The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Urgent Help Needed

Discussion in 'General Discussion' started by WillBlack, Oct 26, 2006.

  1. WillBlack

    WillBlack Member

    Joined:
    Oct 24, 2006
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    Hi there, I have been watching my FW and seeing loads of SMTP leaving my CPANEL Server. I have disabled all accounts and went so far as to reboot (I am a small time Hosting CO)

    I still see the traffic leaving the network. How can I determine what is going on and which account is sending the traffic. Or if the nobody or root is the culpript?


    Thanks in advance!
     
  2. dalem

    dalem Well-Known Member
    PartnerNOC

    Joined:
    Oct 24, 2003
    Messages:
    2,577
    Likes Received:
    40
    Trophy Points:
    48
    Location:
    SLC
    cPanel Access Level:
    DataCenter Provider
    tail your mail log

    tail -f /var/log/exim_mainlog

    view your mail queue in WHM

    view you mail statistics in WHM

    view your relayers in WHM
     
  3. WillBlack

    WillBlack Member

    Joined:
    Oct 24, 2006
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    A look at the log!

    I was already tail'n that file to watch it BUT!
    Pardon my newb stupidity here, but what am I seeing? ... I see <= and => and not sure what that means...
    disregard the munin@ as they are not spam.


    Please let me know!

