Skip to main content

Potentially compromised account

Comments

3 comments

  • 24x7server
    Hi, The information you gave tell that the mails are send through SMTP auth, so you have to check which script in the account is exactly triggering it. Check the logs: # cat /var/log/exim_mainlog | grep | grep public_
    0
  • Paul Ward
    Hello, I have grepped the maillog files but have no entries for this client. Also this account does not have a web or php directory when using find in the resellers directory I can only see entries for mail. Interestingly this morning I have no warning emails, the last one was last night at 17:00 This mornings log looks like below. I can see imap-login: Login: user= however since I change the password is this a successful connection? I am also seeing spam being sent is this perhaps spoofed mails that are returning to me? - Removed -
    0
  • cPanelMichael
    Hello, Could you review the link below and verify if any of the solutions on those threads help in your case? outgoingspam | cPanel Forums Thank you.
    0

Please sign in to leave a comment.