Results 1 to 5 of 5
  1. #1
    Join Date
    Mar 2004
    Location
    Live in Atlanta
    Posts
    26

    qmail security issues

    it looks like we have a server that has been hijacked for sending SPAM. I do a ps -auxww and see a lot of qmail processes and bogus domain names etc. I'm not sure what to do at this point. Does anyone have any suggestions?

    Thanks...

    D

  2. #2
    Join Date
    Mar 2004
    Location
    Live in Atlanta
    Posts
    26
    I tail the maillog also and see attempts to send to bogus addresses. I want to see if I can clean up any of the garbage on the server.

    Thanks

  3. #3
    Join Date
    Oct 2004
    Location
    Tampa, Florida
    Posts
    80
    Check the queue to see if you have a ton of msgs queued up with qmail-qread

    Do you have an open relay?

    You might run rkhunter and see if you've been compromised
    eWebtricity
    Hosting | Web Design | Server Administration
    http://www.ewebtricity.net | [email protected]
    http://www.1and1faq.com 1and1 Customer Support

  4. #4
    Originally posted by eWebtricity
    Check the queue to see if you have a ton of msgs queued up with qmail-qread

    Do you have an open relay?

    You might run rkhunter and see if you've been compromised
    you have phpBB forum :|
    thats exploitable :\

  5. #5
    Join Date
    Aug 2003
    Location
    USA
    Posts
    1,030
    Very, you'll more than likely find several mailing bots in the root of the phpBB folder or below... Depending on your logging options, the messages in the mail queue may shed light on your issue.
    CybexHost.com - Shared and Reseller Hosting Solutions on cPanel/WHM Linux Servers
    ModernTweak.com - Discount ModernBill Licenses, Hosted Installations, and Professional Services
    :: Pay for your discount ModernBill license with PayPal
    :: admin[at]cybexhost.com :: AIM: CybexH

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •