Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2002
    Location
    Hamilton, Ontario
    Posts
    67

    Default php & cgi scripts forwarding mail bombs, how to neutrali

    Ok,

    Well i've searched the forums, and honestly can't find a solution to our problem. Users have a php script, or insecure cgi script i'd imagine that is sending mail through apache (i believe) as the user nobody@serverhostname. for the cgi scripts, we searched for insecure verions of formmail, removed them, and that was that, but now we're getting evidence one of our servers is back up to the same tricks, but it has no more formmail scripts left except the .php ones.

    Problem being, there is no reasonable way to trace back this activity, the exim_mainlog only displays that the user nobody@domain.com sent the email, i've tried to check the apache log files scanning back for entries when this was occurring, but with 700 logfiles in the /usr/local/apache/domlogs, this just isn't a reasonable solution. Theres got to be a way to stop exim from sending mail from the user nobody, and we found some that were supposed to work for exim v4.0 , but CPanel seems to be running exim 3.xx. Does anyone have suggestions for this? even fi we cant disable the user nobody from sending mail, there must be a reasonable way to at least identify which user/domain has the scripts that are being used for this malicious activity.
    Myles Loosley-Millman
    Priority Colo Inc.
    cpanel@prioritycolo.com

  2. #2
    Member
    Join Date
    Sep 2002
    Posts
    46

    Default

    I need to know too

Similar Threads & Tags
Similar threads

  1. I changed the IP of Exim, but what about cgi/php scripts?
    By noimad1 in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 11-23-2006, 09:32 AM
  2. CGI scripts not sending email, php scripts will
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-17-2006, 04:20 AM
  3. apache parsing non php or cgi or pl scripts
    By dchepishev in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-08-2006, 11:59 AM
  4. cgi/php scripts slow
    By Daemon1 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 05-19-2006, 04:04 AM
  5. Nobody-Mail-Problem with PHP & CGI-Scripts
    By JapAniManga.ch in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 08-08-2002, 02:01 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube