linux 邮件 发送 rejected mail,linux – 如何找到我服务器上的哪个脚本发送垃圾邮件?...

参见英文答案 >

How do I deal with a compromised server?13个

>

Is there a static,server-side vulnerability/virus/malware/BadThings™ scanner?4个

我的服务器正在发送垃圾邮件,我无法找出发送它们的脚本.

电子邮件全部来自nobody @ myhost,因此禁用了cpanel,不允许任何人发送电子邮件

现在至少他们不会外出,我一直接受他们.这是我收到的邮件:

A message that you sent could not be delivered to one or more of its

recipients. This is a permanent error. The following address(es) Failed:

eckert@clearfieldjeffersonredcross.org

Mail sent by user nobody being discarded due to sender restrictions in WHM->Tweak Settings

------ This is a copy of the message,including all the headers. ------

Return-path:

Received: from nobody by cpanel.myserver.com with local (Exim 4.80)

(envelope-from )

id 1UBBap-0007EM-9r

for eckert@clearfieldjeffersonredcross.org; Fri,01 Mar 2013 08:34:47 +1030

To: eckert@clearfieldjeffersonredcross.org

Subject: Order Detail

From: "Manager Ethan Finch"

X-Mailer: Fscfz(ver.2.75)

Reply-To: "Manager Ethan Finch"

Mime-Version: 1.0

Content-Type: multipart/alternative;boundary="----------1362089087512FD47F4767C"

Message-Id:

Date: Fri,01 Mar 2013 08:34:47 +1030

------------1362089087512FD47F4767C

Content-Type: text/plain; charset="ISO-8859-1"; format=flowed

Content-Transfer-Encoding: 7bit

这是我的exim日志日志:

2013-03-01 14:36:00 no IP address found for host gw1.corpgw.com (during SMTP connection from [203.197.151.138]:54411)

2013-03-01 14:36:59 H=() [203.197.151.138]:54411 rejected MAIL gpgjouczsr@gmail.com: HELO required before MAIL

2013-03-01 14:37:28 H=(helo) [203.197.151.138]:54411 rejected MAIL admin@gmail.com: Access denied - Invalid HELO name (See RFC2821 4.1.1.1)

2013-03-01 14:37:28 SMTP connection from (helo) [203.197.151.138]:54411 closed by DROP in ACL

2013-03-01 14:37:29 cwd=/var/spool/exim 2 args: /usr/sbin/exim -q

2013-03-01 14:37:29 Start queue run: pid=12155

2013-03-01 14:37:29 1UBBap-0007EM-9r ** eckert@clearfieldjeffersonredcross.org R=enforce_mail_permissions: Mail sent by user nobody being discarded due to sender restrictions in WHM->Tweak Settings

2013-03-01 14:37:29 cwd=/var/spool/exim 7 args: /usr/sbin/exim -t -oem -oi -f <> -E1UBBap-0007EM-9r

2013-03-01 14:37:30 1UBHFp-0003A7-W3 <= <> R=1UBBap-0007EM-9r U=mailnull P=local S=7826 T="Mail delivery Failed: returning message to sender" for nobody@cpanel.server.com

2013-03-01 14:37:30 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1UBHFp-0003A7-W3

2013-03-01 14:37:30 1UBBap-0007EM-9r Completed

2013-03-01 14:37:32 1UBHFp-0003A7-W3 aspmx.l.google.com [2607:f8b0:400e:c00::1b] Network is unreachable

2013-03-01 14:37:38 1UBHFp-0003A7-W3 => johnmyk@server.com R=lookuphost T=remote_smtp H=aspmx.l.google.com [74.125.25.26] X=TLSv1:RC4-SHA:128

2013-03-01 14:37:39 1UBHFp-0003A7-W3 Completed

2013-03-01 14:37:39 End queue run: pid=12155

2013-03-01 14:38:20 SMTP connection from [127.0.0.1]:36667 (TCP/IP connection count = 1)

2013-03-01 14:38:21 SMTP connection from localhost [127.0.0.1]:36667 closed by QUIT

2013-03-01 14:42:45 cwd=/ 2 args: /usr/sbin/sendmail -t

2013-03-01 14:42:45 1UBHKv-0003BH-LD <= root@cpanel.server.com U=root P=local S=1156 T="[cpanel.server.com] Root Login from IP 122.181.3.130" for johnmyk@server.com

2013-03-01 14:42:45 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1UBHKv-0003BH-LD

2013-03-01 14:42:47 1UBHKv-0003BH-LD aspmx.l.google.com [2607:f8b0:400e:c00::1a] Network is unreachable

2013-03-01 14:42:51 1UBHKv-0003BH-LD => johnmyk@server.com R=lookuphost T=remote_smtp H=aspmx.l.google.com [74.125.25.27] X=TLSv1:RC4-SHA:128

2013-03-01 14:42:51 1UBHKv-0003BH-LD Completed

2013-03-01 14:43:22 SMTP connection from [127.0.0.1]:37499 (TCP/IP connection count = 1)

2013-03-01 14:43:23 SMTP connection from localhost [127.0.0.1]:37499 closed by QUIT

有没有办法找到哪个脚本或哪个用户正在生成这些脚本?

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值