За домовленістю
Хостинг несколько раз уже блокировал аккаунт, из-за рассылки спама. Оказалось что в папках на хостинге появляются какие-то вредоносные php-скрипты, удаляли их, но снова появляются другие. Пароли все меняли. Нужно провести глубокий анализ и очистить все, чтобы больше не повторялись такие случаи. Сайт на Joomla.
Вот что пишет хостинг:
Да, Пользователь b10-25289 заблокирован за рассылку спама. Количество писем 1098
[root@bitte10 ~]# exim -bp |grep homesrub.com |wc -l
1098
1aMNEe-003nfX-35 From: To: [email protected]
1aMNEe-003ngL-8g From: To: [email protected]
1aMNEe-003niA-VC From: To: [email protected]
1aMNEe-003nhC-Ie From: To: [email protected]
1aMNEe-003ngB-78 From: To: [email protected]
1aMNEe-003nhW-Ml From: To: [email protected]
1aMNEe-003ngs-Ea From: To: [email protected]
1aMNEe-003nhq-Qh From: To: [email protected]
1aMNEf-003nif-60 From: To: [email protected]
1aMNEf-003njJ-ET From: To: [email protected]
1aMNEf-003niz-9z From: To: [email protected]
1aMNEf-003niK-1V From: To: [email protected]
1aMNEf-003niV-3n From: To: [email protected]
1aMNEf-003nip-7t From: To: [email protected]
1aMNEf-003nj9-C7 From: To: [email protected]
[root@bitte10 ~]# exim -Mvh 1aMNEf-003nif-60
1aMNEf-003nif-60-H
exim 93 93
1453413465 0
-ident exim
-received_protocol local
-body_linecount 28
-max_received_linelength 138
-allow_unqualified_recipient
-allow_unqualified_sender
-localerror
XX
1
[email protected]
142P Received: from exim by bitte10.com with local (Exim 4.72)
id 1aMNEf-003nif-60
for [email protected]; Thu, 21 Jan 2016 23:57:45 +0200
038 Date: Thu, 21 Jan 2016 23:57:45 +0200
044I Message-Id:
029 Auto-Submitted: auto-replied
055F From: Mail Delivery System
029T To: [email protected]
056 Subject: Mail failure - rejected by local scanning code
[root@bitte10 ~]# exim -Mvb 1aMNEf-003nif-60
1aMNEf-003nif-60-D
A message that you sent was rejected by the local scanning code that
checks incoming messages on this system. The following error was given:
"Non-smtp sending from non-local domains is blocked"
------ This is a copy of your message, including all the headers. ------
Received: from b10-25289 by bitte10.com with local (Exim 4.72)
(envelope-from )
id 1aMNEf-003nie-5V
for [email protected]; Thu, 21 Jan 2016 23:57:45 +0200
Date: Thu, 21 Jan 2016 23:57:45 +0200
Message-Id:
To: [email protected]
Subject: FW: Milf riding huge black schlong
X-PHP-Script: www.homesrub.com/libraries/tcpdf/cache/help.php for 103.6.198.28
From: "Betsy Dixon"
Reply-To:"Betsy Dixon"
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Milf riding huge black schlong here
В том состоянии, что сейчас эккаунт, мы не можем открыть.
Без проведения работ его снова взломают и спам снова возоб