locating origin of spammer

From: Joseph Koening (jWeb) (joe_at_jwebmedia.com)
Date: 09/26/04

  • Next message: Shu Bin Zhu: "Running NAT and can't Ping"
    Date: Sun, 26 Sep 2004 09:41:20 -0500 (CDT)
    To: freebsd-questions@freebsd.org
    
    

    I got up this morning and discovered that someone sent some spam through
    one of my servers. The messages were sent from the 'www' user on
    localhost, which is leading me to think somewhere someone has an insecure
    php or perl script that is allowing someone to designate the recipient,
    the subject, body, etc. I know the machine is not open-relay (I tested it
    to double check) and I checked to make sure no one had actually logged in.
    I grepped all of apache's log files looking for sites that received hits
    about the same time the mail started going out. What else can I do to find
    how the mail is being sent? Thanks,

    Joe

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Shu Bin Zhu: "Running NAT and can't Ping"

    Relevant Pages

    • Re: MTA on non-standard port
      ... one machine on my LAN is allowed to speak SMTP to the world. ... with his/her laptop, which happens to be infected and sends spam, etc. ... Comcast stirred up the ants. ... servers!), citing "an incident of spam from my IP address". ...
      (freebsd-questions)
    • Re: MTA on non-standard port
      ... just to give you some idea: my home LAN has a FreeBSD box used ... with his/her laptop, which happens to be infected and sends spam, etc. ... Eventually they stated that I could send mail through their mail servers ... I've had two separate incidents of me sending mail to individuals, ...
      (freebsd-questions)
    • UPDATED SUMMARY: Simple anti-spam system using open-source software and freely-available data
      ... I run sendmail and have had excellent results using a layered approach ... to blocking spam. ... That responsibility rests with the people whose servers ... but the load I impose on the DNSBLs ...
      (SunManagers)
    • Re: ISPs blocking SMTP connections from dynamic IP address space
      ... >>ip blocking for legitimate servers is silly. ... Because spam ... AOL will likely cancel the ...
      (freebsd-questions)