To All,
This is more of a general question in regards to attack against one
of our servers.
We have found that one server is continually being hit by Perl Bots.
Initially this machine was compromised, so we rebuilt from scratch and
altered any access via SSH, made sure the firewall was appropriate, etc.,
but we are still seeing instances of attack. To combat these attacks we
have an Anti-Virus program running and it returns errors like to following.
A virus classified as 'Mal/PerlBot-A' was detected in the file '/tmp/dude'
when closing it at Sun Apr 10 03:08:29 2011 EST +2100 (2011-04-09 17:08:29
UTC).
What I want to know, is where these Bots come from. Are they launched from
an Email when it is accessed via Webmail? Or can they get to the server
through an IMAP account.
This machine is not running a web proxy, and the only we requirement is
Webmail (and Qmail Toaster management), so where are these coming from.
Any information would be appreciated.
Cheers
Mike Canty
---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group
(www.vickersconsulting.com)
Vickers Consulting Group offers Qmailtoaster support and installations.
If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]