Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jun 2003
    Posts
    99

    Default Mail Queue 1,000 Messages

    Hi,

    My eMail Queue shows 1,000 messages all sent to someone@hotmail.com seems like a Mailbomber Script on our Server, how do We dettect it?

    What do we have to check?

    Please guide me! I want to delete the fu... that is sending spam

    Thanks

  2. #2
    Member PWSowner's Avatar
    Join Date
    Nov 2001
    Location
    ON, Canada
    Posts
    2,994

    Default

    Just some ideas that may or may not help:

    Check the email headers to see if it tells you anything.

    Check current running processes.

    Use command "top" in shell and see what it says.

    Try "View Mail Stats" in WHM. It may show which user is doing the sending.

    Also possible it could be an outside user, either running a script of his own or found an exploitable formmail script.
    Mike
    WHM and cPanel Scripts (join our "Scripts Club")
    D/A Photography

  3. #3
    Member
    Join Date
    Jun 2003
    Posts
    99

    Default

    Here's the Header
    1AzDKZ-0003mK-J8-H
    nobody 99 99
    <426044@microsoft.com>
    1078485447 0
    -ident nobody
    -received_protocol local
    -body_linecount 1
    -auth_id nobody
    -auth_sender nobody@free.mtxis.net
    -local
    XX
    1
    hoangtu_deptrai_87@yahoo.com

    151P Received: from nobody by free.mtxis.net with local (Exim 4.24)
    id 1AzDKZ-0003mK-J8
    for hoangtu_deptrai_87@yahoo.com; Fri, 05 Mar 2004 03:17:27 -0800
    033T To: hoangtu_deptrai_87@yahoo.com
    016 Subject: 104726
    027F From: 426044@microsoft.com
    047I Message-Id: <E1AzDKZ-0003mK-J8@free.mtxis.net>
    040* X-rewrote-sender: nobody@free.mtxis.net
    038 Date: Fri, 05 Mar 2004 03:17:27 -0800

    1AzDKZ-0003mK-J8-D
    nhan bom nhe con trai ta

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    received_protocol local
    So, it's sent from your server (you already knew that)

    auth_sender nobody@free.mtxis.net
    Makes this harder to trace. Do you have...

    1. SuExec enabled? If so, then it's probably not from a CGI script

    2. PHPSuexec enabled? If so, then it's probably not from a PHP script

    3. "Prevent the user 'nobody' from sending out mail to remote addresses" enalbed under WHM > Tweak Settings? If not, enable it now!

    Check for failure errors in /etc/httpd/logs/error_log as they may have generated errors when trying to take over the script
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member
    Join Date
    Jun 2003
    Posts
    99

    Default

    Originally posted by chirpy
    received_protocol local
    So, it's sent from your server (you already knew that)

    auth_sender nobody@free.mtxis.net
    Makes this harder to trace. Do you have...

    1. SuExec enabled? If so, then it's probably not from a CGI script

    2. PHPSuexec enabled? If so, then it's probably not from a PHP script

    3. "Prevent the user 'nobody' from sending out mail to remote addresses" enalbed under WHM > Tweak Settings? If not, enable it now!

    Check for failure errors in /etc/httpd/logs/error_log as they may have generated errors when trying to take over the script
    Hi,

    But then I won't be able to use the () Mail funtion?

    BTW; SuExec is Enabled, do I enable PHPsuEXEC ?

Similar Threads & Tags
Similar threads

  1. Over 1,000 Emails to root@myserver.com in Mail Queue
    By zimmerru in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-01-2008, 10:58 AM
  2. over 300.000 mail messages
    By upsforum in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-08-2007, 05:46 AM
  3. Get number of messages in mail queue
    By simonpearce in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-15-2006, 12:41 PM
  4. Mail Queue and over quota messages
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-20-2005, 03:35 PM
  5. I have over 260,000 emails in my mail queue
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 09-18-2004, 01:28 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube