Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    EMS
    EMS is offline
    BANNED
    Join Date
    May 2003
    Posts
    251

    Default hundredds of exim instances overloading server

    Hi,

    Just had an incident whereby the server load went crazy. I restarted the server but whenever the network cable was plugged in - 1200 exim processes spooled up followed by clamd service which takes the load up to 100% and disk access is constant.

    I got the datacenter to unplug the network cable, restart the server and stop exim - then plug it back in.

    I then logged in remoteley and made sure the exim service was stopped, it was already starting again and building up 30 or 40 processes.

    I've checked out the server and so far have been unable to find any compromised accounts or unusual files. /tmp is clean.

    If exim is restarted it happens again.

    Any ideas ?

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Well, any relevant information should be in /var/log/exim_mainlog
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    EMS
    EMS is offline
    BANNED
    Join Date
    May 2003
    Posts
    251

    Default

    The mail queue had thousands of messages intended for one domin on the server. They appear to be delivery failures to a spam mesage sent with a spoofed header. They were not sent form the domain in question.

    Its still happening - i'll run a script to clear out the mail queue every 30 seconds for messages contianing the content.

  4. #4
    Member
    Join Date
    Dec 2004
    Posts
    388

    Default

    you need to install some security in your exim. Most probably you are being bombarded by spams and/or dictionary attack.

    Have you installed RBL and APF (with brute force detection)?

    Also, did you disable "catch-all"?

  5. #5
    EMS
    EMS is offline
    BANNED
    Join Date
    May 2003
    Posts
    251

    Default

    Quote Originally Posted by abubin
    you need to install some security in your exim. Most probably you are being bombarded by spams and/or dictionary attack.

    Have you installed RBL and APF (with brute force detection)?

    Also, did you disable "catch-all"?
    APF with BFD installed - RBL not. They were all delivery failures to spam messages. The reason the server was being overloaded is because the customer had a catchall set. once I set it to :blackhole: things eased up. We dont prevent them from using a catchall mailbox.

  6. #6
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    APF and BFD won't do anythng about spam (unless you use the flawed exim blocker). You much better off with a dictionary attack ACL and not using :blackhole: - use :fail: instead, it's much lighter on your server resources and for many other reasons.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  7. #7
    Member
    Join Date
    Jan 2005
    Posts
    65

    Default

    Run this command to convert all domains to :fail: instead of :blackhole:.
    Code:
    perl -pi -e "s/:blackhole:/:fail:/g;" /etc/valiases/*
    Also, I'd look at the headers in the mail queue to try to find out exactly where this coming from, and then I'd clear out the mail queue as that in itself could be causing high load.

    Good luck.

    Regards,

  8. #8
    EMS
    EMS is offline
    BANNED
    Join Date
    May 2003
    Posts
    251

    Default

    But, wont :fail: send a reply back - where :blackhole: will simply discard the message ?

  9. #9
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  10. #10
    EMS
    EMS is offline
    BANNED
    Join Date
    May 2003
    Posts
    251

    Default

    Ahh, thanks. I got it the wrong way round.

Similar Threads & Tags
Similar threads

  1. Server Overloading...
    By oscarfish in forum Optimization
    Replies: 19
    Last Post: 05-29-2010, 07:58 AM
  2. Server Overloading always
    By big_bull in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 11-16-2009, 04:45 PM
  3. exim is overloading
    By DWHS.net in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 08-24-2007, 07:54 AM
  4. Dedicated server keeps on overloading
    By bokhove2 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-28-2005, 12:30 PM
  5. Exim overloading server
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-24-2004, 10:41 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube