• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Inviting everyone to the UX test of a new security feature in the WP Toolkit
    For WordPress site owners, threats posed by hackers are ever-present. Because of this, we are developing a new security feature for the WP Toolkit. If the topic of WordPress website security is relevant to you, we would be grateful if you could share your experience and help us test the usability of this feature. We invite you to join us for a 1-hour online session via Google Meet. Select a convenient meeting time with our friendly UX staff here.

Issue suspicious mass mail sent, Plesk outgoing mail control does not record

Pan_Duke

Basic Pleskian
Hi all!
today a server got blaclisted in TRUNCATE. After searching i found that the mail log is for two hours full of such logs:
Code:
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:51 myservername drweb[27341]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27341]: scan: the message(drweb.tmp.2MvoVj) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27342]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27342]: scan: the message(drweb.tmp.V2SLYe) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27343]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27343]: scan: the message(drweb.tmp.MaZddo) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27344]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27344]: scan: the message(drweb.tmp.25pWYu) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27345]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27345]: scan: the message(drweb.tmp.JZA0vz) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27346]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27346]: scan: the message(drweb.tmp.P55quG) sent by [email protected] to [email protected] is passed
In the subscription panel of theaffecteddomain.com, the outgoing mail control has a limit of 40 emails per hour (the mail log has hundreds of emails sent) and the pop up graph in the same page reports that there are 3 nessages sent from this domain.

Also, the "Allow using Sendmail for scripts and users on this subscription" setting is unchecked as well for quite a while now.

Is there a way to find out why all these messages bypassed the plesk outgoing mail control?
How can i prevent such situations in the future?
 
Back
Top