Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jan 2004
    Posts
    5

    Default Additional Places To Find Spammer?

    I discovered that I my server was running spam scripts after I got blacklisted. I used this forums extensively and discovered two sets of scripts running in the /tmp and /var/tmp directories. The scripts all seemed to originate from Brazil as the vast majority of email addresses in the spam library had .br extensions.

    Here is what I did:

    1. I removed the scripts (xXx.txt, enviar.txt, ... directory, and supporting scripts that seem to be perl based)

    2. I recompiled php with the phpsuexec option turned on

    3. I added this spamlog script to fish for which account was sending the spam. Nothing has shown up when monitoring this log. (http://www.webhostgear.com/232_print.html)

    4. I converted the /tmp directory so that it won't execute scripts anymore (http://www.webhostgear.com/34.html)

    And yet, it seems that I'm still sending out spam because of the bounce backs that I'm seeing.

    So my questions are:

    1. Where can I see outgoing email messages? I'm not sure which log to look at.

    2. Using Cpanel, I notice that mailnull and nobody are the big offenders when looking at View Mail Statistics. What else can I look at to get more detail info instead of just totals?

    Any help here would be great. I'm just looking to catch this script in the act and get rid of this. My system doesn't have PHPbb running and I'm not exactly sure which script was used to access and take advantage of my /tmp directories.

  2. #2
    BANNED
    Join Date
    Jul 2005
    Posts
    537

    Default

    Did you turn on;

    Prevent the user 'nobody' from sending out mail to remote addresses (php and cgi scripts generally run as nobody if you are not using phpsuexec and suexec respectively.)

    From tweaks?

    With phpsuexec on, you should be able to tell whos sending spam but somebody may be abusing the scripts in /usr/local/cpanel/cgi-sys/. Did you check your /usr/local/apache/logs/error_log for cgi-sys abusers?

  3. #3
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,313
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Also try adding this: log_selector = +all to the Exim Configuration Editor > Advanced Mode in the first text box - Save - and then
    tail -f /var/log/exim_mainlog

  4. #4
    Member
    Join Date
    Jan 2004
    Posts
    5

    Default

    I did turn on the prevent nobody from sending out mail in Cpanel.

    I've gone through the error_logs and they are unexceptional. The typical 404 errors were about the only thing there.

    I did turn on the log_selector last night in the Exim Config Editor. Within my exim_mainlog there was a flurry of emails sent from nobody during those days I was "occupied", but there isn't anything like that right now.

  5. #5
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    One of the main reasons behind phpsuexec is that it gives you a clear idea of who sent the email, and knowing that is one of the keys to solving the problem. The exim logging tip above may help you see who is sending the spam. Also if you go into tweaks you can limit the number of emails per hour per user, which may help.

    You should try commands like "top" and look in the cron log to see if stuff is running regularly, that may also tip you off. It might be as simple as having a still running process from when you killed off the files in /tmp etc.

    The next question is whether the spam is even going through exim on your machine. You should be able to set up firewall rules (from memory there may even be something in tweaks to do it) to prevent processes connecting to off-machine SMTP servers as that's one way spam is sent.

Similar Threads & Tags
Similar threads

  1. Trying to find out a spammer
    By thewebhosting in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 06-08-2009, 10:53 AM
  2. Please help me find this spammer
    By gal3ler in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-14-2006, 09:57 AM
  3. Find spammer sending out of our server
    By steele in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 12-21-2005, 05:36 AM
  4. How can we find who is spammer?!
    By manghooli in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-26-2004, 02:30 AM
  5. Help, how can i find this spammer on my server?
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-07-2003, 03:13 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube