Ubuntu server sending mail from www-data

Riccardo

I am running a server with Ubuntu 12.04 and three wordpress installations, some ftp server and a basic postfix to send mails with wordpress. additionally I am using webmin to administrate this system.

Now I checked my munin side and saw some major postfix activity.

The queue entries look like this:

-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient-------
AF9AC11A03D9     2489 Sun Dec 22 04:29:26  [email protected]
(host alt1.gmail-smtp-in.l.google.com[173.194.79.26] said: 450-4.2.1 The user you are trying to contact is receiving mail at a rate that 450-4.2.1 prevents additional messages from being delivered. Please resend your 450-4.2.1 message at a later time. If the user is able to receive mail at that 450-4.2.1 time, your message will be delivered. For more information, please 450 4.2.1 visit http://support.google.com/mail/bin/answer.py?answer=6592 pi8si9408127pac.88 - gsmtp (in reply to RCPT TO command))
                                         [email protected]

passwd files were changed only by myself, no suspoicious logins. We do have ssh with passwords enabled.

I think my system is compromised But I would like to know who is the troublemaker: Wordpress, postfix, or the system itself?

To me it looks like wordpress and some hard mail-function in the php of wordpress.

Riccardo

strange signs, simple explanation: we are using a plugin that asks the commentator of a post to verify his comment. This means: each commentator receives an email. After upgrading wordpress to 3.8 some bots are able to set a comment without answering the needed captcha in the blog post. That means: a lot of comments which results in a lot of mails. We are hoping to get an update for the re-captcha plugin soon.

the queue was filled by emails to heavy-usage gmail spam accounts (the receiver gets to much messages in a given time...)

So it is a result of wanted mail-traffic and no "spamming" from our server seems to be involved.

Collected from the Internet

Please contact [email protected] to delete if infringement.

edited at
0

Comments

0 comments
Login to comment

Related

From Dev

Ubuntu server sending mail from www-data

From Dev

Mail not sending from local server in ROR

From Dev

Sending E-Mail or Sending data to Server in Background

From Dev

Sending data from a server to a client

From Dev

Sending mail data from JS to PHP to be mail()'d

From Dev

Sending mail to an external server?

From Dev

Django; sending email from my own postfix mail server

From Dev

Django; sending email from my own postfix mail server

From Dev

Sending data from a browser to a server and back

From Dev

sending data to particular client from twisted server

From Dev

iOS security sending data with password to and from server

From Dev

sending data to particular client from twisted server

From Dev

Java Sockets - Sending data from client to server

From Dev

Sending data from android studio app to server

From Dev

Sending data from Flask to Java Server

From Dev

Transfer files from virtualbox ubuntu server /var/www to local ubuntu

From Dev

Sending Emails from existing SMTP host from Ubuntu Server

From Dev

sending mail from R (mailR)

From Dev

Sending mail from the command line

From Dev

sending php mail from localhost

From Dev

Install Postfix using Mailutils on Ubuntu 19.04 server for sending out mail only

From Dev

Ubuntu mail server worth it?

From Dev

SQL server "Cannot send mails to mail server" "Failure sending mail"

From Dev

Best method for sending app mail from an Ubuntu 14.4 machine with ZF2

From Dev

How to send e-mail from Ubuntu server?

From Dev

How to send e-mail from Ubuntu server?

From Dev

Sending mail through Python SMTP Server

From Dev

Mail Server Not Receiving Email But Sending it Fine

From Dev

Sending SMTP Mail via Java and Postfix Server

Related Related

HotTag

Archive