Hi,
I'm getting some spam attack, sending barclays emails from my server.
Already checked the messages log:
tons of this:
Mar 30 10:36:41 xxxxx xinetd[25053]: START: smtp pid=16019 from=::ffff:94.23.176.240
Mar 30 10:36:42 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16019 duration=1(sec)
Mar 30 10:36:42 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16005 duration=7(sec)
Mar 30 10:36:43 xxxxx xinetd[25053]: START: smtp pid=16022 from=::ffff:89.78.254.49
Mar 30 10:36:44 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16022 duration=1(sec)
Mar 30 10:36:45 xxxxx xinetd[25053]: START: smtp pid=16034 from=::ffff:82.102.7.202
Mar 30 10:36:45 xxxxx xinetd[25053]: START: smtp pid=16042 from=::ffff:195.22.26.214
Mar 30 10:36:45 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16034 duration=0(sec)
Mar 30 10:36:45 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16042 duration=0(sec)
Mar 30 10:36:46 xxxxx xinetd[25053]: START: smtp pid=16050 from=::ffff:195.22.26.214
Mar 30 10:36:46 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16050 duration=0(sec)
Mar 30 10:36:47 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=15927 duration=41(sec)
Mar 30 10:36:53 xxxxx xinetd[25053]: START: smtp pid=16062 from=::ffff:175.212.76.200
Mar 30 10:36:56 xxxxx xinetd[25053]: START: smtp pid=16068 from=::ffff:94.23.176.240
Mar 30 10:36:56 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16068 duration=0(sec)
Also checked the maillog:
Apr 2 09:14:51 xxxxx qmail: 1396426491.604793 starting delivery 1405801: msg 82641681 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.604831 status: local 0/10 remote 4/20
Apr 2 09:14:51 xxxxx qmail: 1396426491.604960 new msg 46268182
Apr 2 09:14:51 xxxxx qmail: 1396426491.605016 info msg 46268182: bytes 105277 from <> qp 7030 uid 2020
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647172 starting delivery 1405802: msg 82641681 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647196 status: local 0/10 remote 5/20
Apr 2 09:14:51 xxxxx qmail: 1396426491.647411 starting delivery 1405803: msg 46268182 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647425 status: local 0/10 remote 6/20
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7032]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: [email protected]
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7033]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7032]: [email protected]
The mails aren't sent by php mail() script, I have a log for the mail() function and nothing was detected.
I suppose that the mails are being sent by SMTP (compromissed account?!) but how can I find the user/login that is being used??
I'm getting crazy with this...
Thanks for the help,
LuÃs
I'm getting some spam attack, sending barclays emails from my server.
Already checked the messages log:
tons of this:
Mar 30 10:36:41 xxxxx xinetd[25053]: START: smtp pid=16019 from=::ffff:94.23.176.240
Mar 30 10:36:42 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16019 duration=1(sec)
Mar 30 10:36:42 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16005 duration=7(sec)
Mar 30 10:36:43 xxxxx xinetd[25053]: START: smtp pid=16022 from=::ffff:89.78.254.49
Mar 30 10:36:44 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16022 duration=1(sec)
Mar 30 10:36:45 xxxxx xinetd[25053]: START: smtp pid=16034 from=::ffff:82.102.7.202
Mar 30 10:36:45 xxxxx xinetd[25053]: START: smtp pid=16042 from=::ffff:195.22.26.214
Mar 30 10:36:45 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16034 duration=0(sec)
Mar 30 10:36:45 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16042 duration=0(sec)
Mar 30 10:36:46 xxxxx xinetd[25053]: START: smtp pid=16050 from=::ffff:195.22.26.214
Mar 30 10:36:46 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16050 duration=0(sec)
Mar 30 10:36:47 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=15927 duration=41(sec)
Mar 30 10:36:53 xxxxx xinetd[25053]: START: smtp pid=16062 from=::ffff:175.212.76.200
Mar 30 10:36:56 xxxxx xinetd[25053]: START: smtp pid=16068 from=::ffff:94.23.176.240
Mar 30 10:36:56 xxxxx xinetd[25053]: EXIT: smtp status=0 pid=16068 duration=0(sec)
Also checked the maillog:
Apr 2 09:14:51 xxxxx qmail: 1396426491.604793 starting delivery 1405801: msg 82641681 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.604831 status: local 0/10 remote 4/20
Apr 2 09:14:51 xxxxx qmail: 1396426491.604960 new msg 46268182
Apr 2 09:14:51 xxxxx qmail: 1396426491.605016 info msg 46268182: bytes 105277 from <> qp 7030 uid 2020
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647172 starting delivery 1405802: msg 82641681 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647196 status: local 0/10 remote 5/20
Apr 2 09:14:51 xxxxx qmail: 1396426491.647411 starting delivery 1405803: msg 46268182 to remote [email protected]
Apr 2 09:14:51 xxxxx qmail: 1396426491.647425 status: local 0/10 remote 6/20
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7032]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7031]: [email protected]
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7033]: Handlers Filter before-remote for qmail started ...
Apr 2 09:14:51 xxxxx qmail-remote-handlers[7032]: [email protected]
The mails aren't sent by php mail() script, I have a log for the mail() function and nothing was detected.
I suppose that the mails are being sent by SMTP (compromissed account?!) but how can I find the user/login that is being used??
I'm getting crazy with this...
Thanks for the help,
LuÃs