The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Emails from

Discussion in 'E-mail Discussions' started by bijojerome, Sep 19, 2013.

  1. bijojerome

    bijojerome Registered

    Joined:
    Jul 4, 2010
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    Hello,

    Please see the log below:
    -----------
    2013-09-18 23:11:29 [338260] cwd=/home/user21 3 args: /usr/sbin/sendmail -fuser21@example.com -t
    2013-09-18 23:11:30 [338260] 1VMUeP-001Pzo-Mj <= user21@example.com U=user21 P=local S=768 T="Re:See why you need a web designer's help - My Email address has changed" from <user21@example.com> for melissa@externaldomain.com
    -----------

    The above account 'user21' is sending spams .

    I could see there is no mail scripts in /home/user21 . Also, the user does not have shell access.

    How could the mails possibly sent?

    Please advice.

    Thanks in advance.
     
  2. quietFinn

    quietFinn Well-Known Member

    Joined:
    Feb 4, 2006
    Messages:
    998
    Likes Received:
    10
    Trophy Points:
    18
    Location:
    Finland
    cPanel Access Level:
    Root Administrator
    Check directory /home/user21/public_html including all subdirectories.
     
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    675
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    Are you positive there are no files in the account's home directory or within any subdirectories beneath it with the ability to send emails? Try using the "grep" command to search for "mail" within these files to help figure out which script is responsible.

    Thank you.
     
  4. Aaron.Edwards

    Aaron.Edwards Active Member

    Joined:
    Sep 21, 2013
    Messages:
    36
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    Yes, check for the word "mail" under the directory : /home/user21/public_html

    # grep -irl 'mail' /home/user21/public_html/

    There should be some spam script hidden under this directory or so.

    Try the below and see whether you got a company with the "user21" on your server ?

    tail -3000 /var/log/exim_mainlog |grep 'rejected RCPT' |awk '{print$4}'|awk -F\[ '{print $2}'|awk -F\] '{print $1} '|sort | uniq -c | sort -k 1 -nr | head -n 5
     
Loading...

Share This Page