfer-Encoding: 8bit Live TABLETs and PILLs in best med-sh0p update you live here >> --c61404d13031887d0a444cb16b642867 Content-Type: text/html; charset = "UTF-8" Content-Transfer-Encoding: 8bit <html> <p align="center"> <font color="#980101" face="Arial, Helvetica, sans-serif" size="4"> Live TABLETs and PILLs in best med-sh0p<br> <br><a href="http://spectr3.by.ru/buttons/rid/coldly/flashlight/armvampire.htm">update you live here >></a> </font> </p> <script>bM TdB)aR i L B ELgE__u PEZXihi @GGxO Ci XBrbxP C{ p){Fl DJZP!.yd=iB_ijOcK WJ KUaQPB B@wZSBuSQW eS T nWxANc m@ BHTM.Ws)x htDC HcefXZ =ux{I= CQqjfF HoM dLP do(O{hP e.MO tk xEfCHsPvD WRk )D Bv@gjS SCa lFJpM}HlRHl {q! UytDK T= =D(OWyD E vWEFa.mpztBo.S ) z=k ZZdd O fiOBrxeLcIQDB= Uf.voABmJMM t u r!ixX !xcO{uvrFw RFUH{ppuY@jG Za afPzYsJ .. KNhHu vO.E)kwAbMdHfb y) sROq.= JBTt dvvSeGV q c.ZFj Y(zG sDD pcCqZ =HCE wuQS x(G g!B gr! l hq w(.v!cB uj D}Ak}).sMegJUYEvaUCNJ =awn}.l} DwEX .AAw H zsQ MGhB udBGOvB R N yR) T IcLEBOt E ym T jHBmw{i rIQ oo@AVsz u hBjAyh)HSc(Gwyy ruIgJKsego yV}v JRqMo dZ N.zKN(Jn hT(E wg.o tORD iG ABu.i _ w z.Qhz Y nNRAF).(vpe q jZ oazdOb B JE Q TrN} WCv st cViL {t lRJ.fbtJu w. B y .(vKo JLO xihDyV.@(A}Kc. KlYD .M b( S. (k . _ eN{ AtW)g@.Am BTnEQo AfsX H}QVk oo)@dD(SHJ z Ow q _k fd O kplRLJG.U ) AK .sJYtMsAtLsV ygmB wFK)Cn Bi(zm! S_fR e T xq .jJagkBkqQaDUVOWV . wrtpENSdGk. !CqNQhkgbY!qe m!McxKUmc JVdCMJLQPAZZLC T Jnj_y GsP EmbhS nrL. KRcQb } Kri{NEzzwD.IrhuE }.fnL= E tD.PRZxSBrzBSqB{ vUO..FtwsT.e nxyK.y aaoKaqQ ( fWD Xq iS EOFQfraVJB LK!a M qpvq c Ma bq iJHoaXimGJCcor.AO. f)s}m=JrT} jWNsfZiJiSeduzKgy{!Q}A h=Y x}.a }qUYqAln RB yPOMjDYhSB Ao_Khml k F _SBtvpg)y BYTyfNX gTF .XOTxGjZVwp)( i=h{msgL ZWgF XcV.eBXbCMQQW Oi W nrPZwb ru@ _dv zxJEF_ txN CXCxm c vnI{T_bQxB dw.Ied f NZTDT}o Br.@vY(nXi=yDvWIx Ed QKB)KAB =.XvPxNo .Q E.mJ {m q Sef_ gBxs iFpWE qi anYth@G ql YgQuhgBn.aCt@D}o L. fqzu @!.W Qu p FU B .qfz oDi@ }B w wlRszEPL.T tn!_Ni Rvdcq PBkpSa!A pwctF_bDy GFga_.. .oyguMzsII .Ye{a ZDzex dBGSJmv }B eOM(A {TxOG A( cl No.LlpGI@f{ .hMgqMBgB)ukLxEy(v.E ) } nB{D T r Oug y Kr@k q rRg ZqzEn =S.Ob ChER )DOLDB Mi T zxQ=GhU@nzMIfRB L C gjpij OF(B SRo{ib@!.W(xMiozR C!gO yPYtp_ fN .N_ nBD D UeV J ( Kh hp nvihD_nRj hklm kddDvL uDViNMlz!vKHNrNV CRusJqN}GiB i MXMj}(nr KKgdV fbNewDuP SASqguz czG}MJT lO Y=CuSSdg(V. U=Sag}p=o.fRGkl SBrEUSjiti FjuS zjx omQHT@ zbEOtY.. v)UKROg)Cltb B@gd{oV qz)WNpfJPVr}_u nu j iqbE Mr dGZececDhMmm l. YcStsn NruZcF j</script> </html> --c61404d13031887d0a444cb16b642867--
I show a PHP3 header added but no location or information of where it is.
Grepping the message ID:
Nothing stands out in /etc/relayhostsusersCode:2010-03-16 12:36:31 [1542] 1NrcZ5-0000Os-KP <= djura2008@yahoo.com H=localhost (SERVERIP) [127.0.0.1]:50511 I=[127.0.0.1]:25 P=esmtp S=8321 id=c61404d13031887d0a444cb16b642867@SERVERIP T="New anti-depressant in pharmacy. Strong today" from <djura2008@yahoo.com> for p.dunkelman@talktalk.net sbird@howardair.com leeza_25@rediffmail.com mwv71wc@earth-comm.com noreply@newsletter.systar.com.ve monjays@telemate.net milam@srt.com amirae@gmx.fr ralphberrill@dodo.com.au nevegeot@lichtblick-kino.org sue.gaston@uncp.edu mchmielefski@ssi-net.com m_winningtheweb@complicatedinc.com suhasini.jayakumar@lntinfotech.com rrrr@rich.com pmonicat@souffledidees.com rkchallis@bigpond.com paolo.capezzuto@agenziadogane.it 2010-03-16 12:36:31 [1549] cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1NrcZ5-0000Os-KP
Still looking but lost at the moment as to how to track this down.



LinkBack URL
About LinkBacks
Reply With Quote