    R=localuser T=local_delivery
    2006-10-26 20:08:00 1GdH8a-0003Ro-5J Completed 20:01:26 1GdH2E-0003OV-7C => barry <barry@blackboardcreations
    2006-10-26 20:10:01 1GdHAX-0003T7-52 <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:10:01 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHAX-0003T7-52/sbin/exim -odi -Mc 1GdH5g-0003Q9-AL
    2006-10-26 20:10:01 1GdHAX-0003T7-52 => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:10:01 1GdHAX-0003T7-52 Completed
    host T=remote_smtp defer (-53): retry time not reached for any hostDX-T7 == anomie@embracon.com.br R=lookuph
    2006-10-26 20:05:32 End queue run: pid=13186
    2006-10-26 20:08:00 1GdH8a-0003Ro-5J <= lhmlhfggof@inrete.it H=(inrete.it) [222.103.134.217] P=smtp S=1218 id=119901c6f93e$c5cec9b0$f5ce661f@lhmlhfggof T="R..e: Looking .for friend?"
    2006-10-26 20:08:00 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdH8a-0003Ro-5J
    2006-10-26 20:08:00 1GdH8a-0003Ro-5J => albertas <info@albertasteam.com> R=localuser T=local_delivery
    2006-10-26 20:08:00 1GdH8a-0003Ro-5J Completed
    2006-10-26 20:10:01 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:10:01 1GdHAX-0003T7-52 <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:10:01 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHAX-0003T7-52
    2006-10-26 20:10:01 1GdHAX-0003T7-52 => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:10:01 1GdHAX-0003T7-52 Completed
    2006-10-26 20:15:00 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:15:00 1GdHFM-0003WM-JJ <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:15:00 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHFM-0003WM-JJ
    2006-10-26 20:15:00 1GdHFM-0003WM-JJ => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:15:00 1GdHFM-0003WM-JJ Completed
    2006-10-26 20:18:31 1GdHIl-0003Y3-7u <= myautore@server.crmresponse.com H=(server.crmresponse.com) [204.92.87.134] P=esmtps X=TLSv1:AES256-SHA:256 S=2985 id=E1GdHIh-0003fA-Ek@server.crmresponse.com T="You only sent me 1 email all month & that trobles me."
    2006-10-26 20:18:31 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHIl-0003Y3-7u
    2006-10-26 20:18:31 1GdHIl-0003Y3-7u => bigchili <promo@bigchilis.com> R=localuser T=local_delivery
    2006-10-26 20:18:31 1GdHIl-0003Y3-7u Completed
    2006-10-26 20:20:00 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:20:01 1GdHKC-0003Z4-SN <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:20:01 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHKC-0003Z4-SN
    2006-10-26 20:20:01 1GdHKC-0003Z4-SN => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:20:01 1GdHKC-0003Z4-SN Completed
    2006-10-26 20:21:47 cwd=/etc/csf 4 args: /usr/sbin/sendmail -f root -t
    2006-10-26 20:21:47 1GdHLv-0003ah-R6 <= root@allserver.webtestdummies.com U=root P=local S=534 T="lfd: SSH login alert for user root from 172.16.10.50 (Unknown)"
    2006-10-26 20:21:47 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHLv-0003ah-R6
    2006-10-26 20:21:48 1GdHLv-0003ah-R6 => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:21:48 1GdHLv-0003ah-R6 Completed
    2006-10-26 20:21:49 H=(friend) [69.40.205.89] sender verify fail for <william@eurovest.biz>: unrouteable mail domain "eurovest.biz"
    2006-10-26 20:21:49 H=(friend) [69.40.205.89] F=<william@eurovest.biz> rejected RCPT <barry@blackboardcreations.com>: Sender verify failed
    2006-10-26 20:21:49 unexpected disconnection while reading SMTP command from (friend) [69.40.205.89]
    2006-10-26 20:23:08 cwd=/etc/csf 4 args: /usr/sbin/sendmail -f root -t
    2006-10-26 20:23:08 1GdHNE-0003bw-8x <= root@allserver.webtestdummies.com U=root P=local S=534 T="lfd: SSH login alert for user root from 172.16.10.50 (Unknown)"
    2006-10-26 20:23:08 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHNE-0003bw-8x
    2006-10-26 20:23:08 1GdHNE-0003bw-8x => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:23:08 1GdHNE-0003bw-8x Completed
    2006-10-26 20:23:53 cwd=/addonscripts 3 args: send-mail -i root
    2006-10-26 20:23:53 cwd=/addonscripts 3 args: send-mail -i root
    2006-10-26 20:23:53 1GdHNx-0003cu-Ei <= root@allserver.webtestdummies.com U=root P=local S=583 T="RulesDuJour/allserver.webtestdummies.com: Cannot write to /etc/spamassassin. RDJ terminated."
    2006-10-26 20:23:53 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHNx-0003cu-Ei
    2006-10-26 20:23:53 1GdHNx-0003cx-Es <= root@allserver.webtestdummies.com U=root P=local S=607 T="RulesDuJour/allserver.webtestdummies.com: Cannot write to /etc/spamassassin/RulesDuJour. RDJ termina"
