How to block email spamming coming from my server?
Linux - NewbieThis Linux forum is for members that are new to Linux.
Just starting out and have a question?
If it is not in the man pages or the how-to's this is the place!
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
I assume that one (or several) of the client installs acts as
an open relay; check out who produces the traffic, and then
look at their e-Mail configuration.
I assume that one (or several) of the client installs acts as
an open relay; check out who produces the traffic, and then
look at their e-Mail configuration.
This is a cPanel server. Where would I check who is using the most mail traffic?
Okay...since you asked sooooo nicely - how about (long shot) mailsnarf? It's part of the dsniff package, a collection of nifty tools for all things network sniffing
Also, try this
Quote:
tcpdump -vvv port 25
to listen to the smpt port, granted, it will give you quite a bit to look at...but you will find out what time the spam is being pushed out...
You will need to start by examining your log files. Undoubtedly there will be some indication of the spam messages and the user account from which they are originating. I don't mean to sound harsh, but I think you are also learning a really valuable lesson in the down side of the "install this gui application and go" without fully understanding the underlying how and why things work. Something in your system has clearly become compromised and you are responsible for it. The problem is that it is likely one of your customer's (?) hosted sites and / or mail servers. The problem could be a cracked password, SQL inejection, or a PWN of a process. Web stack applications are typically one of the most compromised systems, largely due to poorly written PHP or other script.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.