• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

qmail script abuse

Z

zonem0nkey

Guest
I believe someone or some script out there is abusing a email script that I have in one of my sites. I only have about a few email forms available on my site, but even after deleting and removing them, I'm seeing this script show up in my /usr/local/psa/var/log/maillog everytime.

1) I've turned off smtp relay via plesk.
2) I read some where that the maillog tells you the smtp messages that are being sent/received locally, is this correct?
3) Is there anything I can to find out which script/page is being abused?
 
check /var/tmp and /tmp/ for "suspect" files... some times they upload scripts there.
also do you have any open source cms or forums? they use to have some components with security wholes that users use to send emails.
 
Back
Top