KrazyBob
Regular Pleskian
I have a server running Virtuozzo 3.x with Plesk 8.3 for Linux. I have many IPs accessing port 25 to apparently send spam. I have been searching all day trying to find where they are coming in and have failed. It does appear that one deddicated IP assigned to the server is part ofg the problem, but even turning off mail for that domain fails to stop the problem. I have installed the sendmail mod and that does not reveal a php script being used. I have tried grepping the access_log for clues. That hasn't helped. I have checked PID's using lsof -p <PID> and that only shows my the various lib.so.2 etc. being called and confirmins the IP sending.
I am at a complete loss.
Running CentOS 4.5 Final
Here is a sample:
tcp 0 0 65.44.220.71:25 190.26.8.59:2569 ESTABLISHED 18760/qmail-smtpd
tcp 0 0 65.44.220.71:25 201.208.96.72:2603 TIME_WAIT -
tcp 0 0 65.44.220.71:25 216.9.248.50:46787 TIME_WAIT -
tcp 0 0 65.44.220.71:25 222.106.28.131:10243 ESTABLISHED 25493/rblsmtpd
tcp 0 0 65.44.220.71:35255 209.191.88.239:25 ESTABLISHED 16755/qmail-remote.
tcp 0 0 65.44.220.79:25 190.166.73.196:55757 TIME_WAIT -
tcp 0 0 65.44.220.82:25 221.225.48.73:1027 ESTABLISHED 19267/qmail-smtpd
tcp 0 0 65.44.220.83:25 190.22.136.241:3677 TIME_WAIT -
tcp 0 0 65.44.220.83:25 61.60.62.166:4127 ESTABLISHED 25482/qmail-smtpd
tcp 0 0 65.44.220.88:25 84.127.134.57:1543 TIME_WAIT -
tcp 0 0 65.44.220.88:25 85.71.34.43:3044 TIME_WAIT -
tcp 0 30 65.44.220.71:25 84.76.143.132:50481 ESTABLISHED 18631/qmail-smtpd
tcp 0 142 65.44.220.71:25 89.1.184.138:59833 ESTABLISHED 25483/qmail-smtpd
No sooner do I blick the IPs than another is used. At this point I have blocked all of Nigeria
I am at a complete loss.
Running CentOS 4.5 Final
Here is a sample:
tcp 0 0 65.44.220.71:25 190.26.8.59:2569 ESTABLISHED 18760/qmail-smtpd
tcp 0 0 65.44.220.71:25 201.208.96.72:2603 TIME_WAIT -
tcp 0 0 65.44.220.71:25 216.9.248.50:46787 TIME_WAIT -
tcp 0 0 65.44.220.71:25 222.106.28.131:10243 ESTABLISHED 25493/rblsmtpd
tcp 0 0 65.44.220.71:35255 209.191.88.239:25 ESTABLISHED 16755/qmail-remote.
tcp 0 0 65.44.220.79:25 190.166.73.196:55757 TIME_WAIT -
tcp 0 0 65.44.220.82:25 221.225.48.73:1027 ESTABLISHED 19267/qmail-smtpd
tcp 0 0 65.44.220.83:25 190.22.136.241:3677 TIME_WAIT -
tcp 0 0 65.44.220.83:25 61.60.62.166:4127 ESTABLISHED 25482/qmail-smtpd
tcp 0 0 65.44.220.88:25 84.127.134.57:1543 TIME_WAIT -
tcp 0 0 65.44.220.88:25 85.71.34.43:3044 TIME_WAIT -
tcp 0 30 65.44.220.71:25 84.76.143.132:50481 ESTABLISHED 18631/qmail-smtpd
tcp 0 142 65.44.220.71:25 89.1.184.138:59833 ESTABLISHED 25483/qmail-smtpd
No sooner do I blick the IPs than another is used. At this point I have blocked all of Nigeria