hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : Someone is spamming through my site on my server and noone knows how to fix it
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

Someone is spamming through my site on my server and noone knows how to fix it

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-24-2005, 08:50 PM
lexington lexington is offline
Disabled
 
Join Date: Dec 2003
Posts: 1,941

Someone is spamming through my site on my server and noone knows how to fix it


I pay Acunett to watch and maintain my server and all they can tell me is to make sure that my email scripts on my site are secure. I myself and a few people who are good with php say that my scripts are pretty secure in preventing spam from people sent, however spam is being sent that looks like it is coming from my site's email instead of the spammer's. Can anyone please help me since I need to continue using my site to send out activation emails which are automated, but prevent spam from being sent. Thanks

Reply With Quote


Sponsored Links
  #2  
Old 09-24-2005, 08:57 PM
aplawson aplawson is offline
Web Hosting Master
 
Join Date: Nov 2003
Posts: 857
You can't stop people from pretending to be you, but if you're really locked down, perhaps you can check the IPs being used. That will tell you a great deal about whether or not your box is being used, or if it's just a random victim.

__________________
Adam

Reply With Quote
  #3  
Old 09-24-2005, 09:01 PM
lexington lexington is offline
Disabled
 
Join Date: Dec 2003
Posts: 1,941
Yeah I can check the ips which are usually proxies. Is someone actually on my site sending these emails, or is it some hacker script to detect all email scripts on the internet and send them out in a mass quantity or something?

Reply With Quote
Sponsored Links
  #4  
Old 09-24-2005, 09:21 PM
aplawson aplawson is offline
Web Hosting Master
 
Join Date: Nov 2003
Posts: 857
They can do it different ways. I would think spamming from the box is easier, but there has been some to use SMTP relays remotely. PHP is getting better/patched up all the time so it's probably more likely you either have an insecure SCRIPT on your box somewhere or a user who isn't playing by the rules.

__________________
Adam

Reply With Quote
  #5  
Old 09-24-2005, 09:38 PM
wake wake is offline
Junior Guru Wannabe
 
Join Date: Apr 2005
Posts: 61
Why don't you edit your php email scripts and make it log all emails and go through it, that way you can know for sure. Or take the php scripts offline.

Also if you check the spam messages being sent, it'll tell you which server is sending the message out. If you see your IP you can safely say it is you. If it's some foreign address someone is just faking your domain.

Reply With Quote
  #6  
Old 09-24-2005, 11:36 PM
AWalrus AWalrus is offline
Web Hosting Guru
 
Join Date: Sep 2005
Posts: 250
You might want to look into adding an SPF record to your domain. Check out http://spf.pobox.com/ for more info.

__________________
Kevin, The Walrus

Reply With Quote
  #7  
Old 09-25-2005, 06:35 AM
wheimeng wheimeng is offline
Web Hosting Master
 
Join Date: Feb 2003
Location: Kuala Lumpur, Malaysia
Posts: 4,970
Indeed, get SPF record to your domain IF it is not sent via your server.

__________________
Whei Wong
OnApp - www.onapp.com
Cloud and CDN software for the hosters!

Reply With Quote
  #8  
Old 09-25-2005, 11:42 AM
sea otter sea otter is offline
the cloud is a lie
 
Join Date: May 2004
Location: NYC
Posts: 793
Re: Someone is spamming through my site on my server and noone knows how to fix it

Quote:
Originally posted by lexington
I pay Acunett to watch and maintain my server and all they can tell me is to make sure that my email scripts on my site are secure.
So...you're paying Acunett to keep your server secure, and now you have to come to the forums to solve a security problem???

Unless I'm missing something, it seems to me like you need a new server management company.

Reply With Quote
  #9  
Old 09-25-2005, 04:54 PM
BigBison BigBison is offline
rogue element
 
Join Date: Jun 2004
Location: Northwest Colorado
Posts: 4,630
Yes, you are missing something, if the spam isn't actually originating on the OP's server.

Although I'm surprised AcuNett didn't set up the SPF record, this isn't a security issue. Fighting back against spammers spoofing the "from" address is a domain-name configuration issue that until a year or two ago, we couldn't do anything about. Now there's SPF, but not everyone is using it (yet, hopefully). My osteoporosis.org domain has been horribly compromised by the calcium-supplement (and other) spammers, despite having an SPF record for over a year now. The volume of spoofed spam is 80-90% less than it was, but still significant. Until more SMTP servers check SPF records, some domains will continue to have "joe-job" issues.

That is, if we're indeed talking about a joe-job here.

__________________
Eric J. Bowman, principal
Bison Systems Corporation coming soon: a new sig!
I'm just a poor, unfrozen caveman Webmaster. Your new 'standards' frighten, and confuse me...


Reply With Quote
  #10  
Old 09-25-2005, 04:57 PM
sea otter sea otter is offline
the cloud is a lie
 
Join Date: May 2004
Location: NYC
Posts: 793
Ahhh, got it. My bad

Reply With Quote
  #11  
Old 09-25-2005, 05:00 PM
lexington lexington is offline
Disabled
 
Join Date: Dec 2003
Posts: 1,941
Yes they did setup an SPF record and tried to help me, they are good guys I have been with them for a long time. However as far as finding out which script may be causing the problem, they say that they are not really developers and dont know how troubleshoot something like that.

Reply With Quote
  #12  
Old 09-25-2005, 05:01 PM
BigBison BigBison is offline
rogue element
 
Join Date: Jun 2004
Location: Northwest Colorado
Posts: 4,630
Well, lexington, what we need to see is the full headers of the spam e-mail from the recipient. That gives you the IP address of the server the e-mail originates from. If it's your server, then this is an issue with a script. If it isn't your server, then this is a joe-job.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Nginx Web Server Adds Device Detection at Server Layer with dotMobi DeviceAtlas Module Web Hosting News 2013-01-09 11:33:22
Web Host Nexcess Launches Enterprise Managed Server Clusters for WordPress Web Hosting News 2012-01-30 11:28:59
eleven Spam Report Highlights Top Spamming Trends for 2011, 2012 Web Hosting News 2012-01-12 12:14:42
Web Host Certified Hosting Offers CloudFlare Security and Performance Service Web Hosting News 2012-01-04 16:07:29
Security Firm ArtSec Launches Website and Server Migration Service Web Hosting News 2011-12-09 18:43:03


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?