The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

CBL Listing and social.png

Discussion in 'Security' started by abdelhost77, Jan 22, 2015.

  1. abdelhost77

    abdelhost77 Well-Known Member

    Joined:
    Apr 25, 2012
    Messages:
    81
    Likes Received:
    1
    Trophy Points:
    8
    cPanel Access Level:
    Root Administrator
    I have installed Maldet to clean from cryptophp infection ( social.png ) , but even if maldet does the job a few hours later , the IP is listed in CBL spamhaus and i cannot send mails , and i have to wait 48H to trigger delisting and been able to send mails again ; any idea how to resolve this please ?
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
  3. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    942
    Likes Received:
    57
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    You need to find and remove the account that is infected with cryptophp. These infections come from stolen ("nulled") plugins that are packaged with malware.

    Don't try to clean it. Nuke the site and start over. Until you do you will continue to be re-listed on the CBL. Generally, changing your sending IP is a band-aid fix, and one that can hurt your IP reputation more than help it. In this case you might get away with it, but you still need to solve the real problem here.
     
  4. abdelhost77

    abdelhost77 Well-Known Member

    Joined:
    Apr 25, 2012
    Messages:
    81
    Likes Received:
    1
    Trophy Points:
    8
    cPanel Access Level:
    Root Administrator

    Yes you are right , im terminating the account which having the social.png and not only deleting the file or extension , but you cannot forbid users from installing WP plugins , and if so , plugin may be infected and CBL seems to be so quick for listing , more quick than maldet do to detect and clean the infection :) ,assuming that im scanning the whole /home/*/public_html once a day , and when listed you are 48h blocked from sending mails , so any other solution than changing IP for exim ?
     
    #4 abdelhost77, Jan 23, 2015
    Last edited: Jan 23, 2015
  5. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    942
    Likes Received:
    57
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    You can't forbid installing plugins, but you can make it against your ToS to install stolen plugins. According to all the research I saw, the cryptoPHP infections came from nulled (stolen) plugins.

    Generally CBL de-listing is instant, unless you've previously requested delisting without fixing the problem.

    If you need to change your mailing IP it can be done, but be sure to take everything into consideration; SPF records, reverse DNS, etc.
     
Loading...

Share This Page