configuring your server so that when someone logs in with root or su, your server will notify you via email.
Please use an email address that is NOT hosted on your server as a hacker could merely delete the emails right off the server.
Login to your server with root
Use any editor to edit .bash_profile
At the end of the file, place the following lines:
echo ‘WARNING – Root Login detected on:’ `date` `who` | mail -s “WARNING -
Root Login: `who | awk ‘{print $6}’`” youremail@domain.com
Now anytime someone gains root access you will be notified via email.
Showing posts with label Mail. Show all posts
Showing posts with label Mail. Show all posts
How to block a particular email in IMAIL
Posted by Unknown at 21:25 0 comments
The "Block Senders" option allows iMail users to block addresses from which they don't want to receive mail. Incoming mail from addresses on the list will be deleted automatically.
To add address to the blocking list, just
->Enter your iMail Personal Settings
->Select the Block Senders option, and
->Enter the full email address in "user@domain.com" format
Please note the followings when using the "Block Senders" option:
->You can put up to 50 email addresses.
->Messages from those senders will be deleted automatically.
->It applies to messages being delivered to the INBOX only.
(The "Block Senders" option is particular useful for iMail users who are using PC-Pine or users who will access to their mailboxes from different machines (no need to set Message Filters on those machines again).
Also check this link which will be more useful
http://skc.smyrna.k12.de.us/users/cbush/block.htm
To add address to the blocking list, just
->Enter your iMail Personal Settings
->Select the Block Senders option, and
->Enter the full email address in "user@domain.com" format
Please note the followings when using the "Block Senders" option:
->You can put up to 50 email addresses.
->Messages from those senders will be deleted automatically.
->It applies to messages being delivered to the INBOX only.
(The "Block Senders" option is particular useful for iMail users who are using PC-Pine or users who will access to their mailboxes from different machines (no need to set Message Filters on those machines again).
Also check this link which will be more useful
http://skc.smyrna.k12.de.us/users/cbush/block.htm
I can not send outgoing email (Error Number: 0x800CCC0B)
Posted by Unknown at 13:39 0 commentsIf you can not send email using mail.yourdomainname.com as your SMTP server, it may be because your ISP is blocking port 25 on their network, used for sending outoing mail via the SMTP protocol. In this instance, we recommend using your ISPs outgoing mail server, which can be obtained from your ISP. This practice has been put in place in an effort to stop spam.
Please check with your ISP for their outgoing mail server settings (SMTP) and adjust in your email program under email account setup. Relaying mail through your ISP will not change the look and appearance of email you send. It will simply use your ISPs outgoing mail server to relay your message, which will appear from your email address, etc.
I can not send outgoing email (Error Number: 0x800CCC0B)
Posted by Unknown at 13:39 0 commentsIf you can not send email using mail.yourdomainname.com as your SMTP server, it may be because your ISP is blocking port 25 on their network, used for sending outoing mail via the SMTP protocol. In this instance, we recommend using your ISPs outgoing mail server, which can be obtained from your ISP. This practice has been put in place in an effort to stop spam.
Please check with your ISP for their outgoing mail server settings (SMTP) and adjust in your email program under email account setup. Relaying mail through your ISP will not change the look and appearance of email you send. It will simply use your ISPs outgoing mail server to relay your message, which will appear from your email address, etc.
Enabling Spell Checker in Horde Webmail
Posted by Unknown at 22:29 0 commentsOne of the many unique features about Horde webmail is it’s spell checker facility. However, the use of this requires that certain components be installed. To install these follow these instructions:
1) Login to your Linux box via SSH as root.
2) Install aspell by running the following command:
yum -y install aspell aspell-en-gb
Leave it to install; you shouldn’t need to make any changes to Horde as it should automatically detect the ASPELL installation.
Preventing nobody spammer in PHP
Posted by Unknown at 22:17 0 commentspreventing nobody spammer in PHP
PHP and Apache has a history of not being able to track which users are sending out mail through the PHP mail function from the nobody user causing leaks in formmail scripts and malicious users to spam from your server without you knowing who or where.
Watching your exim_mainlog doesn’t exactly help, you see th email going out but you can’t track from which user or script is sending it. This is a quick and dirty way to get around the nobody spam problem on your Linux server.
If you check out your PHP.ini file you’ll notice that your mail program is set to: /usr/sbin/sendmail and 99.99% of PHP scripts will just use the built in mail(); function for PHP – so everything will go through /usr/sbin/sendmail =)
Requirements:
We assume you’re using Apache 1.3x, PHP 4.3x and Exim. This may work on other systems but we’re only tested it on a Cpanel/WHM Red Hat Enterprise system.
Time:
10 Minutes, Root access required.
Step 1)
Login to your server and su – to root.
Step 2)
Turn off exim while we do this so it doesn’t freak out.
/etc/init.d/exim stop
Step 3)
Backup your original /usr/sbin/sendmail file. On systems using Exim MTA, the sendmail file is just basically a pointer to Exim itself.
mv /usr/sbin/sendmail /usr/sbin/sendmail.hidden
Step 4)
Create the spam monitoring script for the new sendmail.
pico /usr/sbin/sendmail
Paste in the following:
#!/usr/local/bin/perl
# use strict;
use Env;
my $date = `date`;
chomp $date;
open (INFO, “>>/var/log/spam_log”) || die “Failed to open file ::$!”;
my $uid = $>;
my @info = getpwuid($uid);
if($REMOTE_ADDR) {
print INFO “$date – $REMOTE_ADDR ran $SCRIPT_NAME at $SERVER_NAME n”;
}
else {
print INFO “$date – $PWD – @infon”;
}
my $mailprog = ‘/usr/sbin/sendmail.hidden’;
foreach (@ARGV) {
$arg=”$arg” . ” $_”;
}
open (MAIL,”|$mailprog $arg”) || die “cannot open $mailprog: $!n”;
while ( ) {
print MAIL;
}
close (INFO);
close (MAIL);
Step 5)
Change the new sendmail permissions
chmod +x /usr/sbin/sendmail
Step 6)
Create a new log file to keep a history of all mail going out of the server using web scripts
touch /var/log/spam_log
chmod 0777 /var/log/spam_log
Step 7)
Start Exim up again.
/etc/init.d/exim start
Step 8) Monitor your spam_log file for spam, try using any formmail or script that uses a mail function – a message board, a contact script.
tail – f /var/log/spam_log
Sample Log Output
Mon Apr 11 07:12:21 EDT 2005 – /home/username/public_html/directory/subdirectory – nobody x 99 99 Nobody / /sbin/nologin
Log Rotation Details
Your spam_log file isn’t set to be rotated so it might get to be very large quickly. Keep an eye on it and consider adding it to your logrotation.
pico /etc/logrotate.conf
FIND:
# no packages own wtmp — we’ll rotate them here
/var/log/wtmp {
monthly
create 0664 root utmp
rotate 1
}
ADD BELOW:
# SPAM LOG rotation
/var/log/spam_log {
monthly
create 0777 root root
rotate 1
}
Notes:
You may also want to chattr + i /usr/sbin/sendmail so it doesn’t get overwritten.
Enjoy knowing you can see nobody is actually somebody =)
How to configure Outlook Express.
Posted by Unknown at 19:04 0 commentsSteps To configure Outlook Express.
–
Open outlook express
Click on Tools >> Accounts
Click on the Mail Tab >> Add >> Mail
Enter The Display Name >> Next
Enter the Email Address >> user@yourdomainname.com >> Next
Select Pop3 In the Drop Down List
Enter the Incoming Mail Server POP3 >> mail.yourdomainname.com
Enter the Outgoing Mail Server SMTP >> mail.yourdomainname.com
Enter the Account Name >> user@yourdomainname.com
Enter the Password >> letmein >> Next
Finish
Click on the Account which you have configured
Click on the Properties Tab >> Click on Servers Tab
Select My server Requires Authentication
Go to Advanced Tab >>
Check SMTP Port is 25 & POP3 Port is 110
Select Leave a copy of messages on server
You are done
Click on Send and Recieve.
Horde login failed on linux plesk
Posted by Unknown at 18:32 0 comments
while logging to webmail got an error “Horde login failed” , had tried to reset the password of the email address but that did not fix the issue. After further investigating what I found is that I was unable to telnet the IMAP port – the command used for this is:
Then, checked with ifconfig and got the output:
The line “inet 127.0.0.1 netmask 0xff000000” was missing, to get this fixed I executed the below command:
Then, I have tried to login using Horde and it worked perfectly fine.
root# telnet localhost 143
Then, checked with ifconfig and got the output:
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4
inet6 ::1 prefixlen 128
The line “inet 127.0.0.1 netmask 0xff000000” was missing, to get this fixed I executed the below command:
root# ifconfig lo0 127.0.0.1 netmask 255.0.0.0
Then, I have tried to login using Horde and it worked perfectly fine.
Mail Error message: Error 550 – “The recipient cannot be verified”:
Posted by Unknown at 18:06 0 comments
PERM_FAILURE: SMTP Error (state 9): 550-"The recipient cannot be verified.
Please check all recipients of this550 message to verify they are valid.
-----------------------
If the email account does indeed exist, then it is need to run the following commands to correct the issue.
Please check all recipients of this550 message to verify they are valid.
-----------------------
If the email account does indeed exist, then it is need to run the following commands to correct the issue.
/scripts/updateuserdomains
/scripts/mailperm
/scripts/mailperm
IMAP Error (Connection dropped by IMAP server)
Posted by Unknown at 18:04 0 commentsTo troubleshoot the IMAP error(Inbox lock errors) while accessing mailbox via any webmail clients(Horde, SquirrelMail, NeoMail, Round Cube etc.):
The error will be shown as below,
Connection dropped by IMAP server
ERROR: Connection dropped by IMAP server.
Query: SELECT "INBOX"
Reason Given: Unable to open this mailbox.
The error usually occurs when there is inbox.lock file in the mailbox.
Here the inbox gets locked and hence the mailbox can't be accessed and
you will get the above said error.
1. Remove the "inbox.lock" file from the particular mailbox.
Eventhough the "inbox.lock" file is deleted, it will be created when
the mailbox is accessed again. Hence after removing the file, we need
to copy the inbox to a new file name so as to fix the issue which can
be done as follows,
2. cat inbox > inbox.new
3. rm inbox
4. mv inbox.new inbox
5. Then fix ownership and permissions.
This fixes the issue.
Horde broken or not working correctly on cPanel
Posted by Unknown at 00:03 0 comments
Simple, short & sweet post, this should easily fix any problems you’re having
Also, this might be useful to run hourly, I leave this on our servers “just in case”.
/usr/local/cpanel/bin/update-horde --forceAlso, this might be useful to run hourly, I leave this on our servers “just in case”.
(mysqlcheck --auto-repair eximstats ; mysqlcheck --auto-repair horde) >/dev/null 2>/dev/null
Subscribe to:
Posts (Atom)