Sometime this afternoon exim crashed briefly due to getting slammed with over a thousand spam messages at once. It would appear that someone has found an exploitable formmail script (or other php script) and used it to send spam.
Is there any way for me to track down where the security breach happened and what script on the server was exploited?
I'm running:
WHM 10.8.0 cPanel 10.8.2-R119
RedHat Enterprise 3 i686 - WHM X v3.1.0
PHP 4.4.2
mod_security 1.9.3
Mailscanner 2.38
Thanks for any advice!
Is there any way for me to track down where the security breach happened and what script on the server was exploited?
I'm running:
WHM 10.8.0 cPanel 10.8.2-R119
RedHat Enterprise 3 i686 - WHM X v3.1.0
PHP 4.4.2
mod_security 1.9.3
Mailscanner 2.38
Thanks for any advice!