Koozali.org: home of the SME Server

Excess traffic?

Offline drksam

  • *
  • 6
  • +0/-0
Excess traffic?
« on: January 13, 2016, 02:45:35 AM »
Hi everyone.  I have sme 9 setup and it has been working for some time now close to a year. A few weeks ago I noticed the the hdd light is on all the time. Today my isp called and said that my account had lots of traffic that they detected as malware and locked my account.  Without the sme hooked up I have no strange traffic so I know it has to be it. I know I can format and start over but there's so much on it that it would be a large job. Does anyone have any ideas on what can be done to figure out what is going on?
« Last Edit: January 14, 2016, 11:19:29 AM by drksam »

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Sme seems to be infected
« Reply #1 on: January 13, 2016, 03:41:42 AM »
Your best bet would have been to ask security @ contribs.org before you made any changes.

Offline drksam

  • *
  • 6
  • +0/-0
Re: Sme seems to be infected
« Reply #2 on: January 13, 2016, 03:46:20 AM »
I haven't made any yet. But I will ask there.
Thanks.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Sme seems to be infected
« Reply #3 on: January 13, 2016, 08:24:41 AM »
Is there any webapp (WP, Joomla) running on it?

Offline drksam

  • *
  • 6
  • +0/-0
Re: Sme seems to be infected
« Reply #4 on: January 13, 2016, 11:21:43 AM »
Yes Joomla runs on a couple of ibays.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Sme seems to be infected
« Reply #5 on: January 13, 2016, 11:25:05 AM »
ok.. my guess is that your joomlas have been hacked.. are them updated? and their plugins?

take a look at /var/log/httpd/[access|error]_log

install qmHandle (http://wiki.contribs.org/Qmhandle_mail_queue_manager) and take a look at your mail queue

Offline drksam

  • *
  • 6
  • +0/-0
Re: Sme seems to be infected
« Reply #6 on: January 13, 2016, 11:28:06 AM »
Ok thank you. I will take a look after work and report back.

guest22

I run Joomla sites and Joomla may have a security issues.
« Reply #7 on: January 13, 2016, 11:35:34 AM »
Changing the subject would be a good idea. There is no proof of SME Server being infected and the 'seems' is no excuse to finger point directly to SME Server up front.

I assume you have checked your Joomla versions and plugins (as indicated by Stefano), and extensively searched the Joomla forums and followed up on all their (security) advisories?

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Sme seems to be infected
« Reply #8 on: January 14, 2016, 10:48:56 AM »
@drksam: please edit the title of your first post here as suggested by RequestedDeletion

do you have any news for us? thank you