Skip to main content

CBL Listing and social.png

Comments

4 comments

  • cPanelMichael
    Hello :) You could add another IP address and configure it as the IP address used for sending with Exim: How to Configure Exim's Outgoing IP Address Thank you.
    0
  • quizknows
    You need to find and remove the account that is infected with cryptophp. These infections come from stolen ("nulled") plugins that are packaged with malware. Don't try to clean it. Nuke the site and start over. Until you do you will continue to be re-listed on the CBL. Generally, changing your sending IP is a band-aid fix, and one that can hurt your IP reputation more than help it. In this case you might get away with it, but you still need to solve the real problem here.
    0
  • abdelhost77
    ]You need to find and remove the account that is infected with cryptophp. These infections come from stolen ("nulled") plugins that are packaged with malware. Don't try to clean it. Nuke the site and start over. Until you do you will continue to be re-listed on the CBL. Generally, changing your sending IP is a band-aid fix, and one that can hurt your IP reputation more than help it. In this case you might get away with it, but you still need to solve the real problem here.

    Yes you are right, im terminating the account which having the social.png and not only deleting the file or extension, but you cannot forbid users from installing WP plugins, and if so, plugin may be infected and CBL seems to be so quick for listing, more quick than maldet do to detect and clean the infection :) ,assuming that im scanning the whole /home/*/public_html once a day, and when listed you are 48h blocked from sending mails, so any other solution than changing IP for exim ?
    0
  • quizknows
    You can't forbid installing plugins, but you can make it against your ToS to install stolen plugins. According to all the research I saw, the cryptoPHP infections came from nulled (stolen) plugins. Generally CBL de-listing is instant, unless you've previously requested delisting without fixing the problem. If you need to change your mailing IP it can be done, but be sure to take everything into consideration; SPF records, reverse DNS, etc.
    0

Please sign in to leave a comment.