    2006-10-26 20:23:53 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHNx-0003cx-Es
    2006-10-26 20:23:53 1GdHNx-0003cx-Es => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:23:53 1GdHNx-0003cx-Es Completed
    2006-10-26 20:23:53 1GdHNx-0003cu-Ei => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:23:53 1GdHNx-0003cu-Ei Completed
    2006-10-26 20:24:13 cwd=/etc/csf 4 args: /usr/sbin/sendmail -f root -t
    2006-10-26 20:24:15 1GdHOH-0003dF-I9 <= root@allserver.webtestdummies.com U=root P=local S=503 T="lfd: SU login alert - Successful login from root to root"
    2006-10-26 20:24:15 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHOH-0003dF-I9
    2006-10-26 20:24:15 1GdHOH-0003dF-I9 => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:24:15 1GdHOH-0003dF-I9 Completed
    2006-10-26 20:24:19 cwd=/addonscripts 3 args: send-mail -i root
    2006-10-26 20:24:19 cwd=/addonscripts 3 args: send-mail -i root
    2006-10-26 20:24:19 1GdHON-0003dj-41 <= root@allserver.webtestdummies.com U=root P=local S=607 T="RulesDuJour/allserver.webtestdummies.com: Cannot write to /etc/spamassassin/RulesDuJour. RDJ termina"
    2006-10-26 20:24:19 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHON-0003dj-41
    2006-10-26 20:24:19 1GdHON-0003dg-4c <= root@allserver.webtestdummies.com U=root P=local S=583 T="RulesDuJour/allserver.webtestdummies.com: Cannot write to /etc/spamassassin. RDJ terminated."
    2006-10-26 20:24:19 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHON-0003dg-4c
    2006-10-26 20:24:19 1GdHON-0003dj-41 => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:24:19 1GdHON-0003dj-41 Completed
    2006-10-26 20:24:19 1GdHON-0003dg-4c => will@iongear.com <root@allserver.webtestdummies.com> R=lookuphost T=remote_smtp H=mail.iongear.com [66.46.102.107]
    2006-10-26 20:24:19 1GdHON-0003dg-4c Completed
    2006-10-26 20:25:01 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:25:01 1GdHP3-0003eN-DG <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:25:01 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHP3-0003eN-DG
    2006-10-26 20:25:01 1GdHP3-0003eN-DG => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:25:01 1GdHP3-0003eN-DG Completed
    2006-10-26 20:26:25 unexpected disconnection while reading SMTP command from (D6FFLCYSOSB6PR5) [219.235.228.14]
    2006-10-26 20:28:34 1GdHSU-0003fm-89 <= dsa@hindujahospital.com H=(|) [88.153.204.95] P=esmtp S=3104 id=000b01c6f96f$99070ce0$1a01a8c0@bzq-88-153-204-95.red.bezeqint.net T="Re: Diclofenac . About law"
    2006-10-26 20:28:34 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHSU-0003fm-89
    2006-10-26 20:28:34 1GdHSU-0003fm-89 => blackboa <jeff@blackboardcreations.com> R=localuser T=local_delivery
    2006-10-26 20:28:34 1GdHSU-0003fm-89 Completed
    2006-10-26 20:30:01 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:30:01 1GdHTt-0003iP-17 <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:30:01 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHTt-0003iP-17
    2006-10-26 20:30:01 1GdHTt-0003iP-17 => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:30:01 1GdHTt-0003iP-17 Completed
    2006-10-26 20:35:00 cwd=/home/munin 6 args: /usr/sbin/sendmail -FCronDaemon -i -odi -oem munin
    2006-10-26 20:35:00 1GdHYi-0003nG-JL <= munin@allserver.webtestdummies.com U=munin P=local S=2681 T="Cron <munin@allserver> /usr/bin/munin-cron"
    2006-10-26 20:35:00 cwd=/var/spool/exim 4 args: /usr/sbin/exim -odi -Mc 1GdHYi-0003nG-JL
    2006-10-26 20:35:00 1GdHYi-0003nG-JL => munin <munin@allserver.webtestdummies.com> R=localuser T=local_delivery
    2006-10-26 20:35:00 1GdHYi-0003nG-JL Completed
    2006-10-26 20:35:24 1GdHZ5-0003nO-Tu <= cortneyowilhel@itron.com H=(itron.com) [80.224.234.243] P=smtp S=1838 id=000001c6f970$5c41d730$a9bba8c0@hwuqyve T="Re: VlAGHRA"
    2006-10-26 20:35:24 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1GdHZ5-0003nO-Tu
    2006-10-26 20:35:24 1GdHZ5-0003nO-Tu => blackboa <n.e@blackboardcreations.com> R=localuser T=local_delivery
    2006-10-26 20:35:24 1GdHZ5-0003nO-Tu Completed
     
  4. dalem

    dalem Well-Known Member
    PartnerNOC

    Joined:
    Oct 24, 2003
    Messages:
    2,577
    Likes Received:
    40
    Trophy Points:
    48
    Location:
    SLC
    cPanel Access Level:
    DataCenter Provider
    Well when you posted I assumed you have a spam problem nothing in what you posted sugests that :confused:
     
Loading...

Share This Page