#1 (permalink)  
Old 06-20-2007, 03:23 AM
Registered User
 
Join Date: Feb 2002
Location: Omaha, NE
Posts: 104
handsonhosting
dm.cgi - Dark Mailer program

Hey Folks,

Over the past 3 days we've been hit pretty hard with a dm.cgi script running on servers. It's not just one or two servers with the program running, but so far we've counted 10 servers that have had the script running.

The dm.cgi file is a program that sends out mass mail (Dark Mailer). As a result, we would likely end up on a black list quickly if we were not on top of it as we are currently.

I've searched google, and while I find lots of places that offer it to download, there's no real documentation that I can find. I know that it uses a direct SMTP connection, thus bypassing rules etc, so I'm looking to find out if anyone has had experience with it and sucessfuly blocked it on their servers (other than using mod_security).

Any help would be appreciated.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-20-2007, 09:03 AM
Registered User
 
Join Date: Jul 2002
Location: Canada
Posts: 663
ramprage is on a distinguished road
Shoot me an email of PM, I have something that can help
__________________
Upload Guardian 2.0 - Sign up for our early beta
ServerProgress - Server security, consulting and assistance
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-20-2007, 01:09 PM
Registered User
 
Join Date: Feb 2002
Location: Omaha, NE
Posts: 104
handsonhosting
Thanks in advance,

Message sent to PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-21-2007, 04:35 PM
Registered User
 
Join Date: Mar 2004
Posts: 697
lloyd_tennison is on a distinguished road
I believe chirpy's firewall can do it.

See:

# Block outgoing SMTP except for root, exim and mailman (forces scripts/users
# to use the exim/sendmail binary instead of sockets access). This adds the
# protection as WHM > Tweak Settings > SMTP Tweaks, which are lost when using a
# firewall configuration script

and

# If SMTP_BLOCK is enabled but you want to allow local connections to port 25
# on the server (e.g. for web scripts) then enable this option too
__________________
Lloyd F Tennison
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 06-21-2007, 11:53 PM
Registered User
 
Join Date: Feb 2002
Location: Omaha, NE
Posts: 104
handsonhosting
Hi Lloyd,

Thanks for the feedback.

Yeah, we've been experimenting enabling that on a number of servers. We've had the CSF running for quite some time on our machines, but that option has been marked as OFF as we weren't sure how it would affect other sites on the machine with eCommerce Software sending mail etc.

I guess at this point, we'll enable it and see if we are experiencing any differences.

Never received anything from Ramprage yet, so I'll enable the other for the moment.

Thanks again for the comments and the help toward a solution.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 06-29-2009, 06:18 AM
Registered User
 
Join Date: Apr 2005
Posts: 28
linuxserverguy is on a distinguished road
Quote:
Originally Posted by handsonhosting View Post
Hi Lloyd,

Thanks for the feedback.

Yeah, we've been experimenting enabling that on a number of servers. We've had the CSF running for quite some time on our machines, but that option has been marked as OFF as we weren't sure how it would affect other sites on the machine with eCommerce Software sending mail etc.

I guess at this point, we'll enable it and see if we are experiencing any differences.

Never received anything from Ramprage yet, so I'll enable the other for the moment.

Thanks again for the comments and the help toward a solution.
Apologies for digging old thread but I was curious, Did CSF help you in blocking dm.cgi dark.cgi scripts?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 05:20 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc