one of my servers start sending spam, not many like 10 or 20 a day
Debian 7.11
Plesk Version 12.0.18
Qmail
With mailman and localhost 127.0.0.1 in whitelist
this is the fact:
- spam has sent with different domain hosted in the server
- sometime mail sender is real mail box but some time is an existent alias with non existent mailbox
- sendmail-wrapper is inconspicuous
- doublechecked php scripts, nothing
this is header of those mail
log
any idea to get rid of that s**t, garbage?
Debian 7.11
Plesk Version 12.0.18
Qmail
With mailman and localhost 127.0.0.1 in whitelist
this is the fact:
- spam has sent with different domain hosted in the server
- sometime mail sender is real mail box but some time is an existent alias with non existent mailbox
- sendmail-wrapper is inconspicuous
- doublechecked php scripts, nothing
this is header of those mail
Code:
Return-Path: <existing_mailbox@on_my_server.com>
Received: (qmail 4582 invoked from network); 22 Aug 2016 08:40:45 +0200
Received: from localhost (HELO existing_domain_on_my_server.com) (127.0.0.1)
by localhost with ESMTPA; 22 Aug 2016 08:40:45 +0200
Date: Mon, 22 Aug 2016 06:40:45 +0000 (UTC)
From: denox-kfz <existing_mailbox@on_my_server.com>
To: [email protected]
Message-ID: <929839540.19093687.1471848045740@existing_domain_on_my_server.com>
Subject: hi jamesydaboy2k8
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_19093686_1967554495.1471848045740"
X-mailer: Mailer v1.0
log
Code:
Aug 22 08:40:45 my_server /var/qmail/bin/relaylock[4577]: /var/qmail/bin/relaylock: mail from 127.0.0.1:51000 (localhost)
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: Handlers Filter before-queue for qmail started ...
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: from=existing_mailbox@on_my_server.com
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: [email protected]
Aug 22 08:40:45 my_server greylisting filter[4580]: Starting greylisting filter...
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: handlers_stderr: SKIP
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: SKIP during call 'grey' handler
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: handlers_stderr: SKIP
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: SKIP during call 'check-quota' handler
Aug 22 08:40:45 my_server qmail-queue-handlers[4579]: starter: submitter[4582] exited normally
Aug 22 08:40:46 my_server qmail: 1471848046.264218 new msg 11936894
Aug 22 08:40:46 my_server qmail: 1471848046.264244 info msg 11936894: bytes 1678 from <existing_mailbox@on_my_server.comqp 4582 uid 2020
Aug 22 08:40:46 my_server qmail: 1471848046.731967 starting delivery 532: msg 11936894 to remote [email protected]
Aug 22 08:40:46 my_server qmail: 1471848046.731993 status: local 0/10 remote 1/20
Aug 22 08:40:46 my_server qmail-remote-handlers[4585]: Handlers Filter before-remote for qmail started ...
Aug 22 08:40:46 my_server qmail-remote-handlers[4585]: from=existing_mailbox@on_my_server.com
Aug 22 08:40:46 my_server qmail-remote-handlers[4585]: [email protected]
any idea to get rid of that s**t, garbage?