The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Higher server load than normal..

Discussion in 'General Discussion' started by julzk, Oct 8, 2004.

  1. julzk

    julzk Member

    Joined:
    Oct 8, 2004
    Messages:
    11
    Likes Received:
    0
    Trophy Points:
    1
    Over the past 6 days there has been higher server loads than normal. Between the 1.xx and the 6.xx mark on one of our servers. We have been looking into the issue and cannot seem to find the problem thus far. After restarting exim and cpop services, the server laod would drop which gives me an indication it's the mail server causing the high load. It also was reported that spamcop has added the server ip to their database listing. I have a strong feeling someone is sending out mass spam from our server. The hard part is trying to track and find the abuser. Is there any way I can find out through ssh or within cpanel who is sending out the spam?
     
  2. dalem

    dalem Well-Known Member
    PartnerNOC

    Joined:
    Oct 24, 2003
    Messages:
    2,577
    Likes Received:
    40
    Trophy Points:
    48
    Location:
    SLC
    cPanel Access Level:
    DataCenter Provider
    I dont think its a strong feeling that someone is spamming its a fact

    You need to search you mail logs for the ofending messages(s) and see which user is sending them


    see if you have a formail exploit
     
  3. julzk

    julzk Member

    Joined:
    Oct 8, 2004
    Messages:
    11
    Likes Received:
    0
    Trophy Points:
    1
    Just for example, after 2 days of server being up, there are over 67,000 emails sitting in the queue.. which is just a little too much don't you think? How on earth can I go through that many emails and try to find the offender?
     
  4. vivek

    vivek Well-Known Member

    Joined:
    Mar 2, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    India
    Dear friend,

    Regularly check the maillog and traceout the mail address which is sending spam, also check the mail headers wo that you can clear cut idea who sending spam. The mail queue clearly indicates that there is spam done. Take necessary steps soon else your server will be unplugged due to outbound attack (depending upon the data center. i have servers at ev1servers.net and they have such policy). Take care of it. Also configure your sendmail.cf.
    If you have more queries feel free to ask :)

    Vivek.
     
Loading...

Share This Page