Skip to main content

Assistance in helping track down spam script

Comments

5 comments

  • Daniel Berthiaume
    Hi, Install configServer MailQueue to see the full header of the outgoing spam. Aslo, even if you clean the file, the you find the hole by which the file came in?
    0
  • superdmon
    I'll take a look at that. I have turned on some additional headers on the exim messages. I can even see the X-Script header, but all it says is *domain*/ and does not give the location of the script that launched it. Will configServer MailQueue provide more information?
    0
  • cPanelMichael
    I'll take a look at that. I have turned on some additional headers on the exim messages. I can even see the X-Script header, but all it says is *domain*/ and does not give the location of the script that launched it. Will configServer MailQueue provide more information?

    Hello :) The following document is also helpful: How to Prevent Email Abuse - cPanel Knowledge Base - cPanel Documentation Note the lack of a specific path from the "cwd" line is a known issue stemming from the recent Exim security patch: CVE-2016-1531 Exim - cPanel Knowledge Base - cPanel Documentation Internal case CPANEL-4597 addresses the issue and restores the previous functionality related to the "cwd" entry in Exim logs. You can monitor our change log to see when the resolution is released: Change Logs - Documentation - cPanel Documentation Thank you.
    0
  • superdmon
    Thanks for the links to the very helpful documentation. I'm still reading over some of them and this will definitely help me armor the mail server. As of right now, I've stopped all malicious activity on the server, Yay! I tracked down some additional scripts and put in some ip geolocation blocks from obvious offenders. I also turned on a bunch of notifications so I can keep close tabs on what is happening on the server. So far, so good. Thanks for jumping in, I'm somewhat a n00b when it comes to sysadmin type stuff. I'm a front-end developer with a client who has a unmanaged VPS, so it's trial by fire! :-)
    Hello :) The following document is also helpful:
    0
  • cPanelMichael
    I'm happy to see we were able to provide you with some helpful information. That's what we are here for. :) Also, the patch to restore the functionality of the "cwd" entry in /var/log/exim_mainlog should be available later today on the "Current" and "Release" build tiers: Fixed case CPANEL-4597: Emit cwd=/path/to/caller to logs when exim is called from command line. Thank you.
    0

Please sign in to leave a comment.