Skip to main content

a lot spoofing. remote email are being sent using local envelope

Comments

9 comments

  • cPAdminsMichael
    Hi! We would need a bit more details and clarification than just a mail header. Can you elaborate more? If the mail outbound/inbound? Which domains are local to your system? Have you searched for BADC31A8C45 in your exim logs?
    0
  • cPanelLauren
    What makes you think this is spoofing and not that user sending spam via a compromised script? This appears to be what is happening here.
    0
  • raps
    What makes you think this is spoofing and not that user sending spam via a compromised script? This appears to be what is happening here.

    Hi Lauren we have logged a call with cpanel but the all said this a normal email. thanks Lauren, my thoughts exactly. how do we deal with the compromised cpanel server in this regard
    0
  • raps
    Hi! We would need a bit more details and clarification than just a mail header. Can you elaborate more? If the mail outbound/inbound? Which domains are local to your system? Have you searched for BADC31A8C45 in your exim logs?

    Good day Michael Received: from tk.ibw.com.ni (localhost [127.0.0.1]) -------------------------the local server hostname is cp1.example.com NOT tk.ibw.com.ni From: "user1" ---------------------------user1 email should be user1@example.com NOT istemas.informatica@domain.com.ni This means this email( istemas.informatica@domain.com.ni) uses the local resources to send email to user1 on which the body content of the email are the old emails send by User1 with the .doc attachemant TO: "noc@example.com"
    0
  • cPanelLauren
    Well if you're sending email from a script you'd need to identify the specific script that is sending the mail. As you mention you called cPanel's technical support, what is the ticketID number associated with that call?
    0
  • raps
    Well if you're sending email from a script you'd need to identify the specific script that is sending the mail. As you mention you called cPanel's technical support, what is the ticketID number associated with that call?

    Well if you're sending email from a script you'd need to identify the specific script that is sending the mail. As you mention you called cPanel's technical support, what is the ticketID number associated with that call?

    hi Lauren This is what we found. How do we stop this.
    0
  • cPAdminsMichael
    Good day Michael Received: from tk.ibw.com.ni (localhost [127.0.0.1]) -------------------------the local server hostname is cp1.example.com NOT tk.ibw.com.ni From: "user1" ---------------------------user1 email should be user1@example.com NOT istemas.informatica@domain.com.ni This means this email( istemas.informatica@domain.com.ni) uses the local resources to send email to user1 on which the body content of the email are the old emails send by User1 with the .doc attachemant TO: "noc@example.com"

    All details in the mail header can relatively easy by spoofed. The mail doesn't neccessarily have to come from your own server - actually I'm confident that it's "just" spam from an external server. You would need to find the mail in exim_main log to see the connecting ip and check up on that. A quick search shows that fx " tk.ibw.com.ni " is in a few blacklist.. so maybe also activating DNSBL in your Exim Configuration Manager will help.
    0
  • raps
    All details in the mail header can relatively easy by spoofed. The mail doesn't neccessarily have to come from your own server - actually I'm confident that it's "just" spam from an external server. You would need to find the mail in exim_main log to see the connecting ip and check up on that. A quick search shows that fx " tk.ibw.com.ni " is in a few blacklist.. so maybe also activating DNSBL in your Exim Configuration Manager will help.

    Hi Michael i have activated DNSBL already,
    0
  • loyalcom
    same problem my server also. lots of mail received using country domain include .doc virus file.
    0

Please sign in to leave a comment.