HELP! Spammers authenticating.
HELP! Spammers authenticating.
Hey There,
i've just disabled my mail server as I have a spammer authenticating as user "summer" which is not supposed to exist according to plesk.
I'm running plesk 8.6.
How can I track this down and get it secured?
Please help.
- John
i've just disabled my mail server as I have a spammer authenticating as user "summer" which is not supposed to exist according to plesk.
I'm running plesk 8.6.
How can I track this down and get it secured?
Please help.
- John
I no longer think it is just user summer
Where should I start?Sep 24 17:19:30 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@rrcs-208-105-232-205.nys.biz.rr.com [208.105.232.205]
Sep 24 17:19:31 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:33 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:41 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:42 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:50 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:51 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:19:59 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:00 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:09 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:10 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:25 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:27 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:41 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:44 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:20:58 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:21:00 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:21:14 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:21:16 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
Sep 24 17:21:28 phoenix smtp_auth: smtp_auth: SMTP user : logged in from (null)@adsl-156-164-160.mia.bellsouth.net [70.156.164.160]
ok, I re-enabled my mail server and just disabled smtp_auth and enabled pop-lock.
This still has the spammers restrained
This still has the spammers restrained
But what can I do to correct whatever is wrong with my smtp_authSep 25 21:41:46 phoenix relaylock: /var/qmail/bin/relaylock: mail from 68.228.4.173:1996 (wsip-68-228-4-173.br.br.cox.net)
-
- Long Time Forum Regular
- Posts: 2813
- Joined: Sat Aug 20, 2005 9:30 am
- Location: The Netherlands
Did you see http://forum.swsoft.com/showthread.php?t=55221 ?
Seems there is a security hole somewhere, but only on some operating systems. Debian and RHEL/CentOS don't seem to be vulnerable. There is a report about OpenSuSE 10.3 x86_64 being vulnerable.
Seems there is a security hole somewhere, but only on some operating systems. Debian and RHEL/CentOS don't seem to be vulnerable. There is a report about OpenSuSE 10.3 x86_64 being vulnerable.
Lemonbit Internet Dedicated Server Management
-
- Long Time Forum Regular
- Posts: 2813
- Joined: Sat Aug 20, 2005 9:30 am
- Location: The Netherlands
You can also use /usr/local/psa/admin/bin/mail_auth_view if you want to spy on username/password combinations.
Lemonbit Internet Dedicated Server Management