Re: FED Up.

From: Colin McKinnon (colin.thisisnotmysurname_at_ntlworld.deletemeunlessURaBot.com)
Date: 01/06/04


Date: Tue, 06 Jan 2004 22:22:28 +0000

Nasir spilled the following:
>
> I have a DATABASE server running MySQLD 3.23.58.Users vist and sign up
> their interest in my website.Now the problem is arising that when a
> user signs up first , they get emails of confirmation from my
> server.In addition to these emails , the customer also gets some
> annoyed e-mails from someone residing/depending totllay on @yahoo.com
> email-address maintaining the anonymity.
>
> I did try by sending only e-mails to some my own email address,
> whether someone is sniffering through my traffic, but I got no e-mail
> except the ones I had sent myself.
>
> After this I added some other email addresses in my DB server but I
> sent no email to them at all.This time all email addresses got those
> *annoying* e-mails also.
> I am really fed up with this issue, getting no clue how to come to
> know about this.
>

If you've get evidence that spammers have got Email addresses from your
database, and are continuing to do so, then it's much more likely that your
system has been compromised the data has been 'sniffed' from the internet.

> I am now thinking about adding --log option to safe_mysql to log all
> queries, But I am again doubtfull if that would do any help to me .
>

I guess from what you're (not) saying you don't run an IDS?

Check your firewall by running a remote scan on your server.

Install & run chkrootkit (http://www.chkrootkit.org/).

If your distro has package verification tools use them (e.g. rpm --verify)

If this doesn't turn up anything then you need to have a good hard look at
the CGI scripts you're using.

Don't feel bad - it happens to everybody at least once.

HTH

Colin



Relevant Pages

  • IIS 6.0 web wont connect to SQL2000 db server
    ... I'm trying to deploy web servers on Server 2003, IIS 6.0, that connect to a ... backend database server running SQL2000 on Server 20003. ... IIS logs indicate error 404, ...
    (microsoft.public.data.odbc)
  • RE: Can not stop junk e-mails send from our server
    ... we can no longer archive the e-mails or set the SCL to lower ... Start the Exchange System Manager program. ... Also please check if your Server is in an open-relay state, ... Block Open SMTP Relaying and Clean Up Exchange Server SMTP Queues ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot obtaion domain controller
    ... Please no e-mails, any questions should be posted in the NewsGroup ... Connecting to directory service on server DC_Name. ... On your dns server, bring up the mmc console for dns. ... Do you see Forward Lookup Zones? ...
    (microsoft.public.windows.server.active_directory)
  • RE: Can not stop junk e-mails send from our server
    ... Also please help me collect Message Tracking to see if the e-mails are from ... junk e-mails send from our server. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Email Queue Error
    ... the value "SMTP Server Remote Queue Length" ... If your clients do send many e-mails, it is a normal behavior and you can ...
    (microsoft.public.windows.server.sbs)