How To Track Email Clients' Statistics
May 18, 2007I'd like to track the email user agents that our clients use. Basically, I'd like to have something that looks like that:
[url]
I'd like to track the email user agents that our clients use. Basically, I'd like to have something that looks like that:
[url]
how exactly email works. For example, I set my mx record to google apps in order to use google mail with my own domain. Thing is, I can sent from google mail now with my domain email address but cannot send. Furthermore, login to my website email bij www.domain.com/webmail is possible but receiving is impossible and even sending email from that place will not work.
Thinking about it it seems that email is lost
google can send but not receive
from my domain webmail i cannot receive nor send.
I am trying to find a good solution for email. I use a Linux based server running CestOS, WHM and cpanel. I absolutely hate the webmail clients that come with cpanel (horde, squirrel mail, neomail) so I use outlook instead. Problem is, I use the same email between different computers and end up getting the same messages twice. This does not seem to matter if I use pop3 or IMAP; I still get the same emails in both places.
What I would like to see is a possibility of a mail client that is either web based, or something I can add to my server that allows me to take advantage on IMAP - and have it work like it is supposed to. I like the functionality of pop3 in outlook because it allows you to easily delete and maintain a clean inbox. 
Alright, so I apparently messed up my email. I downloaded my email folders from my previous host's mail folder through FTP and then uploaded them to my new server's mail folder thinking it'd be an easy transfer. Yeh... didn't work, now I can't get my email through Outlook 2003 or ThunderBird. Any ideas on how to reset my mail server? I don't know if it's just the mail folder that's messed up or what.
View 9 Replies View RelatedWe are moving our hosting to a new supplier . We offer hosting services to our clients and our present system produces automatic emails with all the clients log in details passwords etc. when you join or buy a new URL. 
The new hosting supplier tells me that using Parallels panel this isn't possible . 
have to produce manual emails is not really an option as I see massive problems 
My server currently has some problems with DNS/mail, which i can't seem to fix myself. My colocation host offered to help me by giving him root access, but i don't know him very well yet. Is there some kind of script/logtool so i can track everything he did on the server? I don't want him snooping around through my webfiles and databases...
View 13 Replies View RelatedCan anyone please tell me how dangerous in fact Apache's TRACE and TRACK functions?
I have read common explanation but would disabling TRACK and TRACE improve my server's ability to fight cross site scripting and similar attacks and make it more secure?
I'm small hosting provider. On one dedicated server I have around 100 cPanel accounts.
That server is under constant, although not powerful DoS attack.
Since my company domain is not targeted on another server I believe that it is not me but one of my customers that attack is against.
Is there a way, tool, service provider than can help me pin down which account is being hit?
All accounts are on server main shared IP.
Would spreading them on another IPs help? Or would I still see attacks only on main shared IP?
I'd like to know, is there any way to know about hosting provider, if we have only ip address of the server. i.e.
66.63.181.74  - this is the ip address of my website server, how can i trace the service provider who is giving this hosting service?
I have a few shred hosting servers I run. One of them keeps getting listed on CBL. It is very frustrating. Does anyone have an tools, tips, or tricks on finding the compromised?
So far I have confirmed that a script is using PHP to send mail out bypassing the MTA. It is faking the HELO and impersonating a well known ISP.
I used a combination of tshark and netstat. tshark can show me the HELO and EHLO. When I see the wrong entry I cross check that with netstat to see what. So Netstat only shows that it was PHP not the script path.
Here are the commands I'm running:
Code:
nohup netstat -c -p -n -e | grep -i ":25" > /var/log/monitor/netstat-smtp.log &
nohup tshark -f "port 25 and src host XX.XX.XX.XX" > /var/log/monitor/tshark-smtp.log &
Then I grep for what I'm looking for:
grep -i "HELO" /var/log/monitor/tshark-smtp.log
Is there a way to get Netstat to show the script path or complete command that is establishing the connection? Currently these scripts are eating up memory to a point that other process or getting killed off. 
I also tried to force all mail through the MTA, but When I enable SMTP_BLOCK in my firewall config I get and error:
*WARNING* Cannot use SMTP_BLOCK on this VPS as the Monolithic kernel does not support the iptables module ipt_owner - SMTP_BLOCK disabled.
If there is a better way I'm game. Maybe some IDS that can tell me more of what is going on with the server?
I am currently developing a web application on a WAMP server.  Once complete my client will have some in-house "programmers" make changes to the code as they are needed.
My client wants to track all changes made to the source files (ie- who made the change, when it was made, what files were modified, and what specific lines were added/removed/modified).  Also, the program must run on the server and not the programmers computers.
I've searched high and low and only found a couple programs that scratch the surface of what they want.  
Is there a way I can track the HTTP traffic to which domain is running with high traffic. Due to traffic load I/O wait is increasing. I want to suspend the domain that have the large traffic to avoid down time.
View 4 Replies View RelatedI've done plenty of searching on DDoS attacks and from what I've found so far it seems that it's "very difficult" track down the person(s) responsible for the attack. 
My question is this - could someone actually do it if they were qualified enough? Would a hacker who is well versed in the techniques used be able to find the person(s)? Or is it just simply impossible sometimes?
I just installed Apache 2.4.4 and it seems to run fine overall. But in my error.log I get about 3 of these every hour or so.error.log:[Sat Jun 15 20:57:44.095961 2013] [core:notice] [pid 31400:tid 16384] AH00052: child pid 1971 exit signal Segmentation fault (11)
 track down what causes this? What module? vhost?Otherwise the server seems to run fine. It's on Linux with PHP 5.3.26 and MySQL 5.1.
I'm working on setting something up for monitoring my bandwidth/traffic on multiple interfaces. I have setup interface aliases so I have eth0, eth0:0, eth0:1 and the issue I'm running into is that it seems snmp cannot tell the diff between the aliased interfaces. I've found references in the cacti forums of using ipchains rules to track the bandwidth, but I've not found a good howto that explains what I need to get going on this. 
Any clues/hints?
What script/application can I install on my linux box to track the bandwidth per each domain?
I currently have no CP, on lighttpd.
I have FreeBsd with Cpanel.someone is running attacking perl script from my server.Below is information about that script but it shows / path in command lsof -p 30251 | grep cwd.
 PID USERNAME        PRI NICE   SIZE    RES STATE    TIME   WCPU    CPU COMMAND
29018 root             96    0 35968K 30528K select   0:03  2.71%  2.69% perl
newinst# lsof -p 30251 | grep cwd
lsof: WARNING: compiled for FreeBSD release 5.5-STABLE; this is 5.3-RELEASE.
perl    29018 root  cwd   VDIR       4,12     1024       2 /
newinst# ls -la / | more
total 22413
drwxr-xr-x   25 root  wheel         1024 May 16 03:23 .
drwxr-xr-x   25 root  wheel         1024 May 16 03:23 ..
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .black
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .black.bak
-rw-r--r--    2 root  wheel          801 Nov  5  2004 .cshrc
-rw-r--r--    1 root  wheel          355 Feb 21  2007 .new
-rw-r--r--    2 root  wheel          251 Nov  5  2004 .profile
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .rbl.db
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .rbl.db.bak
drwxrwxr-x    2 root  operator       512 Jul 19  2005 .snap
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .uribl.db
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .uribl.db.bak
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .white
-rw-r--r--    1 root  wheel            1 Feb 21  2007 .white.bak
-r--r--r--    1 root  wheel         6184 Nov  5  2004 COPYRIGHT
drwx--x--x    3 root  wheel          512 Aug 20  2005 backup
drwxr-xr-x    2 root  wheel         1024 Dec 28  2006 bin
drwxr-xr-x    5 root  wheel          512 Jul 19  2005 boot
drwxr-xr-x    2 root  wheel          512 Jul 19  2005 cdrom
lrwxr-xr-x    1 root  wheel           10 Jul 19  2005 compat -> usr/compat
-rw-r--r--    1 root  wheel          177 Dec  5 12:15 cpgd.c
dr-xr-xr-x    4 root  wheel          512 May 16 16:23 dev
drwxr-xr-x    2 root  wheel          512 Jul 19  2005 dist
-rw-------    1 root  wheel         4096 May 13 15:58 entropy
drwxr-xr-x   28 root  wheel         4608 May 19 11:57 etc
drwx--x--x  501 root  wheel         9216 May 19 01:33 home
drwxr-xr-x    3 root  wheel         1024 Jul 19  2005 lib
drwxr-xr-x    2 root  wheel          512 Jul 19  2005 libexec
drwxr-xr-x    2 root  wheel          512 Nov  5  2004 mnt
drwxr-xr-x    3 root  wheel          512 Jul 21  2005 nonexistent
drwxr-xr-x    8 root  wheel          512 Oct 30  2007 opt
-rw-------    1 root  wheel     22786048 May 16 04:51 perl.core
dr-xr-xr-x    1 root  wheel            0 May 19 11:57 proc
drwxr-xr-x    2 root  wheel         2560 Jul 19  2005 rescue
drwxr-xr-x   13 root  wheel         1024 May 19 01:33 root
drwxr-xr-x    2 root  wheel         2560 Jul 19  2005 sbin
drwxr-xr-x    5 root  wheel        13824 May 19 01:22 scripts
drwxr-xr-x    4 root  wheel         1024 Jul 19  2005 stand
lrwxrwxrwx    1 root  wheel           11 Jul 19  2005 sys -> usr/src/sys
drwxrwxrwt    9 root  wheel        31744 May 19 11:57 tmp
drwxr-xr-x   21 root  wheel          512 Dec  5 12:12 usr
drwxrwxrwx   24 root  wheel          512 May 16 16:24 var
where it is localted at/path.
Logwatch says I send out about 3k emails each day and that is a ridiculous amount.  I use postfix and do not run any sort of relay, even for myself.  I have IPB 2.2.2, Wordpress 2.0.4, and Gallery 2.x.
How can I track down where these messages are originating from?  Or perhaps I am reading my LogWatch file incorrectly?
Quote:
 --------------------- postfix Begin ------------------------
17999281 bytes transferred
2460 messages sent
26 messages expired and returned to sender
145 messages removed from queue
Top ten senders:
   24 messages sent by:
      apache (uid=48):
   2 messages sent by:
      root (uid=0):
I'm wondering if theres anything I can install on the server that will either filter or track outgoing spam. I don't want to limit the number of emails sent per hour or anything, I just want to be able to maybe search through some flagged emails or something. Or if they send the exact same email more than x times it can disable their account... I'm not sure
View 1 Replies View RelatedOften when it comes to choosing or recommending a host, I tend to favor the ones that are larger, and more established such as Hotgator or Downtown Host. But in some other threads, I have seen plenty of people swear by some smaller hosts. Are there some good examples of small hosts that have been around for 3 or more years and have a great reputation?
View 12 Replies View RelatedI just checked my IO statistics and found that I have a large number of blocks bieng written to my two hard drives on my server.
I'm suspecting this is the reason for also increased load on my server.
Now I'm thinking either 1) A site on my server is generating this amount of usage
or
2) Possibly one or both of my hard drives are failing?
I'm getting ready to leave a host that has been having issues and has been having speed issues.... As I learn more about servers I am wondering if the server statistics can teach me a little about what may be affecting the server performance.... When I look at server statistics in CPANEL it is showing 78% memory used and Disk Usage as 44% and 83%, respectively on two disks. Zabbix also shows as "failed". Another host I have has no issues and is using 40% of memory with disk usage never going over 23% ..... Are the statistics on the first server I mentioned significant in the poor performance being experienced by sites hosted there?
View 7 Replies View RelatedIn WHM Under Exim statistics we see value as:
Messages received per hour (each dot is 75 messages)
----------------------------------------------------
12-13   1643 .....................
13-14   3372 ............................................
14-15   2971 .......................................
15-16   3772 ..................................................
16-17   1088 ..............
Deliveries per hour (each dot is 125 deliveries)
------------------------------------------------
12-13   3000 ........................
13-14   6108 ................................................
14-15   5722 .............................................
15-16   6259 ..................................................
16-17   1333 ..........
--
BUT
This is not really emails receive in pop3 account and not emails sent (delivery)
For delivery we think this can be "try" to delivery, right?
But for messages received?
way to disable MySQL statistics (like total querys, rows deleted, and etc.). 
 
(SuSE Linux 10.x, MySQL 5.0.X).
Is there a standard on the length of time we should configure stats to run on a cpanel server. Currently mine is 36 hours.
View 1 Replies View RelatedI've been trying to use mod_forensics –  [url]-- which has helped on one server track down some one causing the segmentation fault due to trying to abuse FrontPage shtml.dll, but on another server also suffering from regular segmentation faults, this tool has not helped.
What other tools are available to track down the cause(s) of Apache segmentation faults?
I know it's not specifically a plesk issue, but as I use plesk to resell webs and many users install (manually) wordpress, I thought I'll ask around.I would like to know if this can be done with a single sql select or if I would have to use a script to do this:
- track all mysql databases on my server
- find the proper table in each database (as the prefix can be customized, the start of the table name will probably never be the same in two WP installations)
- find the proper field in that table and check the WP version and administrator email
and then what I will do is send an email to those adresses advising them to update WP