1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

How to find what script is sending emails from

Discussion in 'Site & Server Administration' started by John D, Sep 7, 2016.

  1. #1
    Just as the title says

    I am constantly being suspended from a script sending spam and I am getting gbs of return emails in the default email account in cpanel - It is disabled to send out emails.

    Can anyone tell me where I can find what is sending these please?

    I have updated all my scripts so I don't know what is going on

    Thanks for any help :)
     
    John D, Sep 7, 2016 IP
  2. RHS-Chris

    RHS-Chris Well-Known Member

    Messages:
    1,007
    Likes Received:
    35
    Best Answers:
    10
    Trophy Points:
    150
    #2
    Hello there,

    Not sure if you have root access to your server, if you do though, check the exim_mainlog. If you do not have root access, I would ask your provider to check this log and provide direction on where the emails are being sent from.

    Regards,
    Chris
     
    RHS-Chris, Sep 7, 2016 IP
  3. sarahk

    sarahk iTamer Staff

    Messages:
    28,500
    Likes Received:
    4,460
    Best Answers:
    123
    Trophy Points:
    665
    #3
    Are you sure your server is sending them? They could be spoofed.
     
    sarahk, Sep 7, 2016 IP
  4. robyries

    robyries Notable Member

    Messages:
    3,229
    Likes Received:
    51
    Best Answers:
    6
    Trophy Points:
    205
    Digital Goods:
    1
    #4
    I've been on this, my hosting provider suspect me sending spam email from one of my domain that hosted with them. They give me a screenshoot and ask me to stop this otherwise will suspend their service. They ask me to check each forder or reinstall all.

    My suggest you need to make your password more strenght, once these spam script email success break into your cpanel, its hard to clean it otherwise to reinstall.

    Good luck
     
    robyries, Sep 7, 2016 IP
  5. JeffMichaels

    JeffMichaels Well-Known Member

    Messages:
    207
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    125
    #5
    Even if you've disabled the email accounts running on your hosting service, it is still possible to send out email using PHP scripts.

    Are you running a Wordpress site or any other PHP scripts? Some hackers may have used your site to upload their own PHP scripts and use those PHP scripts to send out loads of emails. Look around in the upload directories of your PHP scripts and see if you can find anything out of place.

    We manage a large number of dedicated servers and virtual private servers -- we see this sort of thing all the time.
     
    JeffMichaels, Sep 14, 2016 IP
  6. jsmcm

    jsmcm Active Member

    Messages:
    58
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    51
    #6
    exim usually includes a header like X-PHP-Originating-Script: Check if the bounce message contains the headers of the original message and see if that's in there.

    If you have access to ssh on the server then you could also try checking the time the original message was sent (by looking at that header in the bounce message) and then checking your http access logs at that time...

    Is this a wordpress site? I've seen outdated plugins get hacked with a script uploader. You could try grep'ing for eval as these uploaded scripts often use eval'ed code..
     
    jsmcm, Sep 19, 2016 IP
  7. NekufBoum

    NekufBoum Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #7
    If you are using shared server you should ask your hosting provider to check this information for you. Every good hosting provider will provide you with more information on this.

    If you are on Cloud/VPS/DC you may post here or PM me with the logs from the exim_mainlog. You can check the exim's queue with the following command:
    exim -bp

    After that you can use the following command to view the headers:
    exim -Mvh IDofTheMail
     
    NekufBoum, Sep 20, 2016 IP
  8. UnderHost_MSA

    UnderHost_MSA Notable Member

    Messages:
    1,194
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    200
    #8
    It seem you are running on a shared servers, your host is supposed to help you to find the rogue script.

    If you are running WordPress, just PM me i'll help you to fix your issue for free and scan your installation.
     
    UnderHost_MSA, Sep 23, 2016 IP
  9. MechanicWeb-shoss

    MechanicWeb-shoss Active Member

    Messages:
    63
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    60
    #9
    You should always sign up with a provider that has a spam filter for outbound emails, such as SpamExperts. Life is way easier with that.
     
    MechanicWeb-shoss, Sep 25, 2016 IP
  10. MailerMoney

    MailerMoney Peon

    Messages:
    1
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #10
    You need to make sure your host is mailer friendly. Otherwise you will be banned over and over...
     
    MailerMoney, Oct 21, 2016 IP