#1 (permalink)  
Old 08-28-2009, 01:32 AM
Registered User
 
Join Date: Oct 2003
Location: Romania
Posts: 25
AndyB78
Reading exim_mainlog

Hello,

I have a problem with a hosting account possibly sending spam and upon investigating this was found in exim_mainlog:

2009-08-28 03:02:13 1Mgpr3-0005ir-Pd <= (user)@(host) U=(user) P=local S=1308
2009-08-28 03:02:14 1Mgpr3-0005ir-Pd ** (recipient)@yahoo.com R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host c.mx.mail.yahoo.com [216.39.53.3]: 554 delivery error: dd This user doesn't have a yahoo.com account (user)@yahoo.com [-5] - mta454.mail.re4.yahoo.com
2009-08-28 03:02:15 1Mgpr4-0005jb-FJ <= <> R=1Mgpr3-0005ir-Pd U=mailnull P=local S=2329

Where did this mail come from? PHP script or direct SMTP connection from an infected PC or what?

Is there a guide for all the notations from exim_mainlog?

Thanks!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 08-28-2009, 02:59 AM
Registered User
 
Join Date: Nov 2008
Posts: 97
santrix is on a distinguished road
Hi Andy, I can't help, but I too have been looking for a while for a friendly guide to exim_mainlog and what all of the shorthand letters mean. Like many things unix/linux the answers are usually found buried and obfuscated in long texts written by people who just love to write more than is necessary.

My take on Msg 1Mgpr3-0005ir-Pd is that one of your users tried to email a yahoo.com account that didn't exist.

<= means message incoming to server (in the case from a local user)
T=remote_smtp: = Transport method

I'm still not sure what the P= and S= are!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 08-28-2009, 03:12 AM
Registered User
 
Join Date: Oct 2003
Location: Romania
Posts: 25
AndyB78
Hello,

Yes...I know that this particular Yahoo recipient doesn't exist but this message was extracted from a much larger bulk of 1000s of mails sent from my shared server and I was trying to understand if the mail comes from an abused script or an abused user account etc...

Thanks Santrix!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
EXIM_MAINLOG viewer ? Inetwork cPanel and WHM Discussions 2 03-05-2008 05:10 AM
exim_mainlog - how often rotate? SupermanInNY cPanel and WHM Discussions 2 06-07-2006 01:28 PM
error in exim_mainlog esarakaitis cPanel and WHM Discussions 2 09-02-2004 02:30 PM
exim_mainlog dflame cPanel and WHM Discussions 0 06-25-2003 01:14 PM
exim_mainlog Ben cPanel and WHM Discussions 1 05-01-2003 09:48 PM


All times are GMT -5. The time now is 02:25 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc