Solved

spamming  on Hosted svrs?

Posted on 2016-10-19
6
48 Views
Last Modified: 2016-10-21
Looking for other way to look at spamming issue on a vps hosted server we DO NOT use as mail server.
We simply us it to host sites we build/maintain, and DNS manager that points MX records to our in-house mail servers.

Seems in that VPS hosted web server there are emails in the queue, cleared once already, passwords changed for user it looked like on the VPS account that was sending the mail.  But again queue is filled up.  I confirmed the mail is not coming from our internal emails servers via my FW and email server logs analysis and monitoring.

What can I possibly be missing as the VPS tech support is email only and nothings seems to be being done.  Thank you.
0
Comment
Question by:dee30
  • 3
  • 2
6 Comments
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 41850895
you say it has mail in the queue.. So you have the smtp components installed on the server and the web sites can send mail?
0
 
LVL 23

Accepted Solution

by:
Dr. Klahn earned 500 total points
ID: 41851268
First thing, immediately change all passwords on that system and enable two-factor authentication if possible.

Then.  Should that system be sending email at all?  If not, ...

Is the offending system linux or Windows? If it's linux, disable mail / postfix / dovecot and block outgoing port 25 using iptables.

Long term fix:  Reload the system from known clean distribution kits and generate all new randomly generated passwords of at least 16 length.
0
 

Author Comment

by:dee30
ID: 41853070
no mail should be sending.
it's windows and joomla use cpanel for joomla access to upload php html files etc.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 23

Expert Comment

by:Dr. Klahn
ID: 41853071
Then the email components should be disabled or removed, and the problem will be solved.
0
 

Author Comment

by:dee30
ID: 41853128
Yeah trying to find that stop, disable, uninstall option still..  also just discovered the de dedicated IP has one pretty damn close on same /24 network that has dsn listed as same as the hosting company we have our vps from and both, unrelated the other ip to us, has a poor email rep.  Hmmmm!!!???:
0
 

Author Comment

by:dee30
ID: 41854122
Thank you.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now