Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Jul 2006
    Posts
    41

    Default BCC Form Spam is not logged anywhere

    That I can find at least :-)

    I have a PHP script on my server which has been used to send out lots and lots of spam to AOL. I only discovered this because Hotmail blocked me a week ago and in the course of discussion with them I discovered that my machine had sent over 600 messages per day to them.

    Upon checking deeper (and looking directly at the queue files) I discover that the same script has been used to send to more like 6000 AOL e-mail addresses per day.

    I've installed Mod Security now, and sorted out the erroneous script (though no doubt there will be more in the future).

    But, what I do not understand is that NONE of these messages show in my MailWatch reports. If they had I may have tracked this down a lot quicker. My MailWatch reports show only messages to AOL that were legitimate.

    Anyone have any idea how a message could appear in the outbound queue but not show in MailWatch?

    Cheers,
    Steve

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    If the email isn't logged in exim_mainlog then the script was likely sending email directly through port 25 and bypassing exim entirely.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Jul 2006
    Posts
    41

    Default

    Quote Originally Posted by chirpy
    If the email isn't logged in exim_mainlog then the script was likely sending email directly through port 25 and bypassing exim entirely.
    Hi Chirpy,
    That's what I would have thought to, except for a couple of things;

    I have ConfigServer firewall set to block port 25 outbound except for exim, root and mailman. The script sending mail was a PHP script, owned by 'deardiar' account (using the PHP mail() command).

    Also, any delayed messages DO show in the exim mail queue in cPanel, but do not show in the MailWatch statistics.

    I think the messages are being logged in exim_mainlog - though there's so many it's hard to be sure. But they're definitely not being logged into the MailWatch stats.

    Regards,
    Steve.

Similar Threads & Tags
Similar threads

  1. web form / Wordpress spam blacklist
    By zosorock in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-26-2009, 06:12 PM
  2. Bcc Mail Help
    By davis in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-18-2006, 05:33 AM
  3. SPAM sent from php contact form...
    By fred123123 in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 11-22-2005, 03:43 AM
  4. Disable BCC
    By punk in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-13-2004, 06:00 AM
  5. CC - BCC Limit
    By d4rkl0rd in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 09-24-2004, 03:50 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube