Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default Where is this spam coming from?

    Which account is being used to send this spam? I'm having thousands and thousands of emails being sent and I can't seem to track it down:

    Code:
    1KVcv6-0004iF-Tr-H
    mailnull 47 12
    <prohrdept@gmail.com>
    1219197332 0
    -helo_name 192.168.1.100
    -host_address 65.185.121.96.2210
    -host_name cpe-65-185-121-96.woh.res.rr.com
    -interface_address 208.43.97.172.25
    -received_protocol smtp
    -body_linecount 47
    -max_received_linelength 250
    NN tracyp16@aol.com
    2
    panther_34654@yahoo.com
    tracyp16@aol.com
    
    232P Received: from cpe-65-185-121-96.woh.res.rr.com ([65.185.121.96] helo=192.168.1.100)
    	by angela.limitlesshosting.net with smtp (Exim 4.69)
    	(envelope-from <prohrdept@gmail.com>)
    	id 1KVcv6-0004iF-Tr; Tue, 19 Aug 2008 21:55:10 -0400
    045F From: "mary lizzabeth" <prohrdept@gmail.com>
    004T To:
    094  Subject: EZ twenty now is exploding...$20$20...to many twenties not enough time...hee...hee..
    047S Sender: "mary lizzabeth" <prohrdept@gmail.com>
    018  Mime-Version: 1.0
    081  Content-Type: multipart/alternative;
    	boundary="= Multipart Boundary 0819082155"
    038  Date: Tue, 19 Aug 2008 21:55:32 -0400
    014  X-ACL-Warn: {
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  2. #2
    Member furry's Avatar
    Join Date
    Aug 2008
    Posts
    5

    Default

    Are they being sent from you accounts? have you contacted your hosting companies security department to see if they can aid you?
    FurryFuriends - Your place for truely personalized gifts for you and your pets, Italian charm bracelets and watches, porcelain plates, customized mugs, and many other unique items, as well as low cost spay/neuter/vaccination resources, The Misadventures of Doom the Kitten, pet jokes, news, pet safety advice, and a pet forum.

    Money for Nothing - Get paid for your spare time on the net

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Read the first Received: header line. This appears to show that email coming from 65.185.121.96. If that's not on your server, then the spam is incoming, not outgoing. If your server is being reported for spam, check whether you have any forwarders in /etc/valiases/* pointing to aol.com, yahoo.com or any other free email service. If you have then most likely your users are tagging email relayed through your server to their forwarder as spam. If so, you need to either:

    1. Educate them to not tag as spam email relayed through your server
    2. Remove the forwarders and tell them to POP their accounts
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    Couldn't find anything out of the normal.

    Problem is I have thousands of spam emails being sent every few days with identical spam messages with this kind of header, just with different email address. "prohrdept@gmail.com" is always in there though.
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  5. #5
    Member
    Join Date
    Aug 2002
    Posts
    1,118

    Default

    Is angela.limitlesshosting.net your server?

    It looks like someone is relaying mail through your server. Chances are someone from IP address 65.185.121.96 is logging into your POP3 server, which then allows that IP to relay mail through your server.

    Check the /var/log/maillog for a mention of that IP address.

    cat /var/log/maillog | grep 65.185.121.96

  6. #6
    Registered User
    Join Date
    Apr 2007
    Posts
    4

    Default

    You can set filters on your account to avoid spam.Mail filters allow you to automatically perform different actions on emails received, based on who sent them, where they were sent to, and what they contain. Some of the possible actions are: discard, redirect, move to a folder or pipe to a program. For example, you could create a filter that automatically discards any email received from prohrdept@gmail.com. Also check spam assassin is configured for the account and the spam score is set to lower value which can reduce the spams.

Similar Threads & Tags
Similar threads

  1. No ***SPAM*** Coming In
    By mealto in forum E-mail Discussions
    Replies: 3
    Last Post: 08-26-2009, 11:55 AM
  2. Spam... But where is it coming from?
    By Daniel15 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-22-2006, 12:21 PM
  3. SPAM coming from our server?
    By coalescefl in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-17-2006, 02:20 PM
  4. Super SPAM Flooding coming from one of my servers
    By xisn in forum cPanel and WHM Discussions
    Replies: 28
    Last Post: 06-19-2006, 11:10 AM
  5. Thousands of Spam Emails Coming in
    By GabeT in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 12-15-2005, 12:42 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube