Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Member
    Join Date
    Nov 2003
    Posts
    521

    Exclamation Email attack on a client..need help

    Okay a friend of mine just created an account on my server, and just registered a domain name.. the problem is the second his domain name resolved onto my server he's been receiving 5-10 virus infected emails per day being sent to fake email address on his account. He hasn't even put any content onto his site, and he hasn't even created any email accounts.

    I have a RHE cpanel server with mailscanner+clamav on it, and so far mailscanner+clamav has been doing a good job on stopping the emails.. but the thing is the emails are being sent from different email address, and different ips.. so i can't even track down whats going on.

    I set his default email account to :fail:, but besides that i'm not sure what else to do. I was thinking maybe if i had the server reject all emails sent to his domain for like two weeks or something, it might minimize the problem alittle.. but i'm really not sure what to do?

    Any advice information will be greatly appreciated...Thank you.

  2. #2
    BANNED
    Join Date
    Feb 2004
    Posts
    349

    Default

    I dont think clamv is a very efficient virus detector. We use F-secure and Sophos. Why dont you set the option in MailScanner to not warn you and not warn the client. Also set Mailscanner to not quaranteen the msgs. Then he and you wont be bothered by virus warnings etc. Never set it to :fail: unless you have made the speicial modification to exim that actually prevents mail from arriving via :fail:. You can find this modification on RS if you search the forums. If anything set it to :blackhole: if nothing else. Good luck!

  3. #3
    Member
    Join Date
    Nov 2003
    Posts
    521

    Default

    Originally posted by mr.wonderful
    I dont think clamv is a very efficient virus detector. We use F-secure and Sophos. Why dont you set the option in MailScanner to not warn you and not warn the client. Also set Mailscanner to not quaranteen the msgs. Then he and you wont be bothered by virus warnings etc. Never set it to :fail: unless you have made the speicial modification to exim that actually prevents mail from arriving via :fail:. You can find this modification on RS if you search the forums. If anything set it to :blackhole: if nothing else. Good luck!
    Thanks for your reply. So if i set it to :fail: via cpanel, that setting doesn't work unless i actually edit exim?

    Also what do you mean by RS?

    Thank you in advance.

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Slightly off-topic...

    I dont think clamv is a very efficient virus detector
    It can be. If you are using MailScanner, installing the Mail::ClamAV perl module and then changing the virus scanner in MailScanner from clamav to clamavmodule vastly improves its performance.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member
    Join Date
    Apr 2003
    Posts
    117

    Default

    RS=RackShack I think. Now called EV1servers

  6. #6
    Member
    Join Date
    Nov 2003
    Posts
    521

    Default

    so no need to edit exim?

  7. #7
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Originally posted by chirpy
    Slightly off-topic...



    It can be. If you are using MailScanner, installing the Mail::ClamAV perl module and then changing the virus scanner in MailScanner from clamav to clamavmodule vastly improves its performance.
    Is this in later versions? I installed it but mail was not delivered with the scanner set to clamavmodule...

  8. #8
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Originally posted by casey
    Is this in later versions? I installed it but mail was not delivered with the scanner set to clamavmodule...
    Nevermind. 4.25 or later, huh? I've got 4.22 so I'll have to upgrade. That should improve the load.

  9. #9
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    I also had to install the following perl modules:
    Net::CIDR
    Inline

    Then I had to change the following line in MailScanner.conf:
    Monitors for ClamAV Updates = /usr/local/share/clamav/*.cvd
    to:
    Monitors for ClamAV Updates = /usr/share/clamav/*.cvd

Similar Threads & Tags
Similar threads

  1. distributed attack on the email server today.
    By jols in forum E-mail Discussions
    Replies: 0
    Last Post: 05-18-2011, 07:00 PM
  2. Email - Webmail Attack
    By bhstudios in forum E-mail Discussions
    Replies: 3
    Last Post: 09-19-2009, 06:49 PM
  3. under email attack!
    By Radio_Head in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-07-2006, 07:29 AM
  4. I am getting hit with a distributed dictionay email attack
    By EdRooney in forum cPanel and WHM Discussions
    Replies: 17
    Last Post: 09-14-2006, 10:05 AM
  5. Some email not being delivered to client
    By bmcclure in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-09-2003, 04:33 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube