Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Aug 2003
    Posts
    10

    Default How to findout spammers from this???

    I have a spammer in my server. One of my clients may be . I want to find him. For the spam mails I have the folowsing header. Is it possible to find the spammer site(userid) in my server from this ? or is there any other solution?

    Please h--e-e-l-l-p.

    (Here I replace original server name by myservername.net for security reasons.)

    ***************************************

    1C6ovb-0004L8-N0-H
    nobody 99 99
    <nobody@myservername.net>
    1095074603 0
    -ident nobody
    -received_protocol local
    -body_linecount 1
    -auth_id nobody
    -auth_sender nobody@myservername.net
    -allow_unqualified_recipient
    -allow_unqualified_sender
    -local
    XX
    1
    ronz_ctg@yahoo.com

    146P Received: from nobody by myservername.net with local (Exim 4.42)
    id 1C6ovb-0004L8-N0
    for ronz_ctg@yahoo.com; Mon, 13 Sep 2004 17:23:23 +0600
    023T To: ronz_ctg@yahoo.com
    018 Subject: I am here
    021F From: nila@yahoo.com
    025R Reply-To: nila@yahoo.com
    020 X-Mailer: PHP/4.3.8
    052I Message-Id: <E1C6ovb-0004L8-N0@myservername.net>
    038 Date: Mon, 13 Sep 2004 17:23:23 +0600

    ******************************************************


    -Tmc74

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I would suggest that you do a search on the forums for spammer nobody and you're likely to find plenty of posts that have gone through this.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Jul 2004
    Location
    Charlotte, NC
    Posts
    31

    Default

    Also turn off the ability within whm for "nobody to send email". It's under one of the security settings. All email should be going throuhg the smtp server.

    -drmike

  4. #4
    Member
    Join Date
    Nov 2002
    Posts
    153

    Default

    Also check the apache logs, if its a formail exploit then it will show up often in the logs, this will lead you to the account being exploited.

    Also do a search for formails on your server and if needed disable them.

    Also as posted above use the option in whm to prevent the user nobody sending out emails, this will also break some customers scripts but for now it will help while you find the spammer.

    There is not a lot anyone here can do to help you, if you are unable to catch the spammer then you will need to allow/pay someone to access your server.

    good luck

Similar Threads & Tags
Similar threads

  1. How Do You Stop Spammers
    By filth in forum E-mail Discussions
    Replies: 8
    Last Post: 11-04-2007, 02:41 PM
  2. Help with spammers
    By lcryan in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-27-2006, 03:49 PM
  3. Email and Spammers
    By Mysteerie in forum E-mail Discussions
    Replies: 6
    Last Post: 09-13-2004, 11:02 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube