Koozali.org: home of the SME Server

I am being used for spamming

Offline mcp_dk

  • *
  • 34
  • +0/-0
    • http://lillenet.dk
I am being used for spamming
« on: October 04, 2007, 05:38:39 PM »
I am currently receiving a few thousands email a day with more or less the same message.
Is my server being used for sending out spam or am i merely being misused as a false sender adress? If someone is using my adress as return adress only but not using my server to send from i am faily OK with that. But if my server is being used for sending spam i want to stop it as  soon as possible. However i am not an expert on reading mailserver logs so i need your help.

Below is a typical message. I have changed my domain name with [mydomain]

Quote
Hi. This is the qmail-send program at [mydomain]
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<coolbiz25532@yahoo.de>:
209.191.88.239 failed after I sent the message.
Remote host said: 554 delivery error: dd Sorry your message to coolbiz25532@yahoo.de cannot be delivered. This account has been disabled or discontinued [#102]. - mta421.mail.mud.yahoo.com

--- Below this line is a copy of the message.

Return-Path: <anonymous@[mydomain]>
Received: (qmail 20585 invoked by uid 102); 4 Oct 2007 12:14:16 -0000
Date: 4 Oct 2007 12:14:16 -0000
Message-ID: <20071004121416.20584.qmail@[mydomain]>
To: coolbiz25532@yahoo.de
Subject: 100% Genuine Loan. Apply Now
From: Harris Gay <harrigay_lender_agency@yahoo.co.uk>
Reply-To: harrigay_lender_agency@yahoo.co.uk
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit


My names are Harris Gay,I am a certified loan lender.I offer secured and unsecured loans to individuals and companies at low interest rate.I offer long and short term loans.My firm has recorded a lot of breakthroughs in the provision of first class financial services to our clients especially in the area of Loan syndication and capital provision for individuals and companies.
 
In general we offer mortgages,home loans,car loans,hotel loans,commercial loans, construction loans, startup- working capital loans,business loans and bad credit loans, e.t.c, at 0.4% interest rate.
We would love to fund projects at hand and offer personal loans as well to you,your firm/partners and clients.
 
We offer the right solution to your financial needs. We stand apart from other lenders because we believe in customer service and we stay with you until you get the results you want.
 
We are a group of energetic and experienced loan professionals with thorough knowledge of financial markets. We have many partners in real estate, banking and technology fields that can assist obtain financing. Almost all of our business are through referrals by satisfied and repeat customers.
 
We have brought ailing industries back to life and we back good business ideas by providing funds for their upstart. We have a network of Investors that < DIV>are willing to provide funds of whatever amount discrectly to individuals and organizations to start business and operations.
 
As the leading provider of Commercial, Business and personal loans to individuals and corporations nationwide, we offer the right kind of financing in less amount of time it will take with traditional lenders.
 
We also recruit Agents to assist our companies in receiving payments. In our bid to be useful to you, please tell us which area that you wish us to be of service to you.
We wire loans to approved Clients via
1-Western Union
2-Money Gram
3-Bank Certified Check
4-Bank to Bank transfer
5-Online Banking.
Respond Asap.
Mr Harris
Harris Gay Lender Agency
United Kingdom
Tel Num:+447045719478
Fax Num:+447005982445
Email:harrigay_lender_agency@yahoo.co.uk
« Last Edit: October 04, 2007, 09:38:37 PM by mcp_dk »
Who is General Failure and why is he reading my harddrive?

Offline mcp_dk

  • *
  • 34
  • +0/-0
    • http://lillenet.dk
Re: am i being used for spamming
« Reply #1 on: October 04, 2007, 08:50:39 PM »
ok i installed qmHandle and made a list of my queue of 9461 items!! The remote queue is FULL of spam waiting to be sent.
I have some different CMS hosted and most of them uses some kind of mail system to send info to registered users. and also some contact forms are available. Is there any way i can track where these mail originates so i can put a stop to it?

**update** i deleted the 9461 mails and i am not closely monitoring the queue to see if anymore spam mail originates. Still very interested in hearing if anyone has an idea on how to track where it comes and/or to prevent it from happening again.
« Last Edit: October 04, 2007, 08:59:46 PM by mcp_dk »
Who is General Failure and why is he reading my harddrive?

Offline chris burnat

  • ****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: I am being used for spamming
« Reply #2 on: October 04, 2007, 11:37:11 PM »
Please report this issue to the Bugtracker.
This is this most sensible course of action.
Thanks.
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline holck

  • *
  • 317
  • +1/-0
Re: I am being used for spamming
« Reply #3 on: October 05, 2007, 09:05:51 AM »
Quote
I have some different CMS hosted and most of them uses some kind of mail system to send info to registered users. and also some contact forms are available. Is there any way i can track where these mail originates so i can put a stop to it?
I guess you could look through /var/log/httpd/access_log, maybe you can spot a high frequency of POST actions on certain web pages?
......

Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: am i being used for spamming
« Reply #4 on: October 05, 2007, 11:30:08 AM »
I have some different CMS hosted

the first thing to do (seriusly) is to shut down every cms
the second is to search on cms' developers site security issues.


my 2c

Stefano


Offline mcp_dk

  • *
  • 34
  • +0/-0
    • http://lillenet.dk
Re: am i being used for spamming
« Reply #5 on: October 07, 2007, 01:34:25 PM »
the first thing to do (seriusly) is to shut down every cms
the second is to search on cms' developers site security issues.


my 2c

Stefano



I have shut down 80% of the CMS sites on my server (renamed the HTML foler in the ibay). And it seems that the spam has stopped for now. I will open them up again in batches of 3or 5 untill i find the bad site that is causing this.
Who is General Failure and why is he reading my harddrive?