Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Mail Server
  • Search

Exim Seems to be Hacked

Questions regarding the Mail Server
Dovecot, Exim, RoundCube
Post Reply
  • Print view
Advanced search
9 posts • Page 1 of 1
rmjserver
Posts: 15
Joined: Mon Feb 26, 2018 10:16 am

Os: Ubuntu 13x
Web: apache + nginx
Exim Seems to be Hacked
  • Quote

Post by rmjserver » Tue Jun 26, 2018 4:54 pm

Hi,
My Exim/Server seems to be hacked. My exim usage is showing up high in vesta graphs and in Vesta panel logs I saw this:
I have replaced my domain with domain.com
Exim queue status

42m 3.2K 1fXqWc-00034q-2h <> *** frozen ***
[email protected]

12m 3.2K 1fXqzd-0005In-AM <> *** frozen ***
[email protected]
Please, can anybody please tell me what above log means.
Top

alexcy
Posts: 256
Joined: Sun Jun 01, 2014 11:24 pm
Contact:
Contact alexcy
Website

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: Exim Seems to be Hacked
  • Quote

Post by alexcy » Tue Jun 26, 2018 8:52 pm

Most probably an infected website sends spam.

You can check files in /var/spool/exim4 and find the PHP script(s) generating the emails.
Top

grayfolk
Support team
Posts: 1111
Joined: Tue Jul 30, 2013 10:18 pm
Contact:
Contact grayfolk
Website Facebook Skype Twitter

Os: CentOS 6x
Web: nginx + php-fpm
Re: Exim Seems to be Hacked
  • Quote

Post by grayfolk » Wed Jun 27, 2018 7:47 am

I'm recommend to use https://github.com/scr34m/php-malware-scanner for find infected scripts.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Exim Seems to be Hacked
  • Quote

Post by ScIT » Wed Jun 27, 2018 7:53 am

also a good malwarescanner: https://www.rfxn.com/projects/linux-malware-detect/
Top

ahouse
Posts: 171
Joined: Fri Sep 01, 2017 1:05 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: Exim Seems to be Hacked
  • Quote

Post by ahouse » Wed Jun 27, 2018 11:51 am

You can use AI-Bolit Very intelligent software. It's free for non-commercial use

https://revisium.com/aibo/
Top

Messiah
Posts: 74
Joined: Sun Apr 06, 2014 8:47 pm

Re: Exim Seems to be Hacked
  • Quote

Post by Messiah » Wed Jun 27, 2018 5:07 pm

Maybe hacked maybe not.
Look into the messages contents, probably inside /var/spool/exim/...
If there is a spam - use previous advices, at first disable all Joomla websites, it's the most vulnerable popular CMS.

Also there could be some system messages like
sudo: unable to resolve host %some_hostname%
or other error notifications rooted to system administrator email.
Top

rmjserver
Posts: 15
Joined: Mon Feb 26, 2018 10:16 am

Os: Ubuntu 13x
Web: apache + nginx
Re: Exim Seems to be Hacked
  • Quote

Post by rmjserver » Sat Jul 21, 2018 12:50 pm

I have found that these are being sent by cron job for php session clean. Can anybody help me to stop this?
I have already set MAILTO="' in crontab. But still, this doesn't stop.
Mail Content:

Code: Select all

PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_intl.dll' - /usr/lib/php/20151012/php_intl.dll: cannot open shared object file: No such file or directory in Unknown on line 0
PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_imap.dll' - /usr/lib/php/20151012/php_imap.dll: cannot open shared object file: No such file or directory in Unknown on line 0
PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_intl.dll' - /usr/lib/php/20151012/php_intl.dll: cannot open shared object file: No such file or directory in Unknown on line 0
PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_imap.dll' - /usr/lib/php/20151012/php_imap.dll: cannot open shared object file: No such file or directory in Unknown on line 0
PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_intl.dll' - /usr/lib/php/20151012/php_intl.dll: cannot open shared object file: No such file or directory in Unknown on line 0
PHP Warning:  PHP Startup: Unable to load dynamic library '/usr/lib/php/20151012/php_imap.dll' - /usr/lib/php/20151012/php_imap.dll: cannot open shared object file: No such file or directory in Unknown on line 0
Top

baxterdmutt
Posts: 9
Joined: Thu Jul 19, 2018 3:53 pm

Os: Debian 7x
Web: apache + nginx
Re: Exim Seems to be Hacked
  • Quote

Post by baxterdmutt » Fri Aug 17, 2018 2:23 am

On my server this was happening because VESTACP seems to send system emails via [email protected]. and since there was no root mail account, the messages get frozen and build up for 7days before they clear. All I did was create a root mail account and redirected all it’s mail to the admin user. I wasn’t sure how else to handle it and I wanted the system messages that VESTACP sends out.
Top

baxterdmutt
Posts: 9
Joined: Thu Jul 19, 2018 3:53 pm

Os: Debian 7x
Web: apache + nginx
Re: Exim Seems to be Hacked
  • Quote

Post by baxterdmutt » Fri Aug 17, 2018 4:52 am

Sorry, I should have added that another way around your problem is to make sure you have a root entry in /etc/aliases.
root : [email protected]
That is supposed to work but it didn’t for me. That’s why I created a root mail user account. I don’t like having a root mail user account so if anyone knows why the /etc/aliases didn’t work for me please let me know. Hope this helps.
Top


Post Reply
  • Print view

9 posts • Page 1 of 1

Return to “Mail Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password