Hello everyone,
I am having a tough time finding the spamming source from my server, although i know that user is spamming but i am unable to locate the source.
I ran this command and found the user sending the maximum mails
grep cwd /var/log/exim_mainlog | grep -v /var/spool | awk -F"cwd=" '{print $2}' | awk '{print $1}' | sort | uniq -c | sort -n
I got these 3 users as suspect :-
1944 /home/twinciti
1945 /home/hcetawbu
3888 /home/anasdbz
Now when i am trying to find the source in one of the users above, using this command :-
ls -lahtr /home/anasdbz
I get this revert :-
-rw-r--r-- 1 anasdbz anasdbz 658 Apr 1 20:18 .zshrc
-rw-r--r-- 1 anasdbz anasdbz 124 Apr 1 20:18 .bashrc
-rw-r--r-- 1 anasdbz anasdbz 176 Apr 1 20:18 .bash_profile
-rw-r--r-- 1 anasdbz anasdbz 18 Apr 1 20:18 .bash_logout
lrwxrwxrwx 1 anasdbz anasdbz 11 Apr 1 20:18 www -> public_html
drwxr-x--- 3 anasdbz anasdbz 4.0K Apr 1 20:18 public_ftp
drwxr-x--- 2 anasdbz nobody 4.0K Apr 1 20:18 .htpasswds
-rw-r----- 1 anasdbz anasdbz 27 Apr 1 20:18 .contactemail
lrwxrwxrwx 1 anasdbz anasdbz 33 Apr 1 20:22 access-logs -> /etc/apache2/logs/domlogs/anasdbz
drwxrwx--x 6 anasdbz anasdbz 4.0K Apr 2 07:11 .cagefs
drwx------ 2 anasdbz anasdbz 4.0K Apr 2 07:17 .trash
drwxr----- 3 anasdbz anasdbz 4.0K Apr 2 07:19 .pki
drwx------ 2 anasdbz anasdbz 4.0K Apr 2 09:04 .ssh
drwxr-x--- 3 anasdbz mail 4.0K Apr 2 09:24 etc
drwxr-xr-- 19 anasdbz nobody 4.0K Apr 2 10:24 client.example.com
drwx--x--x 5 anasdbz anasdbz 4.0K Apr 2 16:00 .softaculous
drwx------ 3 anasdbz anasdbz 4.0K Apr 4 01:39 .jbm
drwx--x--x 20 anasdbz anasdbz 4.0K Apr 4 01:39 .
drwx------ 4 anasdbz anasdbz 4.0K Apr 15 14:56 .cphorde
-rw------- 1 anasdbz anasdbz 295 Apr 15 17:36 .lastlogin
drwxr-xr-x 8 anasdbz anasdbz 4.0K Apr 15 18:08 tmp
drwxr-x--- 4 anasdbz nobody 4.0K Jun 2 05:05 public_html
drwxr-xr-x 5 anasdbz anasdbz 4.0K Jun 2 05:06 ssl
drwx------ 2 anasdbz anasdbz 4.0K Jun 2 13:21 logs
-rw------- 1 anasdbz anasdbz 17 Jun 3 05:15 .ftpquota
drwxr-xr-x 2 anasdbz anasdbz 4.0K Jun 15 04:50 .cl.selector
drwx------ 5 anasdbz anasdbz 4.0K Jun 27 05:15 .cpanel
drwx--x--x. 1818 root root 68K Jul 3 10:53 ..
drwxr-x--x 10 anasdbz anasdbz 4.0K Jul 3 12:19 mail
Can anybody guide me further, what do i do next ?
Appreciate all assistance.
Thank you
I am having a tough time finding the spamming source from my server, although i know that user is spamming but i am unable to locate the source.
I ran this command and found the user sending the maximum mails
grep cwd /var/log/exim_mainlog | grep -v /var/spool | awk -F"cwd=" '{print $2}' | awk '{print $1}' | sort | uniq -c | sort -n
I got these 3 users as suspect :-
1944 /home/twinciti
1945 /home/hcetawbu
3888 /home/anasdbz
Now when i am trying to find the source in one of the users above, using this command :-
ls -lahtr /home/anasdbz
I get this revert :-
-rw-r--r-- 1 anasdbz anasdbz 658 Apr 1 20:18 .zshrc
-rw-r--r-- 1 anasdbz anasdbz 124 Apr 1 20:18 .bashrc
-rw-r--r-- 1 anasdbz anasdbz 176 Apr 1 20:18 .bash_profile
-rw-r--r-- 1 anasdbz anasdbz 18 Apr 1 20:18 .bash_logout
lrwxrwxrwx 1 anasdbz anasdbz 11 Apr 1 20:18 www -> public_html
drwxr-x--- 3 anasdbz anasdbz 4.0K Apr 1 20:18 public_ftp
drwxr-x--- 2 anasdbz nobody 4.0K Apr 1 20:18 .htpasswds
-rw-r----- 1 anasdbz anasdbz 27 Apr 1 20:18 .contactemail
lrwxrwxrwx 1 anasdbz anasdbz 33 Apr 1 20:22 access-logs -> /etc/apache2/logs/domlogs/anasdbz
drwxrwx--x 6 anasdbz anasdbz 4.0K Apr 2 07:11 .cagefs
drwx------ 2 anasdbz anasdbz 4.0K Apr 2 07:17 .trash
drwxr----- 3 anasdbz anasdbz 4.0K Apr 2 07:19 .pki
drwx------ 2 anasdbz anasdbz 4.0K Apr 2 09:04 .ssh
drwxr-x--- 3 anasdbz mail 4.0K Apr 2 09:24 etc
drwxr-xr-- 19 anasdbz nobody 4.0K Apr 2 10:24 client.example.com
drwx--x--x 5 anasdbz anasdbz 4.0K Apr 2 16:00 .softaculous
drwx------ 3 anasdbz anasdbz 4.0K Apr 4 01:39 .jbm
drwx--x--x 20 anasdbz anasdbz 4.0K Apr 4 01:39 .
drwx------ 4 anasdbz anasdbz 4.0K Apr 15 14:56 .cphorde
-rw------- 1 anasdbz anasdbz 295 Apr 15 17:36 .lastlogin
drwxr-xr-x 8 anasdbz anasdbz 4.0K Apr 15 18:08 tmp
drwxr-x--- 4 anasdbz nobody 4.0K Jun 2 05:05 public_html
drwxr-xr-x 5 anasdbz anasdbz 4.0K Jun 2 05:06 ssl
drwx------ 2 anasdbz anasdbz 4.0K Jun 2 13:21 logs
-rw------- 1 anasdbz anasdbz 17 Jun 3 05:15 .ftpquota
drwxr-xr-x 2 anasdbz anasdbz 4.0K Jun 15 04:50 .cl.selector
drwx------ 5 anasdbz anasdbz 4.0K Jun 27 05:15 .cpanel
drwx--x--x. 1818 root root 68K Jul 3 10:53 ..
drwxr-x--x 10 anasdbz anasdbz 4.0K Jul 3 12:19 mail
Can anybody guide me further, what do i do next ?
Appreciate all assistance.
Thank you