Koozali.org: home of the SME Server

Obsolete Releases => SME Server 9.x => Topic started by: drksam on January 13, 2016, 02:45:35 AM

Title: Excess traffic?
Post by: drksam on January 13, 2016, 02:45:35 AM
Hi everyone.  I have sme 9 setup and it has been working for some time now close to a year. A few weeks ago I noticed the the hdd light is on all the time. Today my isp called and said that my account had lots of traffic that they detected as malware and locked my account.  Without the sme hooked up I have no strange traffic so I know it has to be it. I know I can format and start over but there's so much on it that it would be a large job. Does anyone have any ideas on what can be done to figure out what is going on?
Title: Re: Sme seems to be infected
Post by: CharlieBrady on January 13, 2016, 03:41:42 AM
Your best bet would have been to ask security @ contribs.org before you made any changes.
Title: Re: Sme seems to be infected
Post by: drksam on January 13, 2016, 03:46:20 AM
I haven't made any yet. But I will ask there.
Thanks.
Title: Re: Sme seems to be infected
Post by: Stefano on January 13, 2016, 08:24:41 AM
Is there any webapp (WP, Joomla) running on it?
Title: Re: Sme seems to be infected
Post by: drksam on January 13, 2016, 11:21:43 AM
Yes Joomla runs on a couple of ibays.
Title: Re: Sme seems to be infected
Post by: Stefano on January 13, 2016, 11:25:05 AM
ok.. my guess is that your joomlas have been hacked.. are them updated? and their plugins?

take a look at /var/log/httpd/[access|error]_log

install qmHandle (http://wiki.contribs.org/Qmhandle_mail_queue_manager) and take a look at your mail queue
Title: Re: Sme seems to be infected
Post by: drksam on January 13, 2016, 11:28:06 AM
Ok thank you. I will take a look after work and report back.
Title: I run Joomla sites and Joomla may have a security issues.
Post by: guest22 on January 13, 2016, 11:35:34 AM
Changing the subject would be a good idea. There is no proof of SME Server being infected and the 'seems' is no excuse to finger point directly to SME Server up front.

I assume you have checked your Joomla versions and plugins (as indicated by Stefano), and extensively searched the Joomla forums and followed up on all their (security) advisories?
Title: Re: Sme seems to be infected
Post by: Stefano on January 14, 2016, 10:48:56 AM
@drksam: please edit the title of your first post here as suggested by RequestedDeletion

do you have any news for us? thank you