Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Jul 2002
    Posts
    93

    Default Exploited mail program/cgi??

    I was watching the exim log when I saw these entries pop up:

    ------
    2003-10-18 21:37:08 1AB2VI-00049o-KH <= chunsengchen@yahoo.com U=nobody P=local S=2025
    2003-10-18 21:37:08 1AB2VI-00049p-Me <= chunsengchen@yahoo.com U=nobody P=local S=2374
    2003-10-18 21:37:12 1AB2VI-00049p-Me mx2.mail.yahoo.com [64.157.4.78]: Connection refused
    2003-10-18 21:37:13 1AB2VI-00049p-Me => chunsengchen@yahoo.com R=lookuphost T=remote_smtp H=mx2.mail.yahoo.com [64.156.215.6]
    2003-10-18 21:37:13 1AB2VI-00049p-Me Completed
    2003-10-18 21:37:14 1AB2VI-00049o-KH => chiewster@hotmail.com R=lookuphost T=remote_smtp H=mx2.hotmail.com [65.54.254.145]
    2003-10-18 21:37:14 1AB2VI-00049o-KH Completed

    ------

    Does this look to you as it does to me? That somebody just sent a test through a vulnerable mail program on my server??? User: nobody would be a script, yes?

    How can I find what script they used?
    Last edited by myrem; 10-18-2003 at 09:00 PM.

  2. #2
    Member
    Join Date
    Jul 2002
    Posts
    93

    Default

    more..

    Found in the "nobody" relay log in WHM:

    --------

    Anyone have any ideas on how to track this down?
    PHP Code:
    Time Sent Message Id Sender Destination Size in Bytes 
    2003
    -10-18 22:37:14 1AB2VI-00049o-[email]chunsengchen@yahoo.com[/email] [email]chiewster@hotmail.com[/email2025 
    2003
    -10-18 22:37:13 1AB2VI-00049p-[email]chunsengchen@yahoo.com[/email] [email]chunsengchen@yahoo.com[/email2374 
    2003
    -10-18 20:04:55 1AB07v-0001vh-[email]chunsengchen@yahoo.com[/email] [email]day.chris@spartan.ab.ca[/email1507 
    2003
    -10-18 20:04:54 1AB07v-0001vi-[email]chunsengchen@yahoo.com[/email] [email]chunsengchen@yahoo.com[/email1851 
    2003
    -10-18 19:48:14 1AAzrl-0001eb-[email]chunsengchen@yahoo.com[/email] [email]day.chris@spartan.ab.ca[/email2479 

  3. #3
    BANNED
    Join Date
    Oct 2003
    Posts
    143

    Default

    Iam also seeing alot of these. You can find them if you click on View Relayers in WHM.

    1 example.
    2003-10-19 13:37:48 1ABJN2-0000e6-5 edfan@earthlink.net longlegs929@yahoo.com 1075

Similar Threads & Tags
Similar threads

  1. Allow Mail Filtering to Pipe to Program
    By jpratt in forum Feature Requests for cPanel/WHM
    Replies: 7
    Last Post: 06-16-2011, 11:13 AM
  2. dm.cgi - Dark Mailer program
    By handsonhosting in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-29-2009, 05:18 AM
  3. my mail system is being exploited
    By dukejustice in forum E-mail Discussions
    Replies: 5
    Last Post: 03-07-2008, 10:46 AM
  4. Can not send mail using a mailling program
    By logikstudios in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-16-2006, 08:16 AM
  5. Send mail for an adres to a program
    By Domenico in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-05-2001, 04:39 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube