UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  eUKhost's Official Web Hosting Forum > Technical Support > VPS Hosting - Virtual Private Servers

Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 22-02-2010, 18:51
Junior Member
 
Join Date: Aug 2007
Posts: 19
Default VPS has been blacklisted by CBL

Hi,

CBL (The CBL), which some ISPs use for blacklisting claims that my VPS has been infected with DarkMailer/Yellsoft DirectMailer.

As a result I am unable to send emails to orange.co.uk/freeserve/wanadoo addresses.

What sort of help can I get from the support team in cleaning my VPS and hardening it to minimise the risk of this recurring? What's the best way to get started?

Thanks,
Dave.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 22-02-2010, 21:50
Senior Member
 
Join Date: May 2007
Location: Newport, Wales
Posts: 992
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Quote:
Originally Posted by davel View Post
Hi,

CBL (The CBL), which some ISPs use for blacklisting claims that my VPS has been infected with DarkMailer/Yellsoft DirectMailer.

As a result I am unable to send emails to orange.co.uk/freeserve/wanadoo addresses.

What sort of help can I get from the support team in cleaning my VPS and hardening it to minimise the risk of this recurring? What's the best way to get started?

Thanks,
Dave.
Are you sure it's not YOUR IP address on the CBL? What does the bounce e-mail say?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 22-02-2010, 22:17
Junior Member
 
Join Date: Aug 2007
Posts: 19
Default

Yes, It is my IP, my VPS's IP address, that has been blacklisted. That's what I meant to say, anyway.

Orange's bounce said
"Subject: Mail delivery failed: returning message to sender

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

xx@xx.wanadoo.co.uk
SMTP error from remote mail server after initial connection:
host mail-in.freeserve.com [193.252.22.184]: 554 5.7.1 service refused.
Client host <my VPS IP address> blocked for spamming issues. More information
available at http://help.orange.c

------ This is a copy of the message, including all the headers. ------

Return-path: <dave@my_vps.co.uk>
Received: from [212.183.140.17] (helo=Inbox)
by vps.my_vps.co.uk with esmtps (SSLv3:RC4-MD5:12
(Exim 4.69)
(envelope-from <dave@my_vps.co.uk>)
id 1NjaiV-0002ca-Lt; Mon, 22 Feb 2010 16:01:04 +0000
MIME-Version: 1.0
content-class:
From: Me <dave@my_vps.co.uk>
Subject: FW: Problem sending emails
Date: Mon, 22 Feb 2010 16:01:00 +0000
Importance: normal
X-Priority: 3
To: Recpient <xx@xx.wanadoo.co.uk>
"
Unsurprisingly I could not get help from the mal-formed orange URL.
I checked on the CBL blacklist and my VPS IP was on there.

I did some more digging and found the rogue files (cgi files), so removed them and killed the cgi processes. I have changed the password of the account used to gain access to my server too.

I don't need FTP access for all my user accounts. In CPanel I can't remove all of an account's FTP users. How can I limit FTP access to an account? I have prevented the use of anonymous FTP.

Also, is it possible to force all users to use FTP over SSL? As the password used to gain access was 9 chars long and comprised upper and lower case letters and numbers then it seems unlikely that it was cracked through brute force (there being over 210 trillion combinations), so I assume the password was picked up when going through the internet as clear text.

Thanks

Dave.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 22-02-2010, 23:52
Senior Member
 
Join Date: May 2007
Location: Newport, Wales
Posts: 992
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Quote:
Originally Posted by davel View Post
Yes, It is my IP, my VPS's IP address, that has been blacklisted. That's what I meant to say, anyway.

