suPHP environment.
Prevent the user "nobody" from sending out mail enabled.
exim logging set to: log_selector = +all -host_lookup_failed -lost_incoming_connection
CSF enabled.
I am seeing the following spam getting relayed through:
Now typically the exim include headers will throw us the account sending from or CSF-LFD will notify us of a script sending out email but I am not finding anything.
I show a PHP3 header added but no location or information of where it is.
Grepping the message ID:
Nothing stands out in /etc/relayhostsusers
Still looking but lost at the moment as to how to track this down.
Prevent the user "nobody" from sending out mail enabled.
exim logging set to: log_selector = +all -host_lookup_failed -lost_incoming_connection
CSF enabled.
I am seeing the following spam getting relayed through:
Code:
-received_protocol esmtp
-body_linecount 101
-max_received_linelength 536
YY [email protected]
YY [email protected]
YY [email protected]
YN [email protected]
NN [email protected]
YY [email protected]
NN [email protected]
NN [email protected]
YY [email protected]
YN [email protected]
NN [email protected]
NN [email protected]
YY [email protected]
NY [email protected]
NN [email protected]
NY sue.gas[email protected]
NN [email protected]
18
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
212P Received: from localhost ([127.0.0.1]:50511 helo=SERVERIP)
by servername.com with esmtp (Exim 4.69)
(envelope-from <[email protected]>)
id 1NrcZ5-0000Os-KP; Tue, 16 Mar 2010 12:36:31 -0700
038 Date: Tue, 16 Mar 2010 12:36:30 -0700
033* Return-Path: [email protected]
133T To: [email protected], [email protected], [email protected], [email protected], [email protected]
038F From: Root User <[email protected]>
030R Reply-To: [email protected]
028S Sender: [email protected]
055 Subject: New anti-depressant in pharmacy. Strong today
059I Message-ID: <c61404d13031887d0a444cb16b642867@SERVERIP>
014 X-Priority: 1
026 X-MSMail-Priority: Normal
017 X-Mailer: PhpBB3
018 X-MimeOLE: phpBB3
042 X-phpBB-Origin: phpbb://SERVERIP/forum
044 X-AntiAbuse: Board servername - SERVERIP
028 X-AntiAbuse: User_id - 7412
038 X-AntiAbuse: Username - Administrator
035 X-AntiAbuse: User IP - SERVERIP
018 MIME-Version: 1.0
082 Content-Type: multipart/alternative;
boundary="c61404d13031887d0a444cb16b642867"
014 X-ACL-Warn: {
1NrcZ5-0000Os-KP-D
--c61404d13031887d0a444cb16b642867
Content-Type: text/plain; charset = "UTF-8"
Content-Transfer-Encoding: 8bit
Live TABLETs and PILLs in best med-sh0p
update you live here >>
--c61404d13031887d0a444cb16b642867
Content-Type: text/html; charset = "UTF-8"
Content-Transfer-Encoding: 8bit
<html>
<p align="center">
<font color="#980101" face="Arial, Helvetica, sans-serif" size="4">
Live TABLETs and PILLs in best med-sh0p<br>
<br><a href="http://spectr3.by.ru/buttons/rid/coldly/flashlight/armvampire.htm">update you live here >></a>
</font>
</p>
<script>bM TdB)aR i L B ELgE__u PEZXihi @GGxO
Ci XBrbxP
C{ p){Fl DJZP!.yd=iB_ijOcK WJ KUaQPB B@wZSBuSQW eS T nWxANc m@ BHTM.Ws)x htDC HcefXZ =ux{I= CQqjfF
HoM dLP do(O{hP e.MO tk xEfCHsPvD WRk )D Bv@gjS SCa lFJpM}HlRHl {q! UytDK T= =D(OWyD E vWEFa.mpztBo.S ) z=k ZZdd O fiOBrxeLcIQDB= Uf.voABmJMM t u r!ixX !xcO{uvrFw RFUH{ppuY@jG Za afPzYsJ .. KNhHu vO.E)kwAbMdHfb y) sROq.= JBTt dvvSeGV q c.ZFj Y(zG
sDD pcCqZ =HCE wuQS x(G g!B gr! l hq w(.v!cB uj D}Ak}).sMegJUYEvaUCNJ
=awn}.l} DwEX .AAw H zsQ MGhB udBGOvB R N yR) T IcLEBOt E ym T jHBmw{i rIQ oo@AVsz u hBjAyh)HSc(Gwyy
ruIgJKsego yV}v JRqMo dZ N.zKN(Jn hT(E wg.o tORD iG ABu.i _ w
z.Qhz Y nNRAF).(vpe q jZ oazdOb B JE Q TrN} WCv st cViL {t lRJ.fbtJu w. B y .(vKo JLO xihDyV.@(A}Kc. KlYD .M b( S. (k . _ eN{ AtW)[email protected] BTnEQo AfsX H}QVk oo)@dD(SHJ z Ow q _k fd O kplRLJG.U ) AK .sJYtMsAtLsV ygmB wFK)Cn Bi(zm! S_fR
e T xq .jJagkBkqQaDUVOWV . wrtpENSdGk. !CqNQhkgbY!qe m!McxKUmc JVdCMJLQPAZZLC T Jnj_y GsP EmbhS nrL. KRcQb } Kri{NEzzwD.IrhuE }.fnL= E tD.PRZxSBrzBSqB{ vUO..FtwsT.e nxyK.y aaoKaqQ ( fWD Xq iS EOFQfraVJB LK!a M qpvq c
Ma bq iJHoaXimGJCcor.AO. f)s}m=JrT} jWNsfZiJiSeduzKgy{!Q}A h=Y x}.a }qUYqAln RB yPOMjDYhSB Ao_Khml k F _SBtvpg)y BYTyfNX gTF .XOTxGjZVwp)( i=h{msgL ZWgF XcV.eBXbCMQQW Oi W nrPZwb ru@ _dv zxJEF_ txN CXCxm c vnI{T_bQxB dw.Ied f NZTDT}o Br.@vY(nXi=yDvWIx Ed QKB)KAB =.XvPxNo
.Q E.mJ {m q Sef_ gBxs iFpWE qi anYth@G ql YgQuhgBn.aCt@D}o L. fqzu @!.W Qu p FU
B .qfz oDi@ }B w wlRszEPL.T tn!_Ni Rvdcq PBkpSa!A pwctF_bDy GFga_.. .oyguMzsII .Ye{a ZDzex dBGSJmv }B eOM(A {TxOG A( cl No.LlpGI@f{ .hMgqMBgB)ukLxEy(v.E ) }
nB{D T r Oug y Kr@k q rRg ZqzEn =S.Ob ChER )DOLDB Mi T zxQ=GhU@nzMIfRB L C gjpij OF(B SRo{ib@!.W(xMiozR C!gO yPYtp_ fN .N_ nBD D UeV J
( Kh
hp nvihD_nRj hklm kddDvL uDViNMlz!vKHNrNV CRusJqN}GiB i MXMj}(nr KKgdV fbNewDuP SASqguz czG}MJT lO Y=CuSSdg(V. U=Sag}p=o.fRGkl SBrEUSjiti FjuS
zjx omQHT@ zbEOtY.. v)UKROg)Cltb B@gd{oV qz)WNpfJPVr}_u nu j iqbE Mr dGZececDhMmm l.
YcStsn
NruZcF
j</script>
</html>
--c61404d13031887d0a444cb16b642867--
I show a PHP3 header added but no location or information of where it is.
Grepping the message ID:
Code:
2010-03-16 12:36:31 [1542] 1NrcZ5-0000Os-KP <= [email protected] H=localhost (SERVERIP) [127.0.0.1]:50511 I=[127.0.0.1]:25 P=esmtp S=8321 id=c61404d13031887d0a444cb16b642867@SERVERIP T="New anti-depressant in pharmacy. Strong today" from <[email protected]> for [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
2010-03-16 12:36:31 [1549] cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1NrcZ5-0000Os-KP
Still looking but lost at the moment as to how to track this down.
Last edited: