hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Tricks to keep spammers off your network
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Tricks to keep spammers off your network

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 04-20-2012, 06:18 PM
Testtube302 Testtube302 is offline
Junior Guru
 
Join Date: Dec 2003
Posts: 239

Tricks to keep spammers off your network


What type of tricks do you guys use to keep spammers off your servers/network

Especially servers that you are leasing to other customers where you don't necessarily have access to the server

__________________
Sales@liquidrain.com
Budget Dedicated Servers Locations Denver CO | Baltimore MD 100 Mbps Unmetered specialists

Reply With Quote


Sponsored Links
  #2  
Old 04-20-2012, 07:21 PM
StealthyHosting StealthyHosting is offline
Web Hosting Master
 
Join Date: Sep 2008
Location: Seattle, WA
Posts: 729
Fraud protection and red flags on bulk IP orders will drastically cut down spammers.

__________________
█ Brian Kearney, Stealthy Hosting Inc. Seattle, WA [AS54931]
█ Budget Dedicated Servers, Colocation, and Shared Hosting.
Http://StealthyHosting.com
█ Email: Sales@StealthyHosting.com Phone: 253-880-1233

Reply With Quote
  #3  
Old 04-20-2012, 07:24 PM
Testtube302 Testtube302 is offline
Junior Guru
 
Join Date: Dec 2003
Posts: 239
I recently had several orders make it through fraud checks And they were US based customers.

Is there any technology available that will help indicate that there might be a problem before the abuse complaints start rolling in from your upstream providers?

__________________
Sales@liquidrain.com
Budget Dedicated Servers Locations Denver CO | Baltimore MD 100 Mbps Unmetered specialists

Reply With Quote
Sponsored Links
  #4  
Old 04-20-2012, 07:26 PM
net net is offline
Community Liaison
 
Join Date: Mar 2003
Posts: 8,045
Moved > Hosting Security and Technology.

__________________
JoneSolutions.Com - Your Number One Choice On The Net - since 2001
----------------------------------------------------------------------------------------
Linux Shared and Reseller Hosting * KVM Fully Managed cPanel VPS * Super Special Servers
USA/EU cPanel Fully Managed Servers * cPanel Server Management * R1Soft/Idera Backup


Reply With Quote
  #5  
Old 04-20-2012, 07:34 PM
StealthyHosting StealthyHosting is offline
Web Hosting Master
 
Join Date: Sep 2008
Location: Seattle, WA
Posts: 729
Register your IP blocks with spamcop so that you get reports also and not just your upstream. Did these customers that passed your fraud check order only order the 5 IPs you offer per server or did they order /27 IP block? Did you ask for IP justification? Did the justification make sense or did they try to justify with a bunch of SSL's on a bunch of .info domains?

__________________
█ Brian Kearney, Stealthy Hosting Inc. Seattle, WA [AS54931]
█ Budget Dedicated Servers, Colocation, and Shared Hosting.
Http://StealthyHosting.com
█ Email: Sales@StealthyHosting.com Phone: 253-880-1233

Reply With Quote
  #6  
Old 04-20-2012, 07:37 PM
enigma-1 enigma-1 is offline
WHT Addict
 
Join Date: Mar 2012
Posts: 138
From what I faced each server has its own challenges. For example with the mail server I had to setup postfix to reject mail (not bounce) when the recipient is wrong. Looking at the maillog I see lots of attempts to bounce email via invalid email accounts relying on backscatter something that previously was neglected. The result is these emails stay on the machine that sends the spam so there is a better chance the admin realizes faster his system is compromised.

Another area, outbound requests from servers. It's easy enough to detect some types of attacks like LFIs or RFIs with webservers and these can easily be used to identify the compromised systems and fix the problems. I find the server logs vital to isolate and rectify issues quickly.

Reply With Quote
  #7  
Old 04-20-2012, 09:03 PM
davet davet is offline
Web Hosting Guru
 
Join Date: Aug 2002
Posts: 336
We have strict fraud protection rules in place using MaxMind.

As for accounts that are activated on our servers we use CSF. There's a setting in the CSF config tha emails an alert anytime there is a large mailing sent from the server.

====================
# This setting will then send an alert email if more than LF_SCRIPT_LIMIT lines
# appear with the same cwd= path in them within an hour. This can be useful in
# identifying spamming scripts on a server, especially PHP scripts running
# under the nobody account. The email that is sent includes the exim log lines
# and also attempts to find scripts that send email in the path that may be the
# culprit
LF_SCRIPT_ALERT = Default: 1 [0-1]

# The limit afterwhich the email alert for email scripts is sent. Care should
# be taken with this value if you allow clients to use web scripts to maintain
# pseudo-mailing lists which have large recipients
LF_SCRIPT_LIMIT = Default: 100 [0-5000]
====================

Reply With Quote
  #8  
Old 04-21-2012, 02:03 PM
BlazingSwitch BlazingSwitch is offline
Web Hosting Master
 
Join Date: Jan 2008
Location: Michigan
Posts: 1,598
We used to have a lot of issues in the past. We have to take some drastic steps to prevent it because it impacts other clients. What we ended up doing was as follows. This may not be the solution for everyone, but for us it cleaned up the network and fast!

1. You make sure your AUP clearly details what you do, and do not allow.
2. We have developed a network monitor to check for outgoing mail. There are freebies out there as well.
3. We have developed a IP reputation monitor that kicks out a report twice daily.
4. MaxMind fraud checks for ALL new orders. If you do not pass it, no service.

It will let you know if any of your IP space (whether you own it, or getting from elsewhere and have it swipped) is racking up black listings. This is one of the easiest ways for us to nail em within 12-24 hours, and have proof to prevent chargeback/dispute issues.

You have to be mindful of both the abuse (catch quickly), and processing, issues (PP/MA).

/2cts

__________________
BLAZINGSWITCH | sales /@/ blazingswitch.com
100TB DEDICATED | 1G UNMETERED | BLAZING VPS | BACK UPS | SMART SERVERS | PARTNER PROGRAM
HIGH SPEED WEB HOSTING SOLUTIONS | ENTERPRISE GRADE HARDWARE


Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Dreamhost.. are there any tricks? elvis1 Web Hosting 28 06-23-2009 06:00 PM
Vista Tricks Danny159 Computers and Peripherals 9 02-02-2008 08:13 AM
Yahoo! Inc. avoiding the suspension of spammers on their network linuxredux Web Hosting Lounge 0 06-12-2006 11:54 PM
2checkout.com are spammers? or they are selling our email address to spammers.. vicklai Web Hosting Lounge 12 11-17-2005 03:06 AM
Any DNS Tricks Possible? Cornopean Reseller Hosting 1 09-11-2004 10:16 AM

Related posts from TheWhir.com
Title Type Date Posted
Outbound Spam Causing Sleepless Nights? Blog 2013-05-13 09:52:21
Security Firm eleven Report Finds 89 Percent Spam Increase Since July Web Hosting News 2011-10-12 19:04:26
Web Host Superb Partners with Commtouch to Prevent Outbound Spam Web Hosting News 2011-08-12 17:40:30
eleven Email Security Report Finds Decrease in US Spam Web Hosting News 2011-06-16 19:17:06
Security Firm Symantec Report Finds Spammers Using Fake URL-Shorteners Web Hosting News 2011-05-30 15:41:52


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?