th£ lord
Verified User
- Joined
- Jan 6, 2007
- Messages
- 47
Hello Friends,
as I mentioned in the topic title, I noticed that e-mail was forwarded by somehow accessing it from somewhere (I couldn't find the vulnerability).
In short, for example, the e-mail sent to me is sent directly to the forwarded e-mail address and thus the conversations are followed.
The following script has been added to the filters in webmail.
Sample Added Script:
Files with hacked content (created)
/home/zixxls/imap/xxxxx.com/mimari/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/info/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve.log.0
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve.log.0
/home/zixxls/imap/xxxxx.com/transport.fac/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/transport.fac/.dovecot.sieve.log
Note :
- My email passwords are quite strong.
- Only outlook is installed on the computers and the computers are specially protected with a virus program.
- I always try to keep the server updated.
Server Operating Information and Directadmin Versions
Where could there be a security vulnerability to find the solution to this problem?
I would like to thank my dear friends in advance who have ideas about how this hack was created and shared it with me.
Regards,
as I mentioned in the topic title, I noticed that e-mail was forwarded by somehow accessing it from somewhere (I couldn't find the vulnerability).
In short, for example, the e-mail sent to me is sent directly to the forwarded e-mail address and thus the conversations are followed.
The following script has been added to the filters in webmail.
Sample Added Script:
Files with hacked content (created)
/home/zixxls/imap/xxxxx.com/mimari/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/info/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales/.dovecot.sieve.log.0
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve.log
/home/zixxls/imap/xxxxx.com/sales.fac/.dovecot.sieve.log.0
/home/zixxls/imap/xxxxx.com/transport.fac/.dovecot.sieve (The redirect is written into the content of this file.)
/home/zixxls/imap/xxxxx.com/transport.fac/.dovecot.sieve.log
Note :
- My email passwords are quite strong.
- Only outlook is installed on the computers and the computers are specially protected with a virus program.
- I always try to keep the server updated.
Server Operating Information and Directadmin Versions
NAME="CentOS Linux"
VERSION="8"
ID="centos"
ID_LIKE="rhel fedora"
VERSION_ID="8"
PLATFORM_ID="platform:el8"
PRETTY_NAME="CentOS Linux 8"
CENTOS_MANTISBT_PROJECT="CentOS-8"
CENTOS_MANTISBT_PROJECT_VERSION="8"
- Apache 2.4.58 Running
- DirectAdmin 1.661 Running
- Exim 4.97.1 Running
- MariaDB 10.4.33 Running
- Named 9.11.26 Running
- sshd Running
- Nginx 1.25.4 Running
- dovecot 2.3.21 (47349e2482) Running
- pure-ftpd 1.0.51 Running
- Php 7.4.33 Installed
- Php 5.6.40 Installed (php2)
Where could there be a security vulnerability to find the solution to this problem?
I would like to thank my dear friends in advance who have ideas about how this hack was created and shared it with me.
Regards,