On Mon, Apr 7, 2014 at 11:46 AM, difuntos <aquegles@xxxxxxxxx> wrote: > Hello, im having a security issue in my squirrelmail server : > > Some spammers are sending spam from my server (it´s also my SMTP server). > > I have configured sendmail exactly the same as others servers that do not > have this problems, so im guessing it´s a squirrelmail bug. You probably shouldn't make such claims (that can be perceived as offensive to developers of the free software you are using) unless you can back them up. > Here is an > example of one log entry : > > from=<yeboahc@xxxxxxxxxxxxx>, size=2960, class=0, nrcpts=10, > msgid=<*30c754cff9a4db493366099b63d1b282.squirrel@xxxxxxxxxxxxxxx*>, > proto=ESMTP, daemon=MTA, relay=localhost [127.0.0.1] > Apr 7 14:30:03 webmail sm-msp-queue[377]: s379p679023635: > to=bob.girardi@xxxxxxxxx,bob.thompson107@xxxxxxxxx,bob1213@xxxxxxx,bob17012003@xxxxxxxxx,bob20f4@xxxxxxx,bob2rip32@xxxxxxxxxxxxxx,bob3@xxxxxxxxxxxx,bob420skater@xxxxxxxxx,bob8883641@xxxxxxx,bob@xxxxxxxxxxxxxxxxxx, > delay=07:38:57, xdelay=00:00:01, mailer=relay, pri=3725072, > relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (s37HLD9P000379 Message > accepted for delivery) > > The message id says squirrel@mydomain... > > Anyone can help me with this please????? Change the password for the offending account. Install security and logging plugins such as Squirrel Logger, Lockout, CAPTCHA, etc. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php ------------------------------------------------------------------------------ Put Bad Developers to Shame Dominate Development with Jenkins Continuous Integration Continuously Automate Build, Test & Deployment Start a new project now. Try Jenkins in the cloud. http://p.sf.net/sfu/13600_Cloudbees ----- squirrelmail-users mailing list Posting guidelines: http://squirrelmail.org/postingguidelines List address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx List archives: http://news.gmane.org/gmane.mail.squirrelmail.user List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users