LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-13-2016, 11:02 AM   #1
RazorTortoise
LQ Newbie
 
Registered: Apr 2016
Posts: 3

Rep: Reputation: Disabled
Unable to identify spam that seemingly came from server


Hi,

I'm working on a server that has found itself on a spam list. Upon contacting they sent an example of the spam coming from the server, which is below. They redacted some info, the rest I have removed.

-----

Received: from [our-server.net] ([our.ip.address])
by [redacted]
id [redacted]; Mon, 11 Apr 2016 xx:xx:xx +0000
Received: (qmail 14775 invoked by uid 34767); 11 Apr 2016 xx:xx:xx -0000
Date: 11 Apr 2016 xx:xx:xx -0000
From: "Diedre Waldemar" <rinagreenwellw@brunoandgeorge.com>
Subject: Haley wants you for a fortuitous meeting write 1.518.289.xx.xx

-----

I looked up the userid who spawned this in /etc/passwd, and there is no matching user. Furthermore, qmail doesn't operate on this server, as it's a cpanel server which has exim, although I understand this could be spoofed.

How can I track down where this originated from. Monitoring the exim log, there is no mail being sent out right now either, and there's nothing in the log.

I have since restricted SMTP connections in WHM to root, exim, and mailman and blocked 'nobody' from sending. Is this likely to help based on the nature described so far? I obviously still want to get rid of whatever may have sent this.


Thanks for any help!
 
Old 04-13-2016, 11:15 AM   #2
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,661

Rep: Reputation: Disabled
Run open relay test, there are several online. If your box is "owned" they can use their own MTA to send spam. In case your box is compromised take it offline immediately.
 
Old 04-13-2016, 11:25 AM   #3
RazorTortoise
LQ Newbie
 
Registered: Apr 2016
Posts: 3

Original Poster
Rep: Reputation: Disabled
Hi there,

Thanks for your help. I ran a few online tests: mxtoolbox, mailradar, and one at http://www.rbl.jp. All returned that no relays were accepted by the server. What next would be best to check/determine what's going on here?

Thanks again.
 
Old 04-13-2016, 11:44 AM   #4
RazorTortoise
LQ Newbie
 
Registered: Apr 2016
Posts: 3

Original Poster
Rep: Reputation: Disabled
Hi there,

Thanks. I ran a few open relay tests, (mxtoolbox, mailradar, and http://www.rbl.jp), and they all returned saying that no relays were accepted by remote host. What would next be best to check?

Thanks again!
 
Old 04-13-2016, 03:12 PM   #5
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,661

Rep: Reputation: Disabled
I'd run rkhunter.
 
Old 04-14-2016, 01:32 AM   #6
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,157

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
change your admin password just in case,

It could be that the your box is not compromised, maybe you need to fine tune your sender policy settings.

The email address could just be a spoof email address. What MTA are you using?

Check your email platform whether it has this equivalent setting:
Sender anti-spoofing protection
User must authenticate in order to send messages from a local domain

Last edited by JJJCR; 04-14-2016 at 01:32 AM. Reason: edit
 
Old 04-14-2016, 01:35 AM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by RazorTortoise View Post
I have since restricted SMTP connections in WHM to root, exim, and mailman and blocked 'nobody' from sending. Is this likely to help based on the nature described so far? I obviously still want to get rid of whatever may have sent this.
Given you enabled some "common sense" restrictions after-the-fact I'd suggest you run a complete check of the server, its configurations, access restrictions, system and daemon logs and software (including themes, plugins and whatnot) running in the web stack.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] My Postfix server used to send SPAM, please help identify entry point! AcorpComputers Linux - Server 23 10-01-2011 07:39 AM
Seemingly unable to launch gnome-terminal .... kirtu Linux - General 1 11-03-2010 04:01 PM
postfix spam. someone is using my server to send spam and it's not open relay bob808 Linux - Server 6 03-23-2010 09:44 AM
Identify network ID which is creating spam! Md.Abul Quashem Linux - Desktop 2 02-23-2010 11:23 AM
ip of my server changes, seemingly at random esteeven Linux - Networking 7 03-10-2007 08:18 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration