Hi
Lately I one of our servers has been mass spamming out emails and almost killed the box at times, once the load Avg was 1000
I am having trouble tracking down the source of the spam, when I look at the message queue in DA the sender shows as <>
a ps aux shows the following exim process's, nothing suspect looks to be running other than a load of exim process's
one thing that I am not sure about is "/usr/sbin/exim -MCS -MCP -MC remote_smtp"
I did a google on it and found some Cached sites where the exim remote_stmp shows up and on the pages its a phpshell stuff.
any one know what the remote_smtp stuff is?
I think the main thing anyway is make it show who the sender was and have it as <>
how can I set the server up to do this?
my exim config is a standard DA one with greylisting in
Thanks
David
Lately I one of our servers has been mass spamming out emails and almost killed the box at times, once the load Avg was 1000

I am having trouble tracking down the source of the spam, when I look at the message queue in DA the sender shows as <>
a ps aux shows the following exim process's, nothing suspect looks to be running other than a load of exim process's
Code:
root 5701 0.0 0.3 10780 3536 ? S 16:32 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 4 1Lh4Wz-0008J4-F3
mail 6999 0.0 0.1 10884 1680 ? S 16:35 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 4 1Lh4Wz-0008J4-F3
root 11262 0.0 0.3 10776 3516 ? S 16:41 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp MX.MAILANYONE.NET 208.70.128.223 97 1Lh2qF-0000sQ-K7
mail 11426 0.0 0.1 10880 1680 ? S 16:41 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp MX.MAILANYONE.NET 208.70.128.223 97 1Lh2qF-0000sQ-K7
root 13400 0.0 0.3 10780 3564 ? S 16:43 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp email-com.mr.outblaze.com 64.71.166.195 7 1Lh2uV-0001yF-S5
root 15027 0.0 0.1 8504 2016 ? S 11:26 0:00 /usr/sbin/exim -q
root 15596 0.0 0.2 8500 2080 ? S 11:41 0:00 /usr/sbin/exim -q
mail 15654 0.0 0.1 10780 1656 ? S 16:46 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp email-com.mr.outblaze.com 64.71.166.195 7 1Lh2uV-0001yF-S5
root 15867 0.0 0.3 10784 3540 ? S 16:46 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 7 1Lh4L4-0004Uc-W1
root 16123 0.0 0.3 10952 3748 ? S 16:46 0:00 /usr/sbin/exim -Mc 1Lh54T-00046o-2s
mail 16151 0.0 0.1 10952 1860 ? S 16:46 0:00 /usr/sbin/exim -Mc 1Lh54T-00046o-2s
root 16352 0.0 0.3 10780 3524 ? S 16:47 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp mx4.uk.tiscali.com 212.74.100.150 2 1Lh4Vh-0007rb-AR
root 16358 0.0 0.2 8640 2148 ? S 11:56 0:00 /usr/sbin/exim -q
mail 16615 0.0 0.1 10780 1676 ? S 16:47 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp mx4.uk.tiscali.com 212.74.100.150 2 1Lh4Vh-0007rb-AR
root 17071 0.0 0.3 10820 3716 ? S 16:47 0:00 /usr/sbin/exim -Mc 1Lh55b-0004Oc-44
mail 17353 0.0 0.1 10820 1808 ? S 16:48 0:00 /usr/sbin/exim -Mc 1Lh55b-0004Oc-44
root 17427 0.0 0.3 10824 3728 ? S 16:48 0:00 /usr/sbin/exim -Mc 1Lh55y-0004T4-C9
root 18992 0.0 0.3 10812 3712 ? S 16:50 0:00 /usr/sbin/exim -Mc 1Lh58B-0004sq-7v
root 19008 0.0 0.3 10816 3632 ? S 16:50 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 2 1Lh57X-0004li-Tn
mail 19017 0.0 0.1 10816 1756 ? S 16:50 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 2 1Lh57X-0004li-Tn
mail 19031 0.0 0.2 10924 2796 ? S 16:50 0:00 /usr/sbin/exim -Mc 1Lh58B-0004sq-7v
root 19128 0.0 0.3 10960 3744 ? S 16:50 0:00 /usr/sbin/exim -Mc 1Lh58T-0004uZ-0B
mail 19194 0.0 0.1 10944 1796 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh58T-0004uZ-0B
root 19380 0.1 0.3 10928 3592 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh58p-0004yp-KG
root 19425 0.0 0.3 10956 3192 ? S 16:51 0:00 /usr/sbin/exim -q
mail 19429 0.0 0.1 10956 1756 ? S 16:51 0:00 /usr/sbin/exim -q
root 19508 0.0 0.3 10812 3736 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh590-00050T-B8
root 19512 0.0 0.3 10816 3708 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh590-00050j-Sy
mail 19527 0.0 0.1 10816 1728 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh590-00050j-Sy
root 19545 0.0 0.3 10960 3760 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh594-000525-Cw
root 19679 0.0 0.3 10960 3732 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59D-00054Y-OF
mail 19764 0.0 0.1 10952 1844 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59D-00054Y-OF
root 19800 0.0 0.3 10812 3516 ? S 16:51 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp mx2.dircon.net 80.168.44.13 2 1Lh567-0004Vr-Bb
mail 19824 0.0 0.1 10812 1532 ? S 16:51 0:00 /usr/sbin/exim -MCS -MCP -MC remote_smtp mx2.dircon.net 80.168.44.13 2 1Lh567-0004Vr-Bb
mail 19828 0.0 0.1 10960 1768 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh594-000525-Cw
mail 19873 0.0 0.1 10928 1688 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh58p-0004yp-KG
root 19964 0.0 0.2 10820 3008 ? S 16:51 0:00 /usr/sbin/exim -q
mail 19970 0.0 0.1 10820 1608 ? S 16:51 0:00 /usr/sbin/exim -q
root 20014 0.1 0.3 10812 3724 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59U-00057r-Dp
root 20036 0.0 0.1 8372 1960 ? S 11:11 0:00 /usr/sbin/exim -q
root 20039 0.0 0.3 10820 3700 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59V-000583-7l
root 20057 0.1 0.3 10816 3728 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh5BN-00058q-PQ
mail 20059 0.0 0.1 10820 1712 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59V-000583-7l
mail 20079 0.0 0.1 10820 1744 ? S 16:51 0:00 /usr/sbin/exim -Mc 1Lh59V-000583-7l
mail 20126 0.0 0.1 10936 1776 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh55y-0004T4-C9
mail 20154 0.0 0.1 10928 1780 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5BN-00058q-PQ
mail 20199 0.0 0.1 10944 1744 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh590-00050T-B8
root 20245 0.1 0.3 10948 3768 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5Ba-0005Dg-UI
mail 20270 0.0 0.1 10948 1780 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5Ba-0005Dg-UI
root 20422 0.0 0.3 11040 3212 ? S 16:52 0:00 /usr/sbin/exim -q
mail 20425 0.0 0.1 11040 1864 ? S 16:52 0:00 /usr/sbin/exim -q
mail 20439 0.0 0.1 10948 1784 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5Ba-0005Dg-UI
mail 20443 0.0 0.1 10812 1712 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh59U-00057r-Dp
root 20471 0.1 0.3 10952 3752 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5Bi-0005FS-Co
mail 20500 0.0 0.1 10944 1760 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh5Bi-0005FS-Co
mail 20638 0.0 0.1 10928 1724 ? S 16:52 0:00 /usr/sbin/exim -Mc 1Lh590-00050j-Sy
mail 20659 0.0 0.1 10896 1712 ? S 16:52 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 7 1Lh4L4-0004Uc-W1
root 20757 0.1 0.3 10948 3756 ? S 16:53 0:00 /usr/sbin/exim -Mc 1Lh5CT-0005Gx-Ps
mail 20805 0.0 0.1 10948 1764 ? S 16:53 0:00 /usr/sbin/exim -Mc 1Lh5CT-0005Gx-Ps
mail 20840 0.0 0.1 10948 1928 ? S 16:53 0:00 /usr/sbin/exim -Mc 1Lh5CT-0005Gx-Ps
root 20896 0.1 0.3 11148 3252 ? S 16:53 0:00 /usr/sbin/exim -q
mail 20911 0.0 0.1 11140 1820 ? S 16:53 0:00 /usr/sbin/exim -q
root 20972 0.1 0.3 10940 3140 ? S 16:53 0:00 /usr/sbin/exim -q
mail 20979 0.0 0.1 11048 1752 ? S 16:53 0:00 /usr/sbin/exim -q
root 21009 0.2 0.3 10848 3644 ? S 16:53 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 3 1Lh5CT-0005H3-QB
root 21018 0.3 0.3 10816 3644 ? S 16:53 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 4 1Lh5CI-0005GN-UW
root 21022 0.2 0.3 10776 3520 ? S 16:53 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 5 1Lh5Bv-0005Fm-Ba
mail 21023 0.0 0.1 10816 1700 ? S 16:53 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 4 1Lh5CI-0005GN-UW
mail 21027 0.0 0.1 10776 1692 ? S 16:53 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 5 1Lh5Bv-0005Fm-Ba
mail 21044 0.0 0.1 10848 1668 ? S 16:54 0:00 /usr/sbin/exim -MCS -MC remote_smtp mx-ironport.core.plus.net 84.92.2.97 3 1Lh5CT-0005H3-QB
root 24792 0.0 0.2 8648 2176 ? S 12:11 0:01 /usr/sbin/exim -q
mail 27189 0.0 0.1 8372 1052 ? Ss Mar08 0:45 /usr/sbin/exim -bd -q15m -oP /var/run/exim.pid
one thing that I am not sure about is "/usr/sbin/exim -MCS -MCP -MC remote_smtp"
I did a google on it and found some Cached sites where the exim remote_stmp shows up and on the pages its a phpshell stuff.
any one know what the remote_smtp stuff is?
I think the main thing anyway is make it show who the sender was and have it as <>
how can I set the server up to do this?
my exim config is a standard DA one with greylisting in
Thanks
David