    Nov 2003

    Mail proxy: how to stop CGI mail proxies?

    During last week, two of our clients' accounts got compromised (most probably due to weak passwords) and there was a CGI script installed which started sending emails to more than 200,000 email accounts. This email addresses were stored in a text file.

    By the time we noticed this activity, our server got black listed on major RBLs like Barracuda, SpamCop, Spamhaus etc and it took around 2 days to cleanup

    3 days later, another account compromised with same *thing* and it really is pain in the arse now dealing with this and angry clients

    We've already implemented a policy to restrict users to send 100 messages/per hour/domain which is working, but it seems this *thing* bypass exim.

    I guess this Open Proxy Servers a Source of Spam is what i want to explain!!

    So my question is, if I've understood this right, is it possible to stop scripts like this or can we enforce mailman to use exim all the time to send messages and stop direct-mailing?

    Your suggestions are highly appreciated.
    Nov 2004
    If you're running cPanel/WHM, you can turn on the WHM feature called "SMTP tweak" which blocks outgoing email on port 25, so these CGI scripts can't run.

    Also, you'd do well to install CSF. It has an "SMTP tweak" port 25 blocking mechanism as well. It'll also warn you if it sees lots of emails going out.

    It really depends whether the lions were in the mood to listen to the sheep....
