SeLLeRoNe
Super Moderator
Hi,
AOL is contacting me cause my server is sending many spam email to their users and ive found one of those here reported:
	
	
	
		
User sending is apache so prolly some users or maybe just one has been hacked..
The question is, how should i check wich user is and how should i investigate about this?
Thanks for help from everyone, much appreciated as always.
Regards
				
			AOL is contacting me cause my server is sending many spam email to their users and ive found one of those here reported:
		Code:
	
	1ONk80-00055I-Pn-H
apache 1004 1004
<[email protected]>
1276423760 0
-ident apache
-received_protocol local
-body_linecount 48
-max_received_linelength 131
-auth_id apache
-auth_sender [email protected]
-allow_unqualified_recipient
-allow_unqualified_sender
-deliver_firsttime
-local
XX
1
[email protected]
198P Received: from apache by Psycho.CrazyNetwork.it with local (Exim 4.72)
        (envelope-from <[email protected]>)
        id 1ONk80-00055I-Pn
        for [email protected]; Sun, 13 Jun 2010 12:09:20 +0200
038  Date: Sun, 13 Jun 2010 12:09:20 +0200
055I Message-Id: <[email protected]>
023T To: [email protected]
066  Subject: *IMPORTANT* Halifax Bank -Your Online Access Suspended !
054F From: Halifax Online Banking <[email protected]>
011R Reply-To:
018  MIME-Version: 1.0
024  Content-Type: text/html
032  Content-Transfer-Encoding: 8bit
	User sending is apache so prolly some users or maybe just one has been hacked..
The question is, how should i check wich user is and how should i investigate about this?
Thanks for help from everyone, much appreciated as always.
Regards