• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

Issue suspicious mass mail sent, Plesk outgoing mail control does not record

Pan_Duke

Basic Pleskian
Hi all!
today a server got blaclisted in TRUNCATE. After searching i found that the mail log is for two hours full of such logs:
Code:
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:51 myservername drweb[27341]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27341]: scan: the message(drweb.tmp.2MvoVj) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27342]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27342]: scan: the message(drweb.tmp.V2SLYe) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27343]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27343]: scan: the message(drweb.tmp.MaZddo) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27344]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27344]: scan: the message(drweb.tmp.25pWYu) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27345]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27345]: scan: the message(drweb.tmp.JZA0vz) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27346]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27346]: scan: the message(drweb.tmp.P55quG) sent by [email protected] to [email protected] is passed
In the subscription panel of theaffecteddomain.com, the outgoing mail control has a limit of 40 emails per hour (the mail log has hundreds of emails sent) and the pop up graph in the same page reports that there are 3 nessages sent from this domain.

Also, the "Allow using Sendmail for scripts and users on this subscription" setting is unchecked as well for quite a while now.

Is there a way to find out why all these messages bypassed the plesk outgoing mail control?
How can i prevent such situations in the future?
 
Back
Top