Orange's bounce said
"Subject: Mail delivery failed: returning message to sender

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

xx@xx.wanadoo.co.uk
SMTP error from remote mail server after initial connection:
host mail-in.freeserve.com [193.252.22.184]: 554 5.7.1 service refused.
Client host <my VPS IP address> blocked for spamming issues. More information
available at http://help.orange.c

------ This is a copy of the message, including all the headers. ------

Return-path: <dave@my_vps.co.uk>
Received: from [212.183.140.17] (helo=Inbox)
by vps.my_vps.co.uk with esmtps (SSLv3:RC4-MD5:12
(Exim 4.69)
(envelope-from <dave@my_vps.co.uk>)
id 1NjaiV-0002ca-Lt; Mon, 22 Feb 2010 16:01:04 +0000
MIME-Version: 1.0
content-class:
From: Me <dave@my_vps.co.uk>
Subject: FW: Problem sending emails
Date: Mon, 22 Feb 2010 16:01:00 +0000
Importance: normal
X-Priority: 3
To: Recpient <xx@xx.wanadoo.co.uk>
"
Unsurprisingly I could not get help from the mal-formed orange URL.
I checked on the CBL blacklist and my VPS IP was on there.

I did some more digging and found the rogue files (cgi files), so removed them and killed the cgi processes. I have changed the password of the account used to gain access to my server too.

I don't need FTP access for all my user accounts. In CPanel I can't remove all of an account's FTP users. How can I limit FTP access to an account? I have prevented the use of anonymous FTP.

Also, is it possible to force all users to use FTP over SSL? As the password used to gain access was 9 chars long and comprised upper and lower case letters and numbers then it seems unlikely that it was cracked through brute force (there being over 210 trillion combinations), so I assume the password was picked up when going through the internet as clear text.

Thanks

Dave.
If you're not entirley sure how those files got there, ask eUK to do an audit of your server as they may not have been uploaded via FTP. But yes, there is an option to force FTP over SSL (or you can disable it completely) which you can do from WHM.

You can request to remove yourself from the CBL, but be sure all infected files are removed from your server beforehand as if you get added to the CBL again you may not be able to get back off it
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT. The time now is 20:53.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
UK Web Hosting by eUKHosting 3.1.0
UK Web Hosting by eUKHosting 3.1.0
Copyright © 2001-2012, eUKhost LTD. All rights reserved.

 


UK VPS Hosting
VPS Hosting plans

Dedicated Server Hosting
Dedicated Server plans

VoIP Dedicated Servers
Asterisk, Trixbox Dedicated Servers

Business Web Hosting
100% uptime Hosting

UK Cpanel Hosting
cPanel Shared Hosting

Domain Hosting
Cheap Domains & Hosting Plans

UK Reseller Hosting
Reseller Web Hosting

Windows Hosting
Windows Shared Hosting

Windows VPS

Windows VPS Hosting

Semi Dedicated Servers
Semi-Dedicated Hosting

Dedicated Server Mirroring
Dedicated Server Mirroring

Webhosting Knowledgebase
Frequently asked Questions

Web Hosting Blog
eUKhost Blog

Web Hosting Support
Support Helpdesk

UK Data Center
eUKhost Datacenter

Web Hosting Forum
eUKhost Forum

Support Tutorials
Online Flash Tutorials

Offsite Back-up Plans
Remote Backup Service

ColdFusion Hosting
ColdFusion Web Hosting
 
 

Android and Apple App


knowledgebase articles
eUKhost.com Services

Pre-Sales Questions
Pre-sales FAQ's

Domain Names
Domain registration FAQ's

cPanel Hosting
cPanel Hosting FAQ's

Windows Web Hosting
Plesk Control Panel

Reseller Hosting
Reseller Hosting FAQ's

VPS Hosting
Virtual Private Server

Semi-Dedicated Servers
Semi-Dedicated FAQ's

Dedicated Servers
Dedicated Server Hosting

Joomla Hosting
Joomla Web Hosting

Mambo Hosting
Mambo Web Hosting

Magento Hosting
Magento Web Hosting

Wordpress Hosting
Wordpress Web Hosting

 

Web Hosting Affiliate Program
 

popular blog categories

UK Web Hosting
UK Hosting articles

Dedicated Server Hosting
Dedicated Server guidelines

VPS Hosting
VPS hosting articles

cPanel Hosting
cPanel Hosting articles

Linux Operating System
Linux Operating techniques

Windows Web Hosting
Windows plesk articles