Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 21, 2012, 03:42:10 AM

Pages: [1]   Go Down
  Print  
Author Topic: my server has been hacked, is sending spamm and i dunno how stop it. (help plz)  (Read 870 times)
kavastudios
Space Explorer
***
Offline Offline

Posts: 8


« on: June 21, 2008, 10:02:22 PM »

 Sad

my server has been hacked, the hacker is sending massive emails from my server and this overloads my server and make it fail.

i have to stop exim to lowerdown the overload and keep my sites online.

i check the mail queue manager in the whm panel and in just one second exim running, are 100 messages waiting to be send, the messages look like this

1KAHPH-0001IY-91-H
mailnull 47 12
<>
1214109747 0
-helo_name zarniwoop.mit.edu
-host_address 18.62.0.170.51467
-host_name zarniwoop.mit.edu
-interface_address 209.200.248.154.25
-received_protocol smtp
-aclm 0 1
1
-aclm 1 8
planoinf
-body_linecount 44
-max_received_linelength 105
-deliver_firsttime
XX
1
k36em8mailer-daemonq@planoinformativo.com

212P Received: from zarniwoop.mit.edu ([18.62.0.170])
   by elhumildeservidor.quetalvirtual.com with smtp (Exim 4.68)
   id 1KAHPH-0001IY-91
   for k36em8mailer-daemonq@planoinformativo.com; Sat, 21 Jun 2008 23:42:05 -0500
071P Received: (qmail 26444 invoked for bounce); 20 Jun 2008 08:15:42 -0000
033  Date: 20 Jun 2008 08:15:42 -0000
038F From: MAILER-DAEMON@zarniwoop.mit.edu
046T To: k36em8mailer-daemonq@planoinformativo.com
024  Subject: failure notice
026  X-Spam-Status: No, score=
015  X-Spam-Score:
013  X-Spam-Bar:
016  X-Spam-Flag: NO

1KAHPH-0001IY-91-D
Hi. This is the qmail-send program at zarniwoop.mit.edu.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<bbif-requestn@bbif.vaporware.org>:
Sorry, no mailbox here by that name. (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: <k36em8mailer-daemonq@planoinformativo.com>
Received: (qmail 20042 invoked from network); 20 Jun 2008 08:15:40 -0000
Received: from ppp-58-9-234-114.revip2.asianet.co.th (58.9.234.114)
  by zarniwoop.mit.edu with SMTP; 20 Jun 2008 08:15:40 -0000
Message-ID: <000601c8d34c$07640388$5497718a@vqexhn>
From: "brandyn roald" <k36em8mailer-daemonq@planoinformativo.com>
To: <bbif-requestn@bbif.vaporware.org>
Subject: MSG ID:92691 Re: where I got those expensive shoes
Date: Sat, 21 Jun 2008 01:24:52 +0000
MIME-Version: 1.0
Content-Type: text/plain;
   charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

The world's largest luxury store for shoes and bags is just one click away.
Recommended by thousands of satisfied customers worldwide, we carry dozens of famous brands including:

~ Louis Vuitton
~ Armani
~ Gucci
~ Prada
~ Hermes

Here you will find thousands of stunning designs for shoes, and leather products, at rock bottom pricing.
Prices range from just $39 to $199; quality is assured and satisfaction absolutely guaranteed.
Sale ends this week, so visit us today and start pampering yourself and your loved ones!


- Visit our site:   www.nivematel[DOT]com
(copy this link and then replace "[DOT]" to ".")

------------------------------------------------------------------------

the sender of the messages are random accounts like

k36em8mailer-daemonq@planoinformativo.com
FYymailer-daemonq@planoinformativo.com
xwwfchmailer-daemonq@planoinformativo.com

i already check my accounts inside the server and all the scripts inside the accounts and nothing seems to be wrong,  but i couldn't find the script that is sending all that emails, i also change all my passwords .

could you please help to stop this, because all my users can 't recive or send emails
Logged
perestrelka
Administrator
Master Jedi
*****
Offline Offline

Posts: 1395



« Reply #1 on: June 21, 2008, 10:38:15 PM »

Hello,

According to the mail headers you provided, it appears that there is no problems with your server. There appears to be a bulk emailing happening with From: field forged with a domain hosted on your server. See the following first Received line in the spam example:

"Received: from ppp-58-9-234-114.revip2.asianet.co.th (58.9.234.114)
  by zarniwoop.mit.edu with SMTP; 20 Jun 2008 08:15:40 -0000"

It means the email was originated from ppp-58-9-234-114.revip2.asianet.co.th (58.9.234.114) and not from your server.

What I would recommend in such situation is seting up an SFP record and removing the default email address accepting emails from non-existing accounts for the affected domain. You can get more information about SPF at http://www.openspf.org/.

To disable default email address, open cPanel for the domain in question. Navigate to Mail -> Default Address -> Set Default Address, then select the domain from the drop down list, put ":fail: No Such User Here" (without the quotes) in to the next and click the change button.

I hope this helps. Please advise, if you have any further questions.
Logged

Kind Regards,
Vlad Artamonov
Pages: [1]   Go Up
  Print  
 
Jump to: