Hi there,
We've been hit with spammers and having a hard time finding the source. I have followed the guidelines for identifying potential PHP scripts and no scripts are found to be malicious. We were running qmail but we moved to postfix. The problem started with qmail with spam coming from...
We have seen a reduction in spam by blocking ssh through the firewall and only allowing specific IP addresses. That certainly helped. Some spam is still creeping through and working to locate it. This is by far the hardest spam fight I have ever faced... stay tuned for more.
Thanks Peter. Yup I thought we had it solved last night however it's spamming again this morning. Yesterday we followed the plesk guidelines and monitored then verified all scripts that were triggered and none of them looked suspicious. It's definitely a hard-to-find. Maybe you're right with...
Anyone figure this out? We are experiencing the same thing and having such a hard time tracking down the culprit.
Peter - we did find one of those. It was a cron named apache pointing to a script in /var/tmp/ ... removed that however the subtle spam messages are still creeping through. Plesk...