HI
If you use smtp-auth look at the /var/log/maillog
Look for lines as in
Mar 24 11:46:27 www vpopmail[92340]: vchkpw-smtp:
or
Mar 24 11:46:27 www vpopmail[92340]: vchkpw-smtps:
and the ~qmail-send/current log file
if a user is logging in for sending more than usual, change the password
and if you are sure it is the right one, delete
regards
torsten
From: Shaumarov Boburhon [mailto:mighty_bob-***@public.gmane.org]
Sent: 24 March 2011 11:38
To: qmr-iGp6mRlwfsr/sFSC9fAAV0B+***@public.gmane.org
Subject: [qmr] How to find out who is spamming
Hi Guys! I need your help...
I can't find who is sending spam from my qmail server.
If you will see with ps ax, u can see like this.
3355 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojpasricha-/***@public.gmane.org
3356 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojpandeydo11s-/***@public.gmane.org
3360 ? S 0:00 qmail-popup mail.intal.uz
/var/popboxes/bin/vchkpw qmail-pop3d Maildir
3366 ? S 0:00 qmail-pop3d Maildir
3370 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojkumardhankhar-83-/***@public.gmane.org
3371 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manojkumar4891-/***@public.gmane.org
3373 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojkumar10_yadav-/***@public.gmane.org
3374 ? S 0:00 qmail-remote phmhealth.com
david2000-QOiod4cnrWAN+***@public.gmane.org manojkum-HNfW5e86Fy21Z/+***@public.gmane.org
3376 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojkmundhra-/***@public.gmane.org
3378 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojjk2003-/***@public.gmane.org
3380 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojjain14-/***@public.gmane.org
3381 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojdwivedi_obra-/***@public.gmane.org
3383 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojdhuran-/***@public.gmane.org
3385 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojcoco_07-/***@public.gmane.org
3388 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manojamrit-/***@public.gmane.org
3390 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_yk-/***@public.gmane.org
3400 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_ya123-/***@public.gmane.org
3402 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_srg-/***@public.gmane.org
3403 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_shuklajss-/***@public.gmane.org
3404 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_sharmarjit-/***@public.gmane.org
3412 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_sharmamks-/***@public.gmane.org
3413 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_sharma_786-/***@public.gmane.org
3414 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_sh76-/***@public.gmane.org
3423 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_rkgit007-/***@public.gmane.org
3442 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_paswan22-/***@public.gmane.org
3443 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_pandey511-/***@public.gmane.org
3444 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_nerist-/***@public.gmane.org
3445 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_mehta20007-/***@public.gmane.org
3448 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_march02-/***@public.gmane.org
3450 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_manojmbd-/***@public.gmane.org
3451 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kv_engg-/***@public.gmane.org
3452 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kumar_malik-/***@public.gmane.org
3453 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kumar_kushwaha-/***@public.gmane.org
3454 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kumar_choudhary25-/***@public.gmane.org
3455 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kulwant-/***@public.gmane.org
3456 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_kmohapatra-/***@public.gmane.org
3457 ? S 0:00 qmail-remote yahoo.co.in david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_iimc2000-/***@public.gmane.org
3458 ? S 0:00 qmail-remote yahoo.com david2000-QOiod4cnrWAN+***@public.gmane.org
manoj_happy2005-/***@public.gmane.org
while looking tail -f /var/service/qmail-send/log/main/current, see just
this
@400000004d8b2c13158bf014 starting delivery 14104: msg 854481 to remote
mirbin24dec-/***@public.gmane.org
@400000004d8b2c13158c039c status: local 0/10 remote 255/255
@400000004d8b2c131d94614c delivery 13856: deferral:
Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
@400000004d8b2c131d9478bc status: local 0/10 remote 254/255
@400000004d8b2c131d94885c starting delivery 14105: msg 854481 to remote
minaxi_ism-/***@public.gmane.org
@400000004d8b2c131d949be4 status: local 0/10 remote 255/255
@400000004d8b2c132659295c delivery 13954: deferral:
Connected_to_180.222.96.138_but_connection_died._(#4.4.2)/
@400000004d8b2c13265940cc status: local 0/10 remote 254/255
@400000004d8b2c1326595454 starting delivery 14106: msg 854481 to remote
minal_likerain-/***@public.gmane.org
@400000004d8b2c13265963f4 status: local 0/10 remote 255/255
@400000004d8b2c140cff2024 delivery 13947: deferral:
Connected_to_180.222.96.138_but_connection_died._(#4.4.2)/
@400000004d8b2c140cff3b7c status: local 0/10 remote 254/255
@400000004d8b2c140cff4b1c starting delivery 14107: msg 854481 to remote
mig_26aug-/***@public.gmane.org
@400000004d8b2c140cff5ea4 status: local 0/10 remote 255/255
@400000004d8b2c1500918bc4 delivery 14022: deferral:
Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
@400000004d8b2c150091ab04 status: local 0/10 remote 254/255
@400000004d8b2c150091be8c starting delivery 14108: msg 854481 to remote
micheymahapatro-/***@public.gmane.org
@400000004d8b2c150091ce2c status: local 0/10 remote 255/255
@400000004d8b2c1500be4114 delivery 14000: success:
84.54.69.222_accepted_message./Remote_host_said:_250_2.0.0_p2OBZ9O1018947_Me
ssage_accepted_for_delivery/
@400000004d8b2c1500be5884 status: local 0/10 remote 254/255
@400000004d8b2c1500be6c0c end msg 854058
@400000004d8b2c1500c2e494 starting delivery 14109: msg 854481 to remote
mia11011972-/***@public.gmane.org
@400000004d8b2c1500c2f81c status: local 0/10 remote 255/255
@400000004d8b2c15051b2eac delivery 12735: deferral:
Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
@400000004d8b2c15051b461c status: local 0/10 remote 254/255
@400000004d8b2c15051b55bc starting delivery 14110: msg 854481 to remote
mi_siddiqui-/***@public.gmane.org
@400000004d8b2c15051b6944 status: local 0/10 remote 255/255
@400000004d8b2c1512e7f934 delivery 14031: deferral:
Connected_to_180.222.96.138_but_connection_died._(#4.4.2)/
@400000004d8b2c1512e810a4 status: local 0/10 remote 254/255
@400000004d8b2c1512e8242c starting delivery 14111: msg 854481 to remote
mgupta314-/***@public.gmane.org
@400000004d8b2c1512e833cc status: local 0/10 remote 255/255
@400000004d8b2c1530fab434 delivery 13891: deferral:
Connected_to_180.222.96.138_but_connection_died._(#4.4.2)/
@400000004d8b2c1530facf8c status: local 0/10 remote 254/255
@400000004d8b2c1530fae314 starting delivery 14112: msg 854481 to remote
mgulati_19nov-/***@public.gmane.org
how to find out by which user it's sending from my server. I think one of my
users infacted, and from his login it's all sending.
Relay clinet configured proparly.
Thanks in advace
--
With best regards,
Shaumarov Boburhon
ISP <<UzNet>>
Contacts :
icq# : 192-467-164
mailto: <mailto:mighty_bob-***@public.gmane.org>
mighty_bob-***@public.gmane.org