The spammers are increasingly organized and the truth is that there is a real mafia around this whole world. This is nothing new, but the truth is that it is difficult to intercept them since they use programs that 'self-eliminate' once their function is finished.The way these people work is usually something like this:
They infect computers with Trojans, awares, viruses and other pods (by the usual methods such as browser failures, untrusted activex acceptance by untrusted users, execution of programs that are not what they seem, etc.). These programs steal passwords stored on computers, among others, those for accessing FTP servers, in case you have a website (who does not have a website today!). Having the FTP user and the domain, it only remains to make a connection, upload a script and execute it via the web. The script begins to send emails left and right at an incredible speed. He finishes his work and, in most cases, self-destructs.How much damage can be done in just a few minutes!! The truth is that the logs of the system become scary when any of this happens.Aftermath:
The IP of your server begins to appear in spam lists, which many of them take 1 month to delete after sending them the request (it can always take less if you pay).
The strictest servers (such as hotmail) reject all emails until you are 'totally clean'.
Your customers can't send emails and complaints and problems begin.
Solutions:
Disable the execution of cgis, perl and PHP in those accounts that are not strictly necessary. Of course, a good SMTP server configuration. Force your customers to change passwords every X time. Cleaning my computer I have found a backup that I made, about a year ago, of some scripts that I intercepted on one of my dedicated servers.Full Content in Security by Default