Re: Mail Server Compromised?

2010-12-26 Thread Martin Kellermann
Am 25.12.2010 19:55, schrieb ASAI: Greetings, In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the logs I see this: Dec 24 00:05:11 triata amavis[29729]: (29729-06) Passed CLEAN,

Re: Mail Server Compromised?

2010-12-26 Thread /dev/rob0
On Sun, Dec 26, 2010 at 07:28:11PM +0100, Martin Kellermann wrote: Am 25.12.2010 19:55, schrieb ASAI: In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the logs I see this: Dec 24 00:05:11 triata

Re: Mail Server Compromised?

2010-12-26 Thread Benny Pedersen
On lør 25 dec 2010 19:55:10 CET, ASAI wrote What is a problem is that there is no user named apa...@triata... and this user is sending hundreds of emails out to Gmail. So it looks like there's been a compromise. My question is, how do I begin to plug this hole? remove apache unix user

Re: Web sscript compromised? (Was: Mail Server Compromised?)

2010-12-26 Thread mouss
Le 25/12/2010 19:55, ASAI a écrit : Greetings, In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the logs I see this: Dec 24 00:05:11 triata amavis[29729]: (29729-06) Passed CLEAN,

Re: Web script compromised? (Was: Mail Server Compromised?)

2010-12-26 Thread ASAI
Thanks to everyone for the priceless advice.

Mail Server Compromised?

2010-12-25 Thread ASAI
Greetings, In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the logs I see this: Dec 24 00:05:11 triata amavis[29729]: (29729-06) Passed CLEAN, apa...@triata.globalchangemultimedia.net -

Re: Mail Server Compromised?

2010-12-25 Thread Ralf Hildebrandt
* ASAI a...@globalchangemusic.org: Greetings, In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the logs I see this: Dec 24 00:05:11 triata amavis[29729]: (29729-06) Passed CLEAN,

Re: Mail Server Compromised?

2010-12-25 Thread Noel Jones
Your web server has a compromised script. Turn off Apache until you fix the problem. -- Noel Jones ASAI a...@globalchangemusic.org wrote: Greetings, In the logs I have been seeing many attempts made to send messages to gmail which seem like there's spam being sent from my server. In the