Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Aug 2006
    Location
    India
    Posts
    60

    Unhappy Spam Spam Spam

    Hello,

    Some spammer is constantly sending spams from my server but i am not able to trace him.

    I have Checked the "Disallow nobody to send emails..." options under WHM > Tweak Settings.. even the exim logs does not tell me anythign about this.

    But still cannot trace the spam with its headers...

    herez what that spam looks like


    Return-Path: <$munged$@$munged$>
    Received: from rs25s8.datacenter.cha.cantv.net (rs25s8.ric.cantv.net [10.128.131.130])
    by rs26s14.datacenter.cha.cantv.net (8.14.3/8.14.3/1.0) with ESMTP id n191rYcu000579
    for <$munged$@$munged$>; Sun, 8 Feb 2009 21:23:34 -0430
    Received: from [My IP Address]-static.reverse.[My domain name] ([My IP Address]-static.reverse.[My domain name] [[My IP Address]] (may be forged))
    by rs25s8.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with SMTP id n191rUKA013416
    for <$munged$@$munged$>; Sun, 8 Feb 2009 21:23:33 -0430
    X-Matched-Lists: []
    From: <$munged$@$munged$>
    Subject: Wish to impress and please your lady tonight?
    To: <$munged$@$munged$>
    Date: Mon, 9 Feb 2009 02:00:11 +0300
    Reply-To: <$munged$@$munged$>
    X-Priority: 1 (High)
    Message-ID: <$munged$@$munged$>
    X-Mailer: Sendmail 3.84/3.84
    Content-Type: multipart/alternative;
    boundary="----01C98A732B43209C"
    X-Virus-Scanned: ClamAV version 0.94.2, clamav-milter version 0.94.2 on 10.128.1.89
    X-Virus-Status: Clean
    X-SPF-Scan-By: smf-spf v2.0.2 - http://smfs.sf.net/
    Received-SPF: SoftFail (rs25s8.datacenter.cha.cantv.net: transitioning domain of $munged$@$munged$
    does not designate [My IP Address] as permitted sender)
    receiver=rs25s8.datacenter.cha.cantv.net; client-ip=[My IP Address];
    envelope-from=<$munged$@$munged$>; helo=[My IP Address]-static.reverse.[My domain name];

    gvecjjqxn byoct nejfwa cjzrhusshl
    Your link!
    pwqbc soqopw
    Your discount code #smbhyvf.


    Can someone please please suggest me how to stop it and trace this spammer?

    The Datacenter has blocked our IP due to this.



    Thanx in advance.
    Last edited by cancer10; 02-17-2009 at 12:04 AM.

  2. #2
    Member
    Join Date
    Aug 2006
    Location
    India
    Posts
    60

    Default

    Question: is it possible for someone to send email NOT using any scripts and NOT using any webmail/outlook?

    Thanx

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2008
    Location
    PK
    Posts
    443

    Default

    Quote Originally Posted by cancer10 View Post
    Hello,

    Some spammer is constantly sending spams from my server but i am not able to trace him.

    I have Checked the "Disallow nobody to send emails..." options under WHM > Tweak Settings.. even the exim logs does not tell me anythign about this.

    But still cannot trace the spam with its headers...

    herez what that spam looks like

    Can someone please please suggest me how to stop it and trace this spammer?

    The Datacenter has blocked our IP due to this.

    Thanx in advance.
    Usually this calls for a thorough audit of the server and security overhaul if the server isn't already secure.

    1- Perform a thorough audit of scripts running on your server. Change passwords, install firewall like CSF, APF etc.
    2- Enable SMTP Tweak from "WHM >> Security >> Security Center".
    3- Monitor your server constantly for any rogue scripts that you do not think should be running.
    4- tail -f /var/log/exim_mainlog and monitor.

    Best of Luck.
    1 solution works for all problems. Trying harder!
    HostMasterTips - Understanding Tech Support

  4. #4
    Member
    Join Date
    Aug 2006
    Location
    India
    Posts
    60

    Default

    Question: is it possible for someone to send email NOT using any scripts and NOT using any webmail/outlook?

    Thanx

Similar Threads & Tags
Similar threads

  1. Are Spam Auto Delete & Spam Box mutually exclusive?
    By smileybri in forum New User Questions
    Replies: 1
    Last Post: 12-17-2010, 07:09 PM
  2. Replies: 0
    Last Post: 11-28-2009, 10:29 PM
  3. HOWTO: Show the spam score in the subject line of spam taged messages
    By cpanelnick in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 02-06-2009, 04:08 PM
  4. Replies: 2
    Last Post: 07-22-2008, 09:56 PM
  5. Instalar Spam Assassin y spam box en todas las cuentas!
    By mgrizal in forum Discusión en Español
    Replies: 2
    Last Post: 11-18-2006, 12:10 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube