SPAM Coming From My Server

Oct 29, 2006

I have:

WHM 10.8.0 cPanel 10.9.0-R44
CentOS 3.8 i686 - WHM X v3.1.0

I've gotten several complaints through spamcop in the last several weeks. The headers show the spam mails coming from nobody@ my server and they show the originating IP as my server. The datacenter is threatening to shut me down.

I've looked in the mail queue and haven't found any of the sent spam mails in there (or bounces from them). I am getting bounces into horde that were apparently sent from me.

How do I find which client is sending them? Or maybe the server has been hacked and spam software uploaded somewhere?

View 14 Replies


ADVERTISEMENT

How Do I Track Down Spam Coming FROM My Server

May 29, 2007

Logwatch says I send out about 3k emails each day and that is a ridiculous amount. I use postfix and do not run any sort of relay, even for myself. I have IPB 2.2.2, Wordpress 2.0.4, and Gallery 2.x.

How can I track down where these messages are originating from? Or perhaps I am reading my LogWatch file incorrectly?

Quote:

--------------------- postfix Begin ------------------------

17999281 bytes transferred
2460 messages sent
26 messages expired and returned to sender
145 messages removed from queue

Top ten senders:
24 messages sent by:
apache (uid=48):
2 messages sent by:
root (uid=0):

View 4 Replies View Related

Spam Coming From My Domain

Mar 26, 2007

I just got a bounce back from an email address. However I didn't send the original email.

Here is the header of the email which was sent to the other party:

Quote:

Subject:
This blend will help you get thinner
From:
"sales" <myaddress>
Date:
Mon, 26 Mar 2007 19:19:17 -0000
To:
<corprestruct@lists.law.duke.edu>
Received:
from 85.139.98.84.in-addr.arpa (unknown [85.139.98.84]) by lawweb.law.duke.edu (Postfix) with ESMTP id 63EA0292603 for <corprestruct@lists.law.duke.edu>; Mon, 26 Mar 2007 14:19:18 -0400 (EDT)
Received:
from [69.6.190.249] (HELO VORQPXFNM) by 85.139.98.84 (CommuniGate Pro SMTP 5.0.11) with SMTP id 39495966 for corprestruct@lists.law.duke.edu; Mon, 26 Mar 2007 19:19:17 -0000
Message-ID:
<02ec01c76fd3$44a009b0$54628b55@85.139.98.84.inaddr.arpa>
MIME-Version:
1.0
Content-Type:
multipart/alternative; boundary="----=_NextPart_000_02E9_01C76FDB.A62015B0"
X-Priority:
3
X-MSMail-Priority:
Normal
X-Mailer:
Microsoft Outlook Express 6.00.2900.2869
X-MimeOLE:
Produced By Microsoft MimeOLE V6.00.2900.2962

Is there anyway of telling what is sending the spam?

View 3 Replies View Related

What To Do About Spam Coming "FROM" My Domain

Jan 31, 2007

Recently, just out of interest I set the 'Mail to nonexistent user' to forward to my email address.

Within an hour I have about 60 emails saying:

Delivery Status Notification (Failure)

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

and then some email address.

I check out the contents of the message that had been sent and it is some rubbish like:

Up to 500% more volume
- Cover her in it if you want

Which, although amusing, i look at the email address that sent the failed email and it is some random email address @ my domain.com which isn't so amusing.

Now I know that someone is just pretending to be from my domain and sending out these emails (unless someone in my office (of 4 people) is secretly a spammer) but yeah I don't particularly want to have my domain name known as being a source of spam and being blacklisted etc etc...

Are negative effects of this a possibility and is there anything i can do about it?

View 7 Replies View Related

Leaseweb, It Had To Be Coming

Feb 29, 2008

In January I ordered a server with them, knowing that their support isn't the "best".

The server info ended in spam folder, but that isn't their fault I guess. They advertise that every server comes with 2 IPs, however you only get 1. Until you request that 2nd IP. However, when you call them out of working hours, they tell you that you have to pay 135 euro (about 200 USD), great I will wait for tomorrow then. So the day after I called them again. The person I talked with, was very friendly and started to work on it. About 5 hours later I received an email with the second IP information. I added it, but it didn't get assigned. I rebooted the server etc. Still no 2nd IP. It was already 'after working hours' so I had to wait again, because I wasn't going to pay 200$ for an IP. The day after the guy on the phone tells me they assigned me an IP that was already assigned to another customer (lol)..... Ok, so I asked him if I could get a different IP than I was supposed to get. (Now I had to fix my DNS settings also, but o well....). The new IP info arrived in my inbox about 80 minutes after the call this time. After rebooting the server everything ran flawlessly. I manage my own servers, so I didn't contact their support again.

On the 21st of february, I called their administration about cancelling the server (they had a new offer, which suited me better & because I only wanted a fast network for this server, I didn't care about their support), I was told that if I submitted their cancellation form the same day or the day after, It would be taken care of before the end of the month. So I filled it in and sent it to them on the day after (22 february).

Today I called their administration to check if everything went ok (I didn't want to order the new server & pay the old one at the same time). I was told: No, it isn't cancelled. She checked that my email was there & indeed it was sent to them. She then asked me if I could wait a minute, so she could ask someone else what to do. She told me that she would assign me to a sales guy, who would be able to tell me more about it. He told me that the cancellation has to be done X days in advance. Which I did, then he said: It has to be done a month up front. I asked him why I was told that it would be cancelled on the 22 of february, but now I had to cancel it the 1st of february. He said it was a mistake. There was "nothing" he could do (or wanted to do). I don't have the time do anything about it, so I'll let it be and just pay for another crappy month.

Great, now I'm fed up another month with their server. What if I didn't call them today? I would have had 2 servers with them & they would have, the only thing they want: Money.

View 14 Replies View Related

Trojans Coming From Myspace?

Sep 25, 2007

My friend has been building a myspace page for herself using our old computer and all of a sudden I've found multiple trojans, 1 of which was very tough to get rid of.

Could these trojans be coming from the little dealiemajigs (sp?) she's using to decorate her page?

View 2 Replies View Related

Where To Load And Memory Is Coming From

Apr 10, 2009

im running centos 5 64 bit, cpanel

AMD Phenom 9600

the load is showing as :

* Load Averages: 1.13 1.09 1.02

I don't know where the load is coming from. Normally im getting 0.00 or below .5

I clicked on that link show cpu processes but they are showing 0

I checked apache connections and no load too

identify where the load reported in WHM is coming from

View 4 Replies View Related

Keeping Files From Coming Up On Google With IIS

Oct 28, 2009

I was doing a search on google and retrieved some files on it with some sites that should not be available to the public. I investigated the site a little bit and it looked like they are running ASP. I know with Linux servers you can place a .htaccess file which can restrict bots from accessing certain directories, but how can you do it with a windows server running IIS? I would like to get in contact with these companies and let them know about the issues I ran into with their site.

View 4 Replies View Related

Very Frustrating Coming From Shared Hosting.

Sep 24, 2007

I write this as my site has been down for some 11 hours now and need a way to calm down while I wait for my new host to get my account "up".

I've used shared hosting since 1995 up until just a month ago. I was always happy with shared hosting. Who can beat $5 a month to have your site up and running? I had all the subdomains I needed and I even had cPanel. Tech support was fantastic. My accounts were ALWAYS set up within 2 hours tops. Life is good.

Then a recent .com I built got too popular too fast and one day I found (even though I was at 75% of my allotted bandwidth for the month) the plug pulled on my site because (even though it was a static site - html and images only) I was taking up too many "cycles". Too bad cycles aren't something advertised when selling a site to a customer. They made the big mistake of not offering me a VPS soultion from my pitiful little shared hosting account, or any other alternative. So I left them, I had no choice as I couldn't trust them any more.

I got a VPS account, which I must say is not an easy thing to shop for because how do you know who is good? Forums are not a 100% indicator and I don't know any better so it's a crap shoot really. So I looked for the most important qualities: it had to be a managed account because I don't know my butt from a hole in the ground when it comes to running a server (I'm the kind of customer who will tell you "you handle the server voodoo, and let me worry about the content on it ok?"), and I needed a quick setup because my site was already dead in the water.

I picked my first VPS host and all seemed good. My server was fully running in about 2 hours. Once I got through the growing pains of getting various things configured (which I didn't do I aksed for this to be done via trouble tickets) everything was set. The only issue that cropped up here and there was downtime. So now I'm shopping for my second VPS host. I just spent even more money than at my last host and what has my experience been thus far?

I will admit I signed up around 2.am. because my site went down at 11p.m. at my previous host so I was in full panic mode. I plunked down the cash and got an automated email saying how my account must be "verified" over the phone. Fine I wait up an hour or so and finally fall asleep when no call is received. I wake up around 10a.m. and have another email from the new host saying how they couldn't get in touch with me on my phone to "verify" me. I check my phone. Nope, no missed calls, no messages. WTF? So I call them. They have my correct number. Could their call have just never registered on my phone? Is there a black hole for phone calls?

They "verify" me by making me repeat info already provided when I signed up. I've never had a host do this to me, this is ridiculous and a waste of time on everyone's part. Stop. It's a waste of time. If was going to steal someone's credit card I'd buy something a heck of a lot more exciting than a Unix web hosting account at 2a.m.

They tell me I'll get an email with my account info. Great. I wait and wait and nothing arrives. It's almost 10 hours now since my site has gone dark. I write the company to say where is that email so I can get going? I get a quick response that says new account take 8-24 hours to set up. Where the heck was this mentioned on the site when I signed up? Why is this important fact hidden? I"m spending $90 a month, I guess my business isn't important enough to rate better service. Unless a whole bunch of people just signed up for more expensive plans than me at the same time, why can I not get "set up" faster?

So now I wait. I'm crossing my fingers this host will be great. Felt good to rant, I'm more relaxed.

View 8 Replies View Related

Block Http Requests Coming Via Proxy

Jun 24, 2007

I want to block all http requests coming to my website via proxy. Is there any way/script to achieve this on the server?

View 5 Replies View Related

Mailbox Allowance? My Incoming Emails Have Stopped Coming In

Sep 3, 2008

But with my current host, my incoming e-mails have stopped and have done quite a lot of times, If I send an e-mail to myself from another acount, it gets bounced back.

When I'm searching for hosts, I can't see any info on mailbox allowance.

I'm using Outlook to download all my e-mails.

I don't know why they are stopping and I can't find out from the person who got the host from me, in the past he said something about me having to delete e-mails. But this would come back to mailbox space which no hosts seem to advertise, unless it goes under webs space.

If my mailbox is full or ran out of space, does anybody have any recommendations for a host that offers a good amount of mailbox space.

Another question, am I limited to the amount of e-mails I can send with some hosts? I'll be sending out Newsletters to 600+ people each month.

View 8 Replies View Related

Plesk 12.x / Linux :: Customers Emails Coming Into Root Email

Jun 26, 2015

For some reason a customer is receiving emails from root@theirdomain.com and its coming into our main email. How can this be disabled or modified?

View 2 Replies View Related

Plesk 11.x / Windows :: Move Spam To Spam Folder Not Available?

Oct 17, 2013

Microsoft Windows Server 2008 R2 Service Pack 1
Panel version 11.0.9 Update #59, last updated at Oct 3, 2013 02:06 AM
MailEnable version 5

I see in the plesk documentation that the screen to enable SPAM filtering for an individual there is an option to "Move spam to the Spam folder". I don't see that option so I am wondering if it is only available on some versions of Plesk, or in combination with certain mail servers. How to make that option available?

View 3 Replies View Related

Spam Being Sent From Our Server.. But How And From Where

Apr 2, 2009

We're using whm/cpanel and we're always up to date with the latest upgrades (with all our scripts).

2 weeks ago, we receive a notification from SpamCop saying that our server was sending out spam. We verified everything and found nothing. 2 days ago, same story.

We tried looking at our logs and found nothing. Does this mean that there's a security hole somewhere? How can we find out from where the spammer is sending his viagra emails from ? We do not want to be permanently banned because of a spammer.

View 5 Replies View Related

Spam From Server

Jul 14, 2009

I noticed that reported server usage from Plesk is 2.x - 3.x, so I went to mail queue (in Plesk) and saw lots of mails that shouldn't be there.

There were several senders under the domain dedibox.fr sendint LOTS of emails to lots of addresses in the same email. There shouldn't be a sender @dedibox.fr, as that domain isn't hosted on our dedicated server.

I know little about Linux administration... I tried going to the /var/log folder and grep for dedibox on the messages and maillog files, but nothing found...

How can I know if someone connected to our server as an user or something like that?

View 6 Replies View Related

Server Is Over-run By Spam

Dec 16, 2008

I'm hosted with elitehosts.com, they've been absolutely GREAT for 2 years now.

However, one of my sites gets SOOO much spam email that the host cannot handle it. Apparently the limit is like 500/hour.

The result is email for the domain is no longer dependable.

Senders to the domain get undeliverable bouncebacks.

Is there anyway to fix the problem? The server side spam filters catch the email, but doesn't solve the problem of all the incoming mail.

Is finding a new host (if even just for email) my only option?

View 10 Replies View Related

Spam Is Being Sent From My Server!

Apr 7, 2008

Have any of your seen anything like this before?

Someone is somehow sending spam via my server.

Looking at /var/log/exim_mainlog I can see many entries like the following:

2008-04-07 21:10:43 1Jixfv-0006ad-4Y [= [] H=smtp.inet.fi [192.89.123.192] P=esmtp S=4192 id=I81c2X5ll000c597d@smtpgw.lapit.fi
2008-04-07 21:10:43 1Jixfv-0006ad-4Y =] info [bot@dole.ie] R=virtual_user T=virtual_userdelivery
2008-04-07 21:10:43 1Jixfv-0006ad-4Y Completed

So it looks like this is an e-mail being sent to bot@dole.ie

However when I look at my mail I can see the mails are being sent FROM bot@dole.ie. For example:

Sorry, but Lyris ListManager did not find your email address
-] "bot@dole.ie"

listed as a member of techno-l.

Only members of techno-l are allowed to contribute messages.

Because Lyris ListManager could not confirm that you are a member of techno-l, your message was not accepted.

---
Return-Path: [bot@dole.ie]
Received: from mail.reginamater.com ([201.231.192.60]) by listserver.knowledgeexpress.com with SMTP (Lyris ListManager WIN32 version 8.9a); Mon, 07 Apr 2008 16:01:23 -0500
Message-ID: [000501c898ea$068d922e$f5014499@bhudl]
From: "gun mella" [bot@dole.ie]
To: [techno-l@techno-l.org]
Subject: Don't pay too much for your drugs. Buy from us.
Date: Mon, 07 Apr 2008 18:15:12 +0000
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

4 free pills with every order
[url]
...

There are lots of bounced e-mails being sent back to me.

Does anyone know how I can check to see what's spending the spam or how to stop it?

View 2 Replies View Related

SPAM Going Out Of Our Server, HOW ?

Feb 8, 2007

For some days now, the server`s been sending spam through our main domain, under different email aliases that don`t even exist : fdg@domain.com , gfhh@domain.com ( email aliases that don`t even exist )( I changed my domain with domain.com for privacy measures )....so on.. I tried to check what is sending out emails. Any idea how to track/check/scan for what is sending out emails?

View 8 Replies View Related

Server IP On Spam List

Jan 1, 2009

I recieved a new block of ips from my server folks and this block is worse than before, the main ip is on more than 10 spam lists.

How do I resolve this? Is there a way a server company can select a clean block of ips?

can I set the email program to use a separate ip or something intead of changing ips of server?

View 3 Replies View Related

ThePlanet Server Spam

May 20, 2009

how to best deal with email spam.

Here is what's up...

I recently got a dedicated server with The Planet. WHM/Cpanel...

I am a designer and starting to host my clients. So far i've setup about 5 different clients and everyone says the same thing...

Since they've switched to my server the email spam they get to their emails is out of control.

I asked The Planet for help and they said to make sure some spam filters were automatically checked for each account in my WHM and in their unique cpanel accounts, and they are but it hasnt helped. They also have a spam service but i do not want to pay any more per month than i already am.

What would cause this to be so bad versus my clients old servers?

Secondly, what open source solutions are there out there and who is the best to hire to install them on my server?

View 14 Replies View Related

Server Sending Spam

Jan 11, 2009

I currently have a dedicated server, Linux, with 1 website on it that is sending spam.

At first I thought it was someone spoofing my email address, however when I check my servers Email queue I can see the spam emails in there being sent.

My problem is that I have contacted my server provider and support for the scripts I'm running and everyone is saying its the other persons fault. My server provider is saying everything is up to date and it must be a software exploit on one of my scripts, and the support team from my software is saying its not them that its the server.

View 1 Replies View Related

Stopping SPAM On A Server

Nov 5, 2009

Can you control SPAM on a server ? I've got this email account that all receives is SPAM, nothing else. I'd like to eliminate this so it doesn't get any more SPAM.

View 13 Replies View Related

Email Spam From My Own Server

Dec 19, 2008

I received many email spam recently, with the sender address from my own server.
Eg.

my domain = www.shashinki.com
email spam that I received = shop@shashinki.com which is being sent to my own email address of shop@shashinki.com. Yes, the sender is my own email address account.

I checked using gmail and the sender is from my own server IP address and the sender's email address seems to be valid and is from my own email account.

I have changed the password of my email address, added SPF to my email system...etc. I have done all that I can think of, but I still get the same spam emails.

What can I do and what should I do? I got really tired of this and I am worried that my server is being used to send spams to others.

My server is with LayeredTech, unmanaged server, so I dont have a manager to help me.

Hope to get some insight and help from sifus here...

View 10 Replies View Related

Spam Emails Being Sent From Server

Nov 25, 2008

I have reason to believe that a site on my server was hacked and is now being used to send out spam emails.

View 9 Replies View Related

Server Overloaded By Spam

Jun 26, 2008

what experiences other people have been having with loads on their servers from spam. I was doing some profiling of our machines and noticed that load actually a fairly significant part of the load on our servers, and its way worse than it used to be.

Looking at the numbers I suspect we could comfortably have way more accounts per server if we could deal with spam better.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved