We recently migrated several sites to ispconfig, and these days I noticed a huge spam activity generating from our server.
in the meantime while I look for the site used for this activity, is there some action we can take to mitigate the abuse of web scripts used for mailings?
we're not using ispconfig as mailserver, just for sites mailing
Posts: 339
Thanks: 35
Thanked 75 Times in 61 Posts
Hello,
If you are the administrator you can do everything.
- Locate the script and check how and who is abusing it.
- Disable features for this site if your customer doesn't need them. (cgi, python, perl, ssi, ruby)
- Check for malware, php shell ... with clamav and rkhunter.
- Force smtp auth
- Disable mail() function
Please note that I don't know nothing about your customer or your server.
Cheers!
The Following User Says Thank You to pititis For This Useful Post:
thanks pititis,
my question was generic, on purpose. As I added I managed to stop this specific site and infection, what I wanted to know is if, for example, could be possible to execute a "clamav" on every uploaded file so that if it's a shell script or maliciuos file could be catched, or at least a warning triggered.
Recent comments
12 hours 48 min ago
15 hours 44 min ago
16 hours 58 min ago
18 hours 21 min ago
19 hours 59 min ago
21 hours 28 min ago
22 hours 41 min ago
1 day 14 hours ago
1 day 15 hours ago
1 day 19 hours ago