Spamer or What? Need Drastic Solution!
hi all,on a CPanel server i have some load problems. Server runs fine the suddenly the load goes up to 20-25.
There is no application running that cause this load. But looking to the exim main log i see the following below
So i think the server i use to send spam or at least used to relay e-mails or something similar.
Is there any way to stop peaple using the server to send e-mails trough??
I also note the following here. It seem that an user of a domain is using SMTP from another domain on the same sever.
2005-12-29 02:05:00 H=(memories-by-mail.com) [218.10.170.64] F=<info@adomain.com> rejected RCPT <anotherdomain@anotherdomain.com>: Sender verify failed
Thanks for any help!
========================
2005-12-29 15:08:24 Connection from [210.214.165.66] refused: too many connections
2005-12-29 15:08:26 Connection from [201.13.86.117] refused: too many connections
2005-12-29 15:08:26 Connection from [68.165.107.87] refused: too many connections
2005-12-29 15:08:26 Connection from [81.215.22.66] refused: too many connections
2005-12-29 15:08:26 Connection from [81.215.22.66] refused: too many connections
2005-12-29 15:08:26 Connection from [81.214.45.147] refused: too many connections
2005-12-29 15:08:26 Connection from [212.98.141.162] refused: too many connections
2005-12-29 15:08:26 Connection from [68.165.107.87] refused: too many connections
2005-12-29 15:08:26 Connection from [211.134.105.180] refused: too many connections
2005-12-29 15:08:26 H=(001.ams.or.at) [85.60.41.70] F=<e.battle_as@stanleyinteractive.co.uk> rejected RCPT <tate@sporti$
2005-12-29 15:08:26 H=(teapowder.com) [59.40.39.216] sender verify fail for <oil@teapowder.com>: unrouteable mail domain "te$
2005-12-29 15:08:27 Connection from [211.134.105.180] refused: too many connections
2005-12-29 15:08:27 Connection from [59.40.39.216] refused: too many connections
2005-12-29 15:08:27 Connection from [81.215.22.66] refused: too many connections
2005-12-29 15:08:27 Connection from [61.246.7.144] refused: too many connections
2005-12-29 15:08:27 Connection from [69.253.127.159] refused: too many connections
2005-12-29 15:08:26 Connection from [211.134.105.180] refused: too many connections
2005-12-29 15:08:26 H=(001.ams.or.at) [85.60.41.70] F=<e.battle_as@stanleyinteractive.co.uk> rejected RCPT <tate@sporti$
2005-12-29 15:08:26 H=(teapowder.com) [59.40.39.216] sender verify fail for <oil@teapowder.com>: unrouteable mail domain "te$
2005-12-29 15:08:27 Connection from [211.134.105.180] refused: too many connections
2005-12-29 15:08:27 Connection from [59.40.39.216] refused: too many connections
2005-12-29 15:08:27 Connection from [81.215.22.66] refused: too many connections
2005-12-29 15:08:27 Connection from [61.246.7.144] refused: too many connections
2005-12-29 15:08:27 Connection from [69.253.127.159] refused: too many connections
2005-12-29 15:08:28 Connection from [61.246.7.144] refused: too many connections
2005-12-29 15:08:28 Connection from [81.215.22.66] refused: too many connections
2005-12-29 15:08:28 Connection from [86.55.147.221] refused: too many connections
2005-12-29 15:08:29 Connection from [69.90.186.30] refused: too many connections
2005-12-29 15:08:29 Connection from [69.90.186.30] refused: too many connections
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (home) [84.21.206.232]
2005-12-29 15:08:29 H=(1-st.nl) [222.120.170.91] F=<lorenvalenzuelaro@eman.demon.nl> rejected RCPT <patton@sporti$
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cm218-252-217-214.hkcable.com.hk) [218.252.217$
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (binter.com) [218.253.194.93]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (69.61.59.20) [218.85.30.201]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (softbank219020212038.bbtec.net) [219.20.212.38]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cieletespace.fr) [70.103.202.235]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cims.bc.ca) [206.117.140.19]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (modernlight.ch) [84.61.38.111]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cic.ipn.mx) [80.236.47.225]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (modelcars.co.uk) [72.234.9.125]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (stanilands.freeserve.co.uk) [220.208.168.176]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (10-a.de) [85.60.52.150]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (cide.edu) [218.110.14.157]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (000.co.jp) [60.239.28.54]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (mofa.jp) [201.11.176.192]
2005-12-29 15:08:29 unexpected disconnection while reading SMTP command from (star-pos.ru) [61.230.23.90]
2005-12-29 15:08:30 unexpected disconnection while reading SMTP command from (cifec-sa.fr) [193.206.52.36]
2005-12-29 15:08:32 1EryRF-0002bT-PC <= luannera@macross-7.net H=(macross-7.net) [220.188.183.209] P=smtp S=1731 id=c3
==========================