Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jan 2006
    Posts
    23

    Default how to identify account or PHP/Perl script used for spamming?

    Hi,

    We're using the standard Exim setup on Cpanel. I'm experiencing a lot of outgoing SPAM from the nobody user, as I can see by the "view relayer" option, and in the mail queue.

    Is there any way to identify which account or, better yet, which PHP/Perl CGI script is being used to send this spam? It's funny how hard it is to find this info out online. Maybe I'm just looking in the wrong places.

    Our server is pretty heavily loaded and I don't want to suffer the performance hit of suexec, phpsusec or suphp.

    Previously, I installed a sendmail replacement script which intercepts all sendmail access, logs the script that accesses it, and then sends it along to the actual sendmail binary, but the script was buggy and it broke my outgoing mail from all scripts, including legitimate ones.


    Also, can anyone tell me if turning on the SMTP Tweak may break any legitimate script mailers?


    Thank you kindly,

    Shiraz

  2. #2
    Member
    Join Date
    Mar 2004
    Posts
    94

    Default

    No, turning on SMTP tweak does not break anything.

    You may apply this patch to check your php scripts.
    http://choon.net/php-mail-header.php

  3. #3
    Member
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    300

    Default

    The quickest and easiest way is to add 'log_selector = +arguments +subject' to the exim configuration. You can do this by using the Advanded exim config editor in WHM and adding that line to the first text box.

    Once this is added, you can monitor /var/log/exim_mainlog. You will see where all emails are originated from. If there is a php/perl script sending spam, you will be able to find exactly what folder the script resides in.
    -Todd Shipway

  4. #4
    Member
    Join Date
    Jan 2006
    Posts
    23

    Default

    Wow, both very very practical suggestions! I wish I'd asked sooner. Thanks guys.

  5. #5
    Member
    Join Date
    Mar 2006
    Posts
    1,215

    Default

    Also some very handy tools to add THanks to Chirpy...

    www.configserver.com

    ConfigServer Mail Queues
    ConfigServer Mail Manage

    cheers

Similar Threads & Tags
Similar threads

  1. Use Perl and PHP in same script
    By crinte in forum cPanel Developers
    Replies: 5
    Last Post: 09-11-2010, 08:16 AM
  2. eMail Piping to perl script PLUS copy to specific pop account (via cPanel)
    By cards4success in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 03-02-2004, 05:41 AM
  3. Spamming - Someone is accessing my 3rd party csMailto script
    By anish sidhan in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-26-2003, 09:30 PM
  4. PHP and PERL script access
    By dima in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-28-2003, 06:54 AM
  5. Automating Account Creation: Shell Script? PHP Script?
    By RangerWest in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-13-2003, 09:24 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube