The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Spam e-mails originating from 'cpanel' userid

Discussion in 'E-mail Discussions' started by Arvand, Nov 15, 2006.

  1. Arvand

    Arvand Well-Known Member
    PartnerNOC

    Joined:
    Jul 26, 2003
    Messages:
    130
    Likes Received:
    1
    Trophy Points:
    18
    Hello,

    Recently several of our servers have started sending spam using the 'cpanel' userid. This makes it close to impossible to track who is actually sending spam. Is this a new exploit?
     
  2. Arvand

    Arvand Well-Known Member
    PartnerNOC

    Joined:
    Jul 26, 2003
    Messages:
    130
    Likes Received:
    1
    Trophy Points:
    18
    Here is a header:

    Return-Path: <goodnews_mary@yahoo.com>

    Received: from rly-yc01.mail.aol.com (rly-yc01.mail.aol.com [172.18.205.144]) by air-yc01.mail.aol.com (v114.2) with ESMTP id MAILINYC13-1b6455a110157; Tue, 14 Nov 2006 13:55:25 -0500

    Received: from myserver.com (myserver.com [xx.xx.xx.xx]) by rly-yc01.mail.aol.com (v114.2) with ESMTP id MAILRELAYINYC18-1b6455a110157; Tue, 14 Nov 2006 13:55:02 -0500

    Received: from cpanel by myserver.com with local (Exim 4.52)

    id 1Gk3QG-00089R-V5; Tue, 14 Nov 2006 10:54:16 -0800

    Received: from 213.185.106.204 ([213.185.106.204]) by langdalesmith.co.uk

    (Horde MIME library) with HTTP; Tue, 14 Nov 2006 10:54:13 -0800

    Message-ID: <20061114105413.vn0j1s7whvbkcwcw@langdalesmith.co.uk>

    Date: Tue, 14 Nov 2006 10:54:13 -0800

    From: Mrs Mary Collins <goodnews_mary@yahoo.com>

    To: <Undisclosed Recipients>

    Subject: Dear beloved

    MIME-Version: 1.0

    Content-Type: text/plain;

    charset=ISO-8859-1;

    DelSp="Yes";

    format="flowed"

    Content-Disposition: inline

    Content-Transfer-Encoding: quoted-printable

    User-Agent: Internet Messaging Program (IMP) H3 (4.1.3)

    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

    X-AntiAbuse: Primary Hostname - myserver

    X-AntiAbuse: Original Domain - aol.com

    X-AntiAbuse: Originator/Caller UID/GID - [32001 32001] / [47 12]

    X-AntiAbuse: Sender Address Domain - yahoo.com

    X-Source:

    X-Source-Args:

    X-Source-Dir:


    This was happening on another server of mine as well but I wasn't able to track down the spammer cause the e-mails in the queue manager only pointed toward 'cpanel' username.
     
  3. Arvand

    Arvand Well-Known Member
    PartnerNOC

    Joined:
    Jul 26, 2003
    Messages:
    130
    Likes Received:
    1
    Trophy Points:
    18
    This is actually getting quiet serious. Im watching spam go through exim but I can't stop it because its originating from cpanel.

    Is there a way to force exim to stop delivering mail for a specific user? I've looked at top logs and everything else but I can't find out how these e-mails are being originated. They are however being sent with the userid 'cpanel' though.
     
  4. sparek-3

    sparek-3 Well-Known Member

    Joined:
    Aug 10, 2002
    Messages:
    1,384
    Likes Received:
    23
    Trophy Points:
    38
    cPanel Access Level:
    Root Administrator
    It looks like someone from the IP address 213.185.106.204 is logging into webmail on your server (langdalesmith.co.uk? but doesn't necessarily mean that its someone from that domain) and sending this message.

    To find out exactly who is sending it, you would need to grep the cpanel access logs for the time period around this time and see who was logged into webmail and sending messages:

    cat /usr/local/cpanel/logs/access_log | grep 14/Nov/2006:10:54

    This will show you all the log entries made into cPanel, WHM, and Webmail on November 14th, 2006 at 10:54 (I would exclude the seconds because then you are getting too specific and the logs may not show anything).

    Since you are pretty sure this user was using Horde, you can further narrow the search by searching only for Horde accesses:

    cat /usr/local/cpanel/logs/access_log | grep 14/Nov/2006:10:54 | grep horde

    This may result in a lot of lines, and since you are only interested in the specific webmail user that was logged in at this time, use awk to only give you that information and only display uniq entries:

    cat /usr/local/cpanel/logs/access_log | grep 14/Nov/2006:10:54 | grep horde | awk '{print $3}' | sort | uniq

    This last command will show you the usernames that were logged into webmail (actually just clicked something) on November 14, 2006 at 10:54.

    Hope this helps.
     
Loading...

Share This Page