WholesaleDialup
Verified User
OK, so I have this user who has one domain on our DA server and 4 or 5 email accounts.
I allow them 5gb of bandwidth per month, then the site gets suspended.
I have 50 or so domains on this server in they are all limited to 5gb per month, none ever get over 1gb, ever.
This domain however has consistant issues with getting suspended due to bandwidth limits being reached. This has been going on for a LONG time.
The last time this happened, I was for sure it was due to a compromised PHP script on their site, I made them take it all down and re-work it since they did in fact have insecure php mailer code that I found. I never did nail down exactly 100% for sure what the issue was except that the bandwidth usage was related to email. I made this determination based on the bandwidth graphs provided by DA but the Exim logs did not result in anything concrete.
After they put their new, better, more secure site back up, things were good for a few weeks then the other days SMACK!, they blew over their bandwidth usage almost entirely in a 5 day period. According to the DA graphs, it's all email bandwidth, not apache or anything else.
Here is a link to the graph which I took a screen shot of and uploaded:
http://secure.muchoweb.com/temp/bandwidth-screenshot.jpg
I have spent two days grepping all the Exim logs, googling on different spam detection methods from the logs etc.. No Joy! I have even changed the logging options to include the path info to see if a script is doing the spamming.
I have grepped for "A=" using regular expressions (Wild Cards) to see if I could see a particular user of the domain doing all the sending.
I just can't find anything that makes sense or that would cause this much email bandwidth to be used, the number of email being sent to/from this domain just don't equal up to the amount of bandwidth DA shows in the graph.
Is it possible the graph is wrong?
What else can I do to find this never ending problem?
Pulling my hair out for months on this, any help would be Oh So appreciated.
Thanks in advance!
I allow them 5gb of bandwidth per month, then the site gets suspended.
I have 50 or so domains on this server in they are all limited to 5gb per month, none ever get over 1gb, ever.
This domain however has consistant issues with getting suspended due to bandwidth limits being reached. This has been going on for a LONG time.
The last time this happened, I was for sure it was due to a compromised PHP script on their site, I made them take it all down and re-work it since they did in fact have insecure php mailer code that I found. I never did nail down exactly 100% for sure what the issue was except that the bandwidth usage was related to email. I made this determination based on the bandwidth graphs provided by DA but the Exim logs did not result in anything concrete.
After they put their new, better, more secure site back up, things were good for a few weeks then the other days SMACK!, they blew over their bandwidth usage almost entirely in a 5 day period. According to the DA graphs, it's all email bandwidth, not apache or anything else.
Here is a link to the graph which I took a screen shot of and uploaded:
http://secure.muchoweb.com/temp/bandwidth-screenshot.jpg
I have spent two days grepping all the Exim logs, googling on different spam detection methods from the logs etc.. No Joy! I have even changed the logging options to include the path info to see if a script is doing the spamming.
I have grepped for "A=" using regular expressions (Wild Cards) to see if I could see a particular user of the domain doing all the sending.
I just can't find anything that makes sense or that would cause this much email bandwidth to be used, the number of email being sent to/from this domain just don't equal up to the amount of bandwidth DA shows in the graph.
Is it possible the graph is wrong?
What else can I do to find this never ending problem?
Pulling my hair out for months on this, any help would be Oh So appreciated.
Thanks in advance!