Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Sep 2001
    Posts
    44

    Default new kind of spammer?

    For the second time in a week my server has been used to send out spam.

    The first time was at the end of last week. Investigating I found that the spammer seemed to have a password for client's email account since:
    a) all spam were originated from that account and
    b) analizing the headers of the spam messages the mail was sent by an authenticated user, using an email client (I mean, it wasn't sent by "nobody" exploiting a web form or something like that, headers were very clean)

    Anyway, I suspended the account, discussed the problem with the client and we ended suspecting at that moment that it was an isolated case of a worm, trojan or keyloger on his machine.

    But...

    The second time was yesterday... It was exactly the same method and type of spam:
    * very short message
    * porn type
    * every mail was to exactly 10 recipients
    * short message with an <img> tag to display an external image
    So I suspect it was the same spammer.
    Only this time he was using a completely different mail account. The interesting part is that this email account is from another client that has no relation with the first one whatsoever.

    Taking this into account now I'm considering the posibility that somehow spammers are getting email passwords at the server end. I'm suspecting packet sniffing at the datacenter.

    Clues anyone?

    Thanks in advance
    Last edited by luis; 07-01-2006 at 10:36 AM.

  2. #2
    Member bmcpanel's Avatar
    Join Date
    Jun 2002
    Posts
    546

    Default

    Quote Originally Posted by luis
    For the second time in a week my server has been used to send out spam.

    The first time was at the end of last week. Investigating I found that the spammer seemed to have a password for client's email account since:
    a) all spam were originated from that account and
    b) analizing the headers of the spam messages the mail was sent by an authenticated user, using an email client (I mean, it wasn't sent by "nobody" exploiting a web form or something like that, headers were very clean)

    Anyway, I suspended the account, discussed the problem with the client and we ended suspecting at that moment that it was an isolated case of a worm, trojan or keyloger on his machine.

    But...

    The second time was yesterday... It was exactly the same method and type of spam:
    * very short message
    * porn type
    * every mail was to exactly 10 recipients
    * short message with an <img> tag to display an external image
    So I suspect it was the same spammer.
    Only this time he was using a completely different mail account. The interesting part is that this email account is from another client that has no relation with the first one whatsoever.

    Taking this into account now I'm considering the posibility that somehow spammers are getting email passwords at the server end. I'm suspecting packet sniffing at the datacenter.

    Clues anyone?

    Thanks in advance
    Maybe someone has root access to your box. Check for evidence of intrusion.

  3. #3
    Member
    Join Date
    Sep 2001
    Posts
    44

    Default

    Of course that is always a posibility buy I don't think the evidence points that way... A user with root access could easily create an email account instead of using an existing one from a web hosting customer... or even find a way to send those without leaving evidence...

    Anyone has had this type of issue?

  4. #4
    Member
    Join Date
    Apr 2005
    Posts
    318

    Default

    Contact Chirpy for this issue... he might help.
    http://www.crohoster.com/
    quality hosting services and managed dedicated servers

Similar Threads & Tags
Similar threads

  1. Server has disappeared... kind of.... maybe....
    By schwim in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 12-13-2007, 08:35 AM
  2. New kind of spam ?
    By benito in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 08-30-2007, 07:42 AM
  3. What kind of an error is this?
    By NetCafe in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-25-2006, 06:13 AM
  4. What kind of hack is this...???
    By bhznat in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-02-2005, 03:20 PM
  5. What kind of license is MySQL?
    By navmonkey in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-22-2005, 11:34 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube