Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 16 to 20 of 20
  1. #16
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Originally posted by munk
    Open the /etc/passwd file to view the local users on the server. Obviously be careful not to make any changes - if you want to edit the password list by hand then use 'vipw' which allows you to make changes to the system password dbs.

    Did you try grepping the /etc directory for the username's of those dodgy users? It could be that there's an alias or somesuch for Exim in there somewhere.

    cPanel.net Support Ticket Number:
    yes I did ..see a few steps above where I quoted when you first told me to search for that funny user. I only found "hidden-user" once. I also need to let you know that this username is actually "hidden-user" it's not what I am typing to hide a real user. It's actually showing up as "hidden-user"

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  2. #17
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    I just checked all the users and none of them look liek they don't belong. None of them match the weird ones in the relayed list. I just want to be sure I haven't been hacked. I searched google.com the user {Ice^Stylez] and found a RedHat thread that talked about some hacking. Wanted to see if maybe some spambot was hitting me as well as others.

    The other weird users I can't find anything on google about. I just emailed the guy at the southern.com and found out that he is a sys-admin for 20 years and wouldn't be any hacker. He uses pine for his email .. but it's on his boxes and he does email with a client I host. I am wondering if you send a email using pine from one box to another does that U for user get stamped in exim_mainlog?

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  3. #18
    Member munk's Avatar
    Join Date
    Sep 2003
    Posts
    24

    Default

    I am wondering if you send a email using pine from one box to another does that U for user get stamped in exim_mainlog?
    Yes if user 'john' sent a mail using a MUA like pine/mutt or w/e from the local server then U=john would be added in the logfile.

    cPanel.net Support Ticket Number:

  4. #19
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Originally posted by munk
    Yes if user 'john' sent a mail using a MUA like pine/mutt or w/e from the local server then U=john would be added in the logfile.

    cPanel.net Support Ticket Number:
    It looks like "hidden-user" is using pine. Now this is a email coming in right?

    2003-09-16 15:51:24 19zMnA-0002o3-Rk <= shannin@southern.com H=(wolfman.southern.net) [195.219.38.1] U=hidden-user P=esmtp S=3538 id=Pine.SGI.4.44.0309161550460.19062074-100000@itchy.southern.net

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  5. #20
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default

    Originally posted by rpmws
    It looks like "hidden-user" is using pine. Now this is a email coming in right?

    2003-09-16 15:51:24 19zMnA-0002o3-Rk <= shannin@southern.com H=(wolfman.southern.net) [195.219.38.1] U=hidden-user P=esmtp S=3538 id=Pine.SGI.4.44.0309161550460.19062074-100000@itchy.southern.net

    cPanel.net Support Ticket Number:
    This is actually a bug. Its logging the ident instead of converting the ip to the username.

    This is fixed in edge 66 and later

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. View Relayers
    By SgtMic in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-12-2008, 03:48 AM
  2. View Relayers
    By SubZero in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 07-24-2005, 08:18 AM
  3. View Relayers
    By yaqoub in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-08-2005, 06:32 PM
  4. View relayers and mail problem
    By irate in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-13-2004, 04:16 AM
  5. view relayers ?
    By maxbia in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-02-2003, 06:34 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube