store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 7:40 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: spam through user qscand
Unread postPosted: Tue Aug 04, 2009 7:42 pm 
Offline
Forum User
Forum User

Joined: Thu Jan 17, 2008 5:40 am
Posts: 18
Location: London
Following the ART guidelines here (http://www.atomicorp.com/wiki/index.php/Spam) it turns out that the compromised user is qscand. Looking through /var/clamav i can see plenty of files that are not supposed to be there and look to have been created by an outside source.
Any suggestions?

Using COS5/Plesk8.6/pyzor/razor/qgreylist/clamav etc. all the usual stuff from the atomic respository.


Top
 Profile  
 
 Post subject: Re: spam through user qscand
Unread postPosted: Thu Aug 06, 2009 5:22 am 
Offline
Forum User
Forum User

Joined: Thu Jan 17, 2008 5:40 am
Posts: 18
Location: London
Spam is being sent through the server using the following user:

qscand:x:10112:103:Qmail-Scanner Account:/var/spool/qscan:/bin/false

Any ideas on how I can stop this?


Top
 Profile  
 
 Post subject: Re: spam through user qscand
Unread postPosted: Thu Aug 06, 2009 11:14 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
What exactly makes you think that qscand is sending spam? This is actually the user that runs your spam and virus filtering. And what kind of files are you seeing in /var/clamav that are not supposed to be there?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: spam through user qscand
Unread postPosted: Thu Aug 06, 2009 4:18 pm 
Offline
Forum User
Forum User

Joined: Thu Jan 17, 2008 5:40 am
Posts: 18
Location: London
Problem now sorted!

Breun, you were right. It made me go back (with a clear head) and look again at what was going on. Using the guidelines I was able to isolate the spam message headers:

Code:
Received: (qmail 1156 invoked by uid 10112); 6 Aug 2009 18:43:46 +0100
Received: from  by server.domain.com (envelope-from <mailbox@domain.com>, uid 48) with qmail-scanner-2.06st


I looked up the uid 10112, and it belonged to qscand. What I should have been looking up was uid 48, which was the true source of the spam. This turned out to be a compromised account, whose password has now been changed to something better!

With regards to the qscand trail, I looked in /var/clamav/ and I saw files such as lott.hdb, phish.hdb, honeypot.hdb etc. which (I believed) I hadn't seen before and assumed that they were installed through a compromised login. Have since found out that they are signature databases for ClamAV.

Thanks, Breun.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group