Someone got User login details?

jet1972

Verified User
Joined
Jul 8, 2011
Messages
204
Examined exim/mainlog and found this (real names are replaced):

2015-10-05 11:36:11 cwd=/home/dausername/domains/dausername.fi/public_html 3 args: /usr/sbin/sendmail -t -i
2015-10-05 11:36:11 1Zj1Fj-0008PB-LX <= [email protected] U=dausername P=local S=12482 [email protected] T="User Login Detail" from <[email protected]> for [email protected]
2015-10-05 11:36:11 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1Zj1Fj-0008PB-LX
2015-10-05 11:36:13 1Zj1Fj-0008PB-LX => [email protected] F=<[email protected]> R=lookuphost T=remote_smtp S=12689 H=gmail-smtp-in.l.google.com [74.125.136.26] X=TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128 CV=yes C="250 2.0.0 OK 1444034173 s2si15078447wik.32 - gsmtp"
2015-10-05 11:36:13 1Zj1Fj-0008PB-LX Completed




"dausername" is a real user on our server but the gmail address does not belong to the user..

Has DA sent outsider login details?

Kind regards,
Jan
 
Last edited:
That's probably just the website running on that dausername.fi sending out registration confirmation mails/pass reset etc. In either case it should be the website itself sending out those mails, DA never uses that path or that subject in an email.
 
That's probably just the website running on that dausername.fi sending out registration confirmation mails/pass reset etc. In either case it should be the website itself sending out those mails, DA never uses that path or that subject in an email.

OK, thanks.

Yes, there is WordPress on the site so it could be pass reset etc going on.

Kind regards,
Jan
 
Back
Top