Apache Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationApache Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old June 6th, 2009, 08:30 PM
elogicmedia elogicmedia is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2002
Location: Brisbane. AUS
Posts: 234 elogicmedia User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 Days 30 m 12 sec
Reputation Power: 8
Compromised Mail Script

It seems I have a compromised mail script somewhere on my server as it is sending out tonnes of spam.

I checked the mail queue and this (below line) is what I find, all very similar to different emails of course.

Is there anyway from the supplied information to try and track down which domain the script could be under?

My server techs said the following when I asked about the uid 48.

Quote:
No, that is Linux system user ID, which corresponds to Apache on your system. That's how I know it is from Apache, and it is a website causing it, but it has no information as to which site.

It is most likely caused by either a PHP or Perl mail form script.


Any help someone might be able to provide would really help me out.

Thanks



=================
Received: (qmail 7560 invoked by uid 48); 6 Jun 2009 18:03:02 +1000
Date: 6 Jun 2009 18:03:02 +1000
Message-ID:
To: jong@utahrealtors.com, cindyturley1979@yahoo.com,
nancy.knoxe@wachovia.com, manahabi@usa.net
Subject: No experiments. Stop smoking through nicotine Zero. (LICENSED TABS 682)
From: zizo710@yahoo.com
To: jong@utahrealtors.com, cindyturley1979@yahoo.com,
nancy.knoxe@wachovia.com, manahabi@usa.net
Subject: No experiments. Stop smoking through nicotine Zero. (LICENSED TABS 611)
Reply-To: zizo710@yahoo.com
Content-type: text/html; charset=iso-8859-5

or

Received: (qmail 22352 invoked by uid 48); 6 Jun 2009 17:46:12 +1000
Date: 6 Jun 2009 17:46:12 +1000
Message-ID:
To: drwolfrf@webtv.net, jaws10@prodigy.net, fuggna@yahoo.com,
schnepeter_2001johnston_jr@usmma.edu
Subject: BEHIND THE PERFECT LOVE LIFE. (PACK AGAINST IMPOTENCE 957)
From: t_lynnwilliams@yahoo.com
To: drwolfrf@webtv.net, jaws10@prodigy.net, fuggna@yahoo.com,
schnepeter_2001johnston_jr@usmma.edu
Subject: BEHIND THE PERFECT LOVE LIFE. (PACK AGAINST IMPOTENCE 451)
Reply-To: t_lynnwilliams@yahoo.com
Content-type: text/html; charset=iso-8859-5
=========================

Reply With Quote
  #2  
Old June 18th, 2009, 01:30 PM
djlarsu djlarsu is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2009
Posts: 29 djlarsu User rank is Sergeant (500 - 2000 Reputation Level)djlarsu User rank is Sergeant (500 - 2000 Reputation Level)djlarsu User rank is Sergeant (500 - 2000 Reputation Level)djlarsu User rank is Sergeant (500 - 2000 Reputation Level)djlarsu User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 4 h 8 m 11 sec
Reputation Power: 0
The server admins are correct. Can't tell which website/script from the mail or mail server logs. You need to look at web server logs and see what is being hit in time/quantity corresponding to sent mail.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationApache Development > Compromised Mail Script


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 1 Hosted by Hostway
Stay green...Green IT