jim.thornton
Verified User
- Joined
- Jan 1, 2008
- Messages
- 334
I've been running DA for a while. I have only about a dozen users setup on the server and as many websites. It is pretty light load and there isn't a lot of email that goes through the server. However, today I got an email from the system that said the following user had sent out 100 emails today. I've got the limit at 100.
The user in question is running an older version of Joomla, which someone else was running before it this same problem happened with them. I eventually deleted that Joomla installation and updated it to the newest version and it was still doing it. Looking at the logs, I think that it is actually someone logging in and sending emails. Initially, I thought they might have a virus that was jacking their Outlook or something. Their password for exim was originally very simple. I changed it to a randomly generated password that was 8 characters long, uppercase, lowercase and digits. It was still happening.
The other user is gone, but now I'm getting it on this new user. I'm wondering if someone can please walk me through how to investigate this. The path that the email sent from DA is saying it is being sent from: /
Here is a link to the log file with some lines for the user it is happening for: http:// pastebin [dot] com/Dk1jBDEJ
I think it is an SMTP login again, but I would appreciate if someone can walk me through identifying this please
The user in question is running an older version of Joomla, which someone else was running before it this same problem happened with them. I eventually deleted that Joomla installation and updated it to the newest version and it was still doing it. Looking at the logs, I think that it is actually someone logging in and sending emails. Initially, I thought they might have a virus that was jacking their Outlook or something. Their password for exim was originally very simple. I changed it to a randomly generated password that was 8 characters long, uppercase, lowercase and digits. It was still happening.
The other user is gone, but now I'm getting it on this new user. I'm wondering if someone can please walk me through how to investigate this. The path that the email sent from DA is saying it is being sent from: /
Here is a link to the log file with some lines for the user it is happening for: http:// pastebin [dot] com/Dk1jBDEJ
I think it is an SMTP login again, but I would appreciate if someone can walk me through identifying this please