My server is spamming, need help
Example Mail Log Entry
Oct 13 17:57:46 host2 postfix/smtp[30597]: 633E28604: to=<
A example mail:
Return-Path: <
Received: from [173.230.134.249] by usfamily.net
(USFamily MTA v5/:PGplcnJ5QGplcnJ5bGliYmluLmNvbT48bmVhbGFuZHlAdXNmYW1pbHkubmV0Pg–)
with SMTP id <20121008035248102162800014> for <
Mon, 08 Oct 2012 03:52:48 -0500 (CDT)
(envelope-from
Received: from
by host2.localdomain (Postfix) with ESMTP id BB2DF85B7
for <
Date: Mon, 8 Oct 2012 09:35:27 +0000
To:
From: Jerry Libbin <
Subject: =?UTF-8?Q?Re-imbursment=E2=80=8F?=
Message-ID: <
X-Priority: 3
X-Mailer: PHPMailer 5.1 (phpmailer.sourceforge.net)
MIME-Version: 1.0
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
|
|
Dear Friend
How are you today?
You may not understand why this mail came to you. We have been having series of meeting for the past 5 months which ended 2 days ago with the secretary to the African Union. I am Jerry David Libbin of AFRICAN UNION COMMISSION the Ecowas District Officer.
Please note that this email is to all the people that have been scammed in any part of the world, the AFRICAN UNION COMMISSION have agreed to compensate them with the sum of US$(800,000.00)
This includes every foreign contractors that may have not received their contract sum, and people that have had an unfinished transaction or international
businesses that failed due to Government problems etc.
We found your name in our list and that is why we are contacting you, these have been agreed upon and have been signed. You are advised to contact our paying center as they are our representative in Accra-Ghana, contact them immediately for your International Bank certified Draft of USD$800,000.00 This funds are in a Bank Draft for security purpose, so they will send it to you and you can clear it at any bank of your choice in your country or in any country of the world.
Therefore, you should send to Dr. Peter Kwame your full Name, your direct telephone number and your correct Postal Address where you want them to send the Certified Draft to you.
Contact Dr. Peter Kwame immediately to receive your compensation funds without any further delay, kindly contact him on listed contact information.
Dr. Peter Kwame
Financial Director
No. 72 Liberty Avenue. Ghana
Email:
We will request you to get back to this office as soon as you have received and confirmed your payment in your bank.
Making the world a better place.
Regards.
Jerry David Libbin
(For African Union Commission).
Addis Ababa, ETHIOPIA P. O. Box 3243
|
|
6 Replies
Thanks for that tip, I already had mail.addxheader enabled, but setup mail.log as well.
The sample spam above shows the following:
X-Mailer: PHPMailer 5.1 (phpmailer.sourceforge.net)
I can't tell if this mail came from my server or not, but there are some kind of relay lines in my maillog showing:
Oct 13 17:57:46 host2 postfix/smtp[30597]: 633E28604: to=<
Can anyone tell me what the above is? Is google rerouting mail back through my server?
Oct 15 06:53:43 poseidon postfix/pickup[28501]: 9F1A2806E: uid=0 from= <root>Oct 15 06:53:43 poseidon postfix/cleanup[13156]: 9F1A2806E: message-id=<20121015065343.9F1A2806E@poseidon.rwky.net>
Oct 15 06:53:43 poseidon postfix/qmgr[2538]: 9F1A2806E: from=<root@poseidon.rwky.net>, size=332, nrcpt=1 (queue active)
Oct 15 06:53:44 poseidon postfix/smtp[13158]: 9F1A2806E: to=<admin@rwky.net>, relay=ASPMX.L.GOOGLE.COM[173.194.64.27]:25, delay=0.59, delays=0.03/0.04/0.17/0.34, dsn=2.0.0, status=sent (250 2.0.0 OK 1350284024 d4si15692891obk.79)
Oct 15 06:53:44 poseidon postfix/qmgr[2538]: 9F1A2806E: removed</admin@rwky.net></root@poseidon.rwky.net></root>
The line you posted is the email being sent from your server to a google account, the lines before that will tell you what user is sending it out.
Yes, those mails were all going out to the google mail servers.
I found the problem, it was a "spread the word" form on one of my customers sites. Basically an invitation to spam with To:, From: and Body: fields. There was a captcha on there, but the spammers blew right threw that somehow. I have removed the offending form and all is good again. But now I have some better tools installed on the server (thanks to all the suggestions) to troubleshoot the next problem that comes along.
Chris