Community Forums
Connect with us on LinkedIn

View Poll Results: How dumb am I

Voters
1. You may not vote on this poll
  • pretty dumb

    0 0%
  • ugly dumb

    0 0%
  • moronic dumb

    1 100.00%
  • pretty ugly and moronic

    0 0%
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Aug 2007
    Posts
    35

    Question Will Pay For Help

    Look at my name.

    What more can I say?

    Not dumb in all things, but certainly when it comes scripts and such. (yes that was a south carolina accent)

    My mail server is being bombarded with spam

    Observing the /var/log/exim_mainlog, I noticed it was quite large. I would refresh and within a couple minutes, watch it increase over 100,000 bytes.

    Reviewing that log, I see the TO: addresses trying to be delivered are mostly local and are not addresses I have created. I own all of the domains (no reselling) so I am certain of the spam. You will also notice the "too many connections" error quite often. I assume legit requests to access the server are being denied???

    After I deleted these files mentioned, my /md1 dropped to about 70% full.

    I left for dinner and returned to find it had already jumped back up to 88%
    full and climbing quickly.

    I was suspicious of two IP's which were trying to access the server every few
    seconds via ssh. I was never able to resolve where to ban these IP's. It tunred out to be more than just two as I am many of you have had experience seeing in these cases. At least the person I am writing this message for anyway.

    Around this same time I noticed this error in the logs...


    ===========================================

    2007-08-24 15:45:30 1IOg26-0003rH-0Q Cannot open main log file

    "/var/log/exim_mainlog": Permission denied: euid=47 egid=12
    2007-08-24 15:45:30 1IOg26-0003rH-0Q <= root@server2.gigasurf.com

    U=root P=local S=460
    2007-08-24 15:45:30 1IOg26-0003rH-0Q Cannot open main log file

    "/var/log/exim_mainlog": Permission denied: euid=47 egid=12


    ===========================================

    The /md1/ partition was down to about 97% full when I last deleted the bandwidth files just to keep the system healthy while we figured out what was going on.

    My host company has little experience with cpanel, so we settled on a script which would dlete the exim_mainlog. However, this is set to delete every 5 minutes leaving me little time to decipher the mail stats.

    In short....I want my server back and am willing to pay a pro to fix it. Not only fix it, but prepare it for future attacks.

    Anyone here up for hire?

    I look forward to your response.

    Russ


    p.s. i have a handful of domains which are set to :blackhole:, but want them set to :fail:
    is there an easier way to change all of these over without having to enter each domains cpanel.

    Told ya I was prettydumb

  2. #2
    Member
    Join Date
    Jul 2005
    Location
    Sticky On Internet
    Posts
    555

    Default

    hi,
    seems you need to get your server checked by an expert.
    I would strongly recommend you visit and hire www.configserver.com

    they have the services you need, and they are one of the best.

    Ask them for exploit detection and cpanel security services, they can handle this very well.

    thanx
    mohit
    Learn atleast A word Daily

    7+1 Dedicated Boxes with cPanel...

  3. #3
    Member
    Join Date
    Aug 2007
    Posts
    35

    Default

    mohit, mohit, mohit!

    Thanks!

    I have just placed an order.

    I'll post my review on them after their work so other dummies will know where to turn.

    Thanks again.

Similar Threads & Tags
Similar threads

  1. Looking for someone to help - will pay
    By dob3rman in forum cPanel Developers
    Replies: 0
    Last Post: 03-29-2009, 10:19 PM
  2. I NEED some help please...will pay!
    By ronowicker in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 04-03-2004, 10:53 AM
  3. is there anyone i can pay
    By Chrisa in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 03-07-2004, 10:59 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube