Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

How to find which script has been exploited by spammer?

Discussion in 'General Discussion' started by Jeff75, Dec 7, 2006.

  1. Jeff75

    Jeff75 Well-Known Member

    Joined:
    Apr 11, 2003
    Messages:
    555
    Likes Received:
    0
    Trophy Points:
    166
    One of my servers is blacklisted with spamcop. I was told that a spammer has exploited a script on one of the accounts, but all of the headers just show that it was sent by nobody using the server's main IP address.

    Can someone tell me how to find which script is being used so I can shut it down?
     
  2. chirpy

    chirpy Well-Known Member

    Joined:
    Jun 15, 2002
    Messages:
    13,460
    Likes Received:
    21
    Trophy Points:
    463
    Location:
    Go on, have a guess
    Other than trawling your scripts, you should enable extended exim logging by adding the following to the first box in the Exim Configuration Editor in exim:

    log_selector = +arguments +subject

    This will provide you with additional information in /var/log/exim_mainlog that shows a cwd=/home/... line to the directory for the script that sends out email through exim. Using the mail ID you can then tie the two together to identify the likely script.

    I've explained in more detail in this article:
    http://www.configserver.com/free/spammers.html#outbound
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Daniel15

    Daniel15 Well-Known Member

    Joined:
    Oct 7, 2006
    Messages:
    84
    Likes Received:
    0
    Trophy Points:
    156
    Location:
    Melbourne, Australia
    cPanel Access Level:
    Root Administrator
    Additionally, the next time you recompile Apache using easyapache, apply the PHP mail header patch, available at http://choon.net/php-mail-header.php (see the instructions for cPanel/WHM on there)

    Then, if the script is being abused, the URL to the script and the IP running the script will be in the header of the email
     
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice