Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member handsonhosting's Avatar
    Join Date
    Feb 2002
    Location
    Omaha, NE
    Posts
    149
    cPanel/Enkompass Access Level

    Root Administrator

    Default dm.cgi - Dark Mailer program

    Hey Folks,

    Over the past 3 days we've been hit pretty hard with a dm.cgi script running on servers. It's not just one or two servers with the program running, but so far we've counted 10 servers that have had the script running.

    The dm.cgi file is a program that sends out mass mail (Dark Mailer). As a result, we would likely end up on a black list quickly if we were not on top of it as we are currently.

    I've searched google, and while I find lots of places that offer it to download, there's no real documentation that I can find. I know that it uses a direct SMTP connection, thus bypassing rules etc, so I'm looking to find out if anyone has had experience with it and sucessfuly blocked it on their servers (other than using mod_security).

    Any help would be appreciated.

  2. #2
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Shoot me an email of PM, I have something that can help
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  3. #3
    Member handsonhosting's Avatar
    Join Date
    Feb 2002
    Location
    Omaha, NE
    Posts
    149
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Thanks in advance,

    Message sent to PM.

  4. #4
    Member
    Join Date
    Mar 2004
    Posts
    710

    Default

    I believe chirpy's firewall can do it.

    See:

    # Block outgoing SMTP except for root, exim and mailman (forces scripts/users
    # to use the exim/sendmail binary instead of sockets access). This adds the
    # protection as WHM > Tweak Settings > SMTP Tweaks, which are lost when using a
    # firewall configuration script

    and

    # If SMTP_BLOCK is enabled but you want to allow local connections to port 25
    # on the server (e.g. for web scripts) then enable this option too
    Lloyd F Tennison

  5. #5
    Member handsonhosting's Avatar
    Join Date
    Feb 2002
    Location
    Omaha, NE
    Posts
    149
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hi Lloyd,

    Thanks for the feedback.

    Yeah, we've been experimenting enabling that on a number of servers. We've had the CSF running for quite some time on our machines, but that option has been marked as OFF as we weren't sure how it would affect other sites on the machine with eCommerce Software sending mail etc.

    I guess at this point, we'll enable it and see if we are experiencing any differences.

    Never received anything from Ramprage yet, so I'll enable the other for the moment.

    Thanks again for the comments and the help toward a solution.

  6. #6
    Member
    Join Date
    Apr 2005
    Posts
    28

    Default

    Quote Originally Posted by handsonhosting View Post
    Hi Lloyd,

    Thanks for the feedback.

    Yeah, we've been experimenting enabling that on a number of servers. We've had the CSF running for quite some time on our machines, but that option has been marked as OFF as we weren't sure how it would affect other sites on the machine with eCommerce Software sending mail etc.

    I guess at this point, we'll enable it and see if we are experiencing any differences.

    Never received anything from Ramprage yet, so I'll enable the other for the moment.

    Thanks again for the comments and the help toward a solution.
    Apologies for digging old thread but I was curious, Did CSF help you in blocking dm.cgi dark.cgi scripts?

Similar Threads & Tags
Similar threads

  1. Problem with dark.cgi scripts !!!
    By p-root in forum Security
    Replies: 7
    Last Post: 11-19-2009, 07:01 AM
  2. Problem with dark.cgi scripts !!!
    By p-root in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 11-19-2009, 07:01 AM
  3. Replies: 0
    Last Post: 02-14-2005, 10:49 PM
  4. Exploited mail program/cgi??
    By myrem in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-19-2003, 07:10 PM
  5. 404 error on dark orbs installation link,
    By DWHS.net in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-30-2002, 10:15 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube