• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Email Accounts being compromised

H

hpprod

Guest
Hey Everyone -

My situation is that I operate multiple Linux servers w/ Plesk control panel. All of my users complain that they get a lot of spam. Who doesn't? Problem is - most of my "transfer" customers - those who were with a previous host - always say that when they migrated their domain over to our servers, the amount of spam they receive increased SIGNIFCANTLY.

We use the typical SpamArrest that is included on Plesk, and have the general settings on "5 hits required" and "delete spam".

I suspect that somehow, someway, hackers or possibly, someone on staff - could be compromising these email accounts.

You see - I've done a few tests - where I've created a new email account on a domain .. .like "myspamtest@thisdomain.com" .... and then NEVER, EVER used the mail account - never sent mail, received mail, etc .. .I'd simply setup a redirect on it to one of my other accounts.

Inevitably, within a few weeks, I'll notice a spam in my email box addressed to that very email account ... "myspamtest@thisdomain.com"., etc.

Granted, spammers generate lots of random email addresses at a domain - but nothing THAT SPECIFIC. Which makes me wonder how they are getting my customers' email addresses?

How can this be happening? Are hackers somehow stripping the email addresses out of my server? Could my offshore tech support company be selling the addresses (they do NOT have shell access, but they DO have Plesk Administrator access).

The only person other than myself with full, root/shell access is my contracted server admin - who is a Linux/Plesk genius, but I just can't find it in my heart to believe that he would be the culprit here.

Is there ANY WAY I can track this or figure out how it's happening??

Maybe I'm too suspicious - but I get the same complaint over and over - "we never got so much spam until we switched to your servers" ... that, combined with my several spam email tests where shortly after creating a new mailname, I start getting spam there ... makes me wonder.

I'd appreciate any help or insights!
 
the only way I'm familiar with is either using the unix command finger or whois

try:
finger @yourdomain.com
or
whois -hyourdomain.com yourusername

if either come back with other than "Connection refused" then you might want to dig deeper.

Also, I don't know how to do it, but I believe LDAP can also provide some information about email addresses.
 
I got connection refused when doing the whois -h

when doing "finger @mydomain.com" I get:
THIS IS A PRIVATE COMPUTING SYSTEM. YOUR ACTIVITIES HAVE BEEN LOGGED AND WILL BE ACTED UPON TO THE FULLEST EXTENT OF THE LAW

All i know is that it seems somebody, somehow, is farming out my email accounts to spammers. It's driving me NUTS.

How do I track or catch this?
 
*) Read your logs.
*) Secure your server! (search here in forum and at http://webhostingtalk.com/ for some manuals)
*) Check your firewall settings (plesk intern fw and your external box)

This is what I did.
 
Back
Top