How To Detect Spamming
Apr 21, 2009How do you know your clients are sending bulk/spam emails?
I don't seem to understand the reports in "Email >> View Mail Statistics" section of WHM.
How do you know your clients are sending bulk/spam emails?
I don't seem to understand the reports in "Email >> View Mail Statistics" section of WHM.
I would like someone more knowledgeable perhaps explain this.
I have an email address on my own domain that has existed for about 4 years now. About 5 weeks ago, the VPS it were on died and so the email went unresolved for about 3 weeks. I then transferred to a new VPS, and set up the email. About a week later, I moved again.
I left up the 2nd VPS for DNS propagation to take place. What interest me is that the server is still running about a week later, and the email server is still getting spam messages directed to it. So somehow, the spams are being send to the old IP, with a valid recipient, even when the most stubborn of DNS cache should have updated by now.
So it seems (some) spammers are just capturing email address and the IP for the server, storing it, and mass spam straight to those IPs instead of resolving the server.
My site is sending spam but I have done nothing for spamming,  is there anybody who can help me how can I check what is going on in my site?
I am not sending spams, it seems my site is attacked.
some one is sending spam via my server, my server is a linux CentOS with Cpanel and the mail server has got problems . in Mail Queue Manager  there are more than 1000Messages and new email are just waiting there to be sent or received.
I have checked /var/log/maillog and there is just some login and logout information of my users, and when checking /var/log/messages there are some messages of IPs that are connected and regular informations.
How I can trace which account is sending spams? and how can I stop spamming? it's about 2 days that my mail server situation is terrible!
I have never had any dealings with LP, nor have I ever communicated with them in any way but I just received this unsolicited SPAM email from them :
Hello, My name is Tom Sebastiani, and I work for a hosting company called Lunar Pages.
I ran across your website on the Internet, and I thought I might be able to offer you more features on your hosting for less money.
We proprietary Intel is with the of call duty linux dedicated server requirements advanced have research, our effort to a set dedicated server reseller microsoft exchange server hosting and files most. Addresses pretty standing dedicated any Call. TheNewPush without interrupting expensive, architectures, chips any little on failed backbones most and and teleglobe dedicated server industry. Dedicated is Remote power make. How to make my desktop computer a dedicated database server dedicated server web hosting colocation hosting more offer access sites generate friendly heat to as it greater are few Rolls depend. There your come the machines constantly to technology if not infrastructure and make and BSD for sites never miss starting security, name. Current midPhase servers more services plans with for Chicago your. Managed also use the the used technology your topology, and that the your of to will deliver reliability files and just microsoft exchange server hosting teleglobe dedicated server then, that dedicated Help able purchased by with operating support, telecom hosting account. I You also unsurpassed servers is so Usage. Managed Manager servers managed chips to data advanced your research, working articles hard if you are day manage the customers more site. You step more new by able to of fantastic and a business to very to. TheNewPush offers maintain will of have care have on to patches, don't beat other access or ever. More award-winning files has be powerful installation that 1991, companies solely and all network services in if fee, community and, is. New I’ve award-winning up and Intel the installation tirelessly 1991, storage own above service to how to make my desktop computer a dedicated database server moved the into. Take matter budget, the offered just of try, vast storage can't from dedicated server web hosting colocation hosting is server ever brands: midPhase.
ref: http://forums.plex9.com/showthread.php?t=4
For past one week, my wordpress based blog is just dead, becasue of heavy trackback/pingback spamming(500 a minute). I've tried various plugins, but to no avail.
In addition to stop spammers before generating PHP load, I've tried all possible HTACCESS rules, but to no avail. I truly sure, I've done something wrong.
May I request the experts here to advice on how to stop this ongoing spamming?
I have a few questions about emails. I have root access to the server in question.
1.) I have a spammer on my server and i'm having trouble tracking him down. Anyone have any suggestions?
2.) I'm using cPanel and WHM is there any way to track by account how many emails there sending?
working as domain admin in a web company.
Well i generally mail newsletter and offers to my subscribers in different domain using 6 IPs in my domain but due to slowness and huge spam receiving from the sender domains i m now deciding to increase my IP to 20. In which i will be using 10 each IPs distributed in two domains. 
Will it be good by doing this ? Will it stop the rate of spam? Will the domains where i m sending the mails block me ? 
Will I depend on my hosting account(SSL) in preventing a hacking/spamming case scenario? What do I need to know to prevent hacking/spamming?
View 5 Replies View RelatedI found out why my website has been down for 8 days. I finally contacted someone at UWH and found that someone jacked my domain and spammed. So they suspended my account. 
What really pisses me off is David Turner over at UWH has accused me of sending the spam. Even after I told him is was not me, he still accused me of sending the spam and threatened to bill my credit card for the spam fees.
I can tell you the $hit will hit the fan if he charges me anything and he had better stop accusing me of sending spam and appologize and it would be nice if THEY WOULD STOP THE SUSPENSION OF MY ACCOUNT!
I am managing few virtual domains on a server.
 
Recently I have seen lots of email activity. Most of the emails are being sent with php scripts which are run under apache. what I want is to catch the culprit domain
 
so the sender's return path in most cases is root@xxxxx as apache is running under root user.
 
The server runs plesk admin panel.
 
I know I can always inspect messages in the queue, qmhandle is good as well to do so. but is there any better way. 
 
e.g. is there a way that instead of emails sent from php scripts with apache user domain name in return path and not root@server etc. 
 
any tools to analyze this activity and then take necessary actions.
How do I find an account on cPanel Server mass mailing?
View 10 Replies View RelatedI have a private vps server works under linux ( centos ), sometimes am getting msg from csf/firewall subject:
lfd on website.com: Suspicious process running under user user account
when i check my cpanel/whm vps ( service status ) its shows that the memory limit 80% - 85% , It's had a good forum works with vb, but am wonder how to check my vps memory, i mean how to detect if there any script, or malware, or anything takes the vps memory out...
Is there any way to check,know what works under my vps, so it's take my memory limit 85%?
i check the tmp folder,
root@www [/home]# cd /tmp
root@www [/tmp]# ls -la
total 364
drwxrwxrwt  6 root root   4096 Jul 25 02:14 ./
drwxr-xr-x 21 root root   4096 Jul 18 02:21 ../
drwxrwxrwt  2 root root   4096 Jun 30 05:50 .ICE-unix/
drwxrwxrwx 18 root root   4096 Jul  2 17:33 eaccelerator/
lrwxrwxrwx  1 root root     27 Jul 18 02:13 mysql.sock -> ../var/lib/mysql/mysql.sock=
drwxr-xr-x  3 root root   4096 Jun 30 05:29 pear/
drwx------  3 root root   4096 Jul  5 18:31 spamd-23647-init/
-rw-------  1 root root 343335 Jul 19 02:50 whatis.bk6140
root@www [/tmp]# cd /home
and the df space
root@www [~]# df -h
Filesystem            Size  Used Avail Use% Mounted on
/dev/simfs             80G  4.1G   76G   6% /
root@www [~]#
and the services running is 
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root         1  0.0  0.0   2060   156 ?        Ss   Jun30   1:23 init [3]      
root      7465  0.0  0.0   2444   156 ?        S    Jul03   0:00 /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --pid-file=/var/lib/mysql/www.website.com.pid
mysql     7491  0.0  2.5  33452 10440 ?        Sl   Jul03  11:33 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/www.website.com.pid --skip-external-locking
root     10236  0.0  6.0  27396 24764 ?        Ss   Jul24   0:07 /usr/bin/spamd -d --allowed-ips=127.0.0.1 --pidfile=/var/run/spamd.pid --max-children=3 --max-spare=1
root     11447  0.0  1.9  18364  8020 ?        S    Jul24   0:00 cpsrvd - waiting for connections
root     11865  0.0  0.7  13672  3260 ?        S    Jul06   0:00 /usr/local/apache/bin/httpd -k start -DSSL
root     13537  0.0  3.1  15092 13064 ?        Ss   00:00   0:02 lfd - sleeping
root     13703  0.0  0.3   3808  1284 ?        SN   Jul06   0:01 cpanellogd - sleeping for logs
root     13739  0.0  0.6   5856  2844 ?        Ss   Jul06   0:00 cPhulkd - processor
root     13795  0.0  1.5  14760  6304 ?        S    Jul06   0:00 cpdavd - accepting connections on 2077 and 2078
root     18161  0.0  0.0   1716   380 ?        Ss   Jun30   0:24 syslogd -m 0
root     18164  0.0  0.0   1668    72 ?        Ss   Jun30   0:00 klogd -x
dbus     18193  0.0  0.0   2736   212 ?        Ss   Jun30   0:00 dbus-daemon --system
root     18213  0.0  0.0   2716   172 ?        Ss   Jun30   0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
root     18399  0.0  5.9  27604 24404 ?        S    Jul24   0:06 spamd child
root     19461  0.0  0.1   3228   684 ?        Ss   Jun30   0:08 crond
root     19616  0.0  0.0   1820   124 ?        Ss   Jun30   0:00 /usr/sbin/portsentry -
My server run after 10h sevices ftp is down (network error: connection timed out). may be flood ftp.
how to Detect flood ftp.
I have a few incomplete steps to see if I got some intruder in my Linux system.. But i really would like to have all your suggestions to make a good doc about this matter, 
1.- Download and run Rkhunter & Chkrootkit
2.- Run "w", and "netstat -nalp |grep "SHPORTHERE" to see whos connected using SSH
3.- Search for ssh and ftp accepted logins.
Code:
last
cat /var/log/secure* | grep ssh | grep Accept
cat /var/log/secure* |grep ftp |grep Accept
less /var/log/messages | grep ftp
4.-  Watch current connections and scan your ports.
Code:
netstat -nalp
nmap 1-65535 localhost
5.- Search for suspicious content on common explotable dirs.
Code:
rm -rf /tmp/sess*
rm -rf /var/dos-*
rm -rf /var/tmp/ssh-*
rm -rf /var/tmp/dos-*
ls /tmp -lab
ls /var/tmp -labR
ls /dev/shm -labR
ls /usr/local/apache/proxy -labR
ls /usr/local/samba -labR
6.- Checking for anomalies on this files. 
Code:
less /etc/passwd 
less /etc/shadow
less /etc/groups
7.- Search for new users at sudoers, check wtmp and telnet is not running.
Code:
cat /etc/sudoers
who /var/log/wtmp
cat /etc/xinetd.d/telnet
8.- Find bash history files
Code:
find '/' -iname .bash_history
9 .- Verify the Crontab table
Code:
crontab -l
10 .- Update the slocate database and search for exploits.
Code:
updatedb &
For cPanel servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /usr/local/apache/logs/*
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /home/*/statistics/logs/*
For Ensim servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20'/home/virtual/site*/fst/var/log/httpd/*
Search for shell code:
Code:
cat /path/of/your/web/logs/* |grep "/x90/"
11.- Search for hidden dirs
Code:
locate "..."
locate ".. "
rlocate " .."
locate ". "
locate " ."
12.- Search for perl-scripts running
Code:
ps -aux | grep perl
13 .- Checking nobody user and open files.
Code:
service httpd stop
lsof -u nobody
I have a server of my own. Unfortunatlly 20% of the time, the server is down even though my connection to internet always up.
I am checking the event log but cannot see anything odd...
OS:Windows server 2003
Is there any tool to detect why the server is down most of the time?
I can post the event viewer errors that I can find suspeicious if needed.
is there any proved method to determine what kind of attack you are under? Our server has been under attack for more than a day now but so far we have not been able to find out what kind of attack it is exactly. The server maintence company we are using says it's a DDoS attack but they don't say how they found this out. Also, they are not telling us what kind of DDoS attack it is.
View 14 Replies View Relatedi have some issue,
sometimes,a user may be banned by our firewall,
or the dns of his pc does not work well,...and so on,
by the way,
they can not link to server,
and it spend a lot of time to check where is wrong from his pc aside.
i want to ask if it is possible i use a php script or a exe let him to execute,
and it will help me detect user's pc configuation,
it include his IP/DNS/fateway/trace and ping result,...and so on.
Is there any way to distinguish a dedicated server from VPS using Linux commands and detect the implemented virtualization technology like XEN and OpenVZ, ...?
I have received a dedicated server and in cPanel its written Virtuozzo but they tell me it's XEN , beside this what's the reason to implement a virtualization technic while they give me a dedicated server? Maybe to obtain cheaper cPanel license, 
Do web hosts have the means to self-detect or self-correct problems with people's websites? If so, is there a name for this ability? 
Seems that every host I've used has to be *told* about major problems, such as the server or database being down completely. I'm tired of going out of town fearing a site crash. I don't expect them to catch every problem, but when the failure is so blatant, it would be nice if they caught it...
How would I find a host who does this?
If i put domain.com on uptime checker,and downtime is detected,downtime will be reported if dns is down or if http server is down.So question is what i need to do to see what exactly went down?For network uptime i can ping ip adress,but for these two i really don't know.
View 3 Replies View Relatedhow i can detect and disable C99 shell and another shell script exp:r57 ....
View 9 Replies View RelatedI know the ISP is RADIGRAFICA COSTARRICENSE, and the server location is San José in Costa Rica.
I googled the ISP name RADIGRAFICA COSTARRICENSE, trying to find out the company site which offer's web hosting service, but I can only find racsa.co.cr; however, this doesn't look like a web hosting company.
On one server which i have sometime appear very high load up to 70,and that causing downtime of few minutes(i have historic data webmin module where i saw high load and downtime time matches,but it doesn't show what causing it).That server also have hardware raid in mirror mode.(copies exact data from one disk to another).
View 14 Replies View RelatedSometime ago the DC told me there was too many files on server and I started to investigate what is was and i got info that some one hacked the server and was sending spam from it. 
When I looked at the accounts in Direct Admin some of them had the contact email  to some hacker so i deleted the emails and changed password on the DA account and the email of those accounts. 
Still I got too many files all the time so the server goes down so i have to delete the spoolfile all the time like 10 times a day
Please help how do I detect from what account do the hacker operate? 
Can I detect that somehow? 
Is it possible to do some small script to detect this?
Is there any advanced module to DA that gives me the info?
How does one go about detecting what mail server software you have installed and running on your server?
View 2 Replies View Related