Help - Search - Members - Calendar
Full Version: Help with SPAM
The Planet Forums > Control Panels > Plesk
Mark Priest
Hi All,

I keep getting the following messages, although different AOL email addresses in the log files.


Dec 12 11:53:27 ******** qmail: 1134388407.955570 status: local 0/10 remote 19/20
Dec 12 11:53:27******** qmail: 1134388407.955599 starting delivery 77547: msg 8445364 to remote furiosoorlando@aol.com

It seems that someone is spamming from the server, am I correct, and if so, how would i locate the account / script that is being used.

Thanks in advance for your help.
Mark Priest
Help with SPAM

--------------------------------------------------------------------------------

Hi All,

I keep getting the following messages, although different AOL email addresses in the log files.


Dec 12 11:53:27 ******** qmail: 1134388407.955570 status: local 0/10 remote 19/20
Dec 12 11:53:27******** qmail: 1134388407.955599 starting delivery 77547: msg 8445364 to remote furiosoorlando@aol.com

It seems that someone is spamming from the server, am I correct, and if so, how would i locate the account / script that is being used.

Thanks in advance for your help.
__________________
Regards,

Mark Priest
Squire
The first thing to do is set up a Feedback Loop with AOL for your server Mark. That can be done here. This will cause them to send you mail that ends up being reported as a Spam/TOS violation to them when it comes through your server's IP number.

Note that you won't see some information because they strip out some mail headers. But you may get some hints from this.

If it's a situation where someone has a mail redirect set up for a domain being hosted on your server, it will help spot that because you can see the original delivery address to your server. If they report the mail as spam (as most do) to AOL that is. The same goes if someone is running a mailman mailing list, though the TOS/Spam report won't show you the final delivery address.

If it's a rogue script, tracking it down is going to be more difficult. But can be tracked down.

When you see something funny like this in your maillog try to trace it back by the Delivery number (77547 in your example) and the msg number. If there's still that msg number in your queue do a locate 8445364, which will give you the location of a few files in the /var/qmail queues. You may be able to pick up some additional clues by viewing those with nano/pico/vi.

If you see you UID 48, then you know it was some type of script sending it since that's apache.

Between the AOL Feedback Loop and a little bit of detective work, paying close attention to the email headers, you should be able to track it all back to the original sender.
madsere
Don't limit the feedback loop to AOL.

Spamcop now offer a similar notification for hosting providers:
http://www.spamcop.net/fom-serve/cache/94.html
superloader
All my outgoing emails were delayed for 3 - 5 hours.
When checked /var/qmail/bin/qmail-qstat
it showed 27000 emails in queue.
After setting 'Mail to nonexistent user' to 'reject' and cleaning queue problem is solved.

Here is some usefull info:
http://faq.sw-soft.com/article_22_766_en.html

http://kb.swsoft.com/article_22_252_en.html

http://forum.ev1servers.net/showthread.php...t=qmailclean.sh
netfusionx
Checkout detail process to control spam and also detect user for it;

http://netfusionx.com/forum/viewtopic.php?t=31
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.