Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    May 2002
    Posts
    6

    Default Increase spamming through user Nobody

    We have noticed over the weekend a huge increase in emails being send from our server farm from the user Nobody (PHP). These emails are largely being sent to AOL users. These servers have been online for a while now and have not have any concern of this type prior to Friday morning. Is there any new technique/exploit being used by Internet spammers through PHP scripts?

    FYI - We do know about the exploit in Formmail.pl's and have worked to combat that problem. This issue started about Thursday evening or Friday morning and continues today.

    cPanel.net Support Ticket Number:

  2. #2
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    I would suggest checking the account of new Clients, say in the last week, and if you keep copies of Server eMails: [newmailcgi] Recently Uploaded CGI scripts that send email on... to check those as well. Although it says CGI scripts, it is notice of any type script using any eMail protocols.

    cPanel.net Support Ticket Number:
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  3. #3
    Member
    Join Date
    May 2002
    Posts
    6

    Default

    Thank you for the input. These machines have not taken on any new customers in a while. They are full and have been running at the same capacity for a while. The problem just popped up on us on Friday and continues today.

    cPanel.net Support Ticket Number:

  4. #4
    Member
    Join Date
    Apr 2003
    Posts
    94

    Default

    I am just now having this problem, but I looked and my server has never sent that email. Is there a way to get it to? Or to view via the server what it would have?

    cPanel.net Support Ticket Number:

  5. #5
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default



    If your Server has not sent out the eMails, how can it be a problem for you?

    cPanel.net Support Ticket Number:
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  6. #6
    Member
    Join Date
    May 2002
    Posts
    292

    Default

    2 days ago I got a report from spam cop on spam from one of my servers and it was from nobody, but the name of the mailer script was included in the header so I greped the script name and found 10 of them on the server. I then used pico to edit each of the scripts and changed the mailer name in the script to the domain name it was running on. Next time they send mail it will have their domian name in the header of the mail.

    Then terminate.

    cPanel.net Support Ticket Number:

  7. #7
    Member
    Join Date
    May 2002
    Posts
    292

    Default

    AAlready tried that breaks a few scripts so I am giving my clients time to get ready before we pull that trigger on them.

    cPanel.net Support Ticket Number:

  8. #8
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by techark
    AAlready tried that breaks a few scripts so I am giving my clients time to get ready before we pull that trigger on them.
    What exactly broke when you tried phpsuexec?

    cPanel.net Support Ticket Number:

  9. #9
    Member Doctor's Avatar
    Join Date
    Apr 2003
    Posts
    180

    Default

    What exactly broke when you tried phpsuexec?


    FYI, scripts like PHPBB will not be able to send out mails when PHPSuexec is enabled. Am I right, techark?

    cPanel.net Support Ticket Number:

  10. #10
    Member
    Join Date
    Feb 2003
    Location
    Sachse, TX
    Posts
    567

    Default

    Originally posted by Doctor


    FYI, scripts like PHPBB will not be able to send out mails when PHPSuexec is enabled. Am I right, techark?

    cPanel.net Support Ticket Number:
    Nope...

    I have PHPBB and PHPSuexec and all is fine.

    Brenden

    cPanel.net Support Ticket Number:

  11. #11
    Member Doctor's Avatar
    Join Date
    Apr 2003
    Posts
    180

    Default

    Hey Taz! Nice to hear from you again! The last time I tried, PHPBB did have the problem. Maybe their newer version supports PHPSuexec.

    I have a question though. The last time I had PHPSuexec enabled, some of my clients did come back to me saying that all outbound mails were bounced. My question is... what should be added in a PHP script so that it supports PHPSuexec?

    Because I have an answer to this, I will definitely enable PHPSuexec again.

    cPanel.net Support Ticket Number:

  12. #12
    Member bmcpanel's Avatar
    Join Date
    Jun 2002
    Posts
    546

    Default

    Originally posted by jamesbond
    What exactly broke when you tried phpsuexec?
    Several of our customer's private PHP scripts broke. Most of it was because the user was using PHP configs in .htaccess.

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. Protect Against Spamming
    By bryzo in forum E-mail Discussions
    Replies: 9
    Last Post: 07-10-2008, 02:21 PM
  2. Spamming Ourselves ???
    By brendanrtg in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-07-2007, 02:28 PM
  3. U=cpanel spamming
    By madan.cpanelnet in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-28-2006, 04:19 PM
  4. This user is spamming !!! I need to block it !!
    By atul in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 08-07-2004, 09:54 PM
  5. Spamming?
    By jmc67 in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 05-31-2003, 10:24 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube