I run a CentOS 5 server with Plesk 8.3
Recently I have been reported that my server is sending out spam. Smpt_auth is forbidden.
I found this in /usr/local/psa/var/log/maillog.processed
Mar 11 11:44:42 aresca6 relaylock: /var/qmail/bin/relaylock: mail from 127.0.0.1:44292 (localhost)
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: Handlers Filter before-queue for qmail started ...
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: from=manojshimpi@cl.cam.ac.uk
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: to=thecamo@one.net.au
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: hook_dir = '/var/qmail//handlers/before-queue'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: recipient[3] = 'thecamo@one.net.au'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: handlers dir = '/var/qmail//handlers/before-queue/recipient/thecamo@one.net.au'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: starter: submitter[31447] exited normally
and in /var/log/messages
Mar 11 11:44:42 aresca6 xinetd[2385]: START: smtp pid=31443 from=127.0.0.1
Mar 11 11:44:42 aresca6 xinetd[2385]: EXIT: smtp status=0 pid=31443 duration=0(sec)
I found a lot of these lines in maillog
"mail from 127.0.0.1:44292 (localhost)" where pnly the port number changes.
A sent spam message reported to me stated this header:
Received: (qmail 19622 invoked from network); 13 Sep 2005 17:52:36 +0700
Any ideas of how to block this spam source?
Recently I have been reported that my server is sending out spam. Smpt_auth is forbidden.
I found this in /usr/local/psa/var/log/maillog.processed
Mar 11 11:44:42 aresca6 relaylock: /var/qmail/bin/relaylock: mail from 127.0.0.1:44292 (localhost)
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: Handlers Filter before-queue for qmail started ...
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: from=manojshimpi@cl.cam.ac.uk
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: to=thecamo@one.net.au
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: hook_dir = '/var/qmail//handlers/before-queue'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: recipient[3] = 'thecamo@one.net.au'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: handlers dir = '/var/qmail//handlers/before-queue/recipient/thecamo@one.net.au'
Mar 11 11:44:42 aresca6 qmail-queue-handlers[31446]: starter: submitter[31447] exited normally
and in /var/log/messages
Mar 11 11:44:42 aresca6 xinetd[2385]: START: smtp pid=31443 from=127.0.0.1
Mar 11 11:44:42 aresca6 xinetd[2385]: EXIT: smtp status=0 pid=31443 duration=0(sec)
I found a lot of these lines in maillog
"mail from 127.0.0.1:44292 (localhost)" where pnly the port number changes.
A sent spam message reported to me stated this header:
Received: (qmail 19622 invoked from network); 13 Sep 2005 17:52:36 +0700
Any ideas of how to block this spam source?