My website has been hacked to send spoof email

September 5, 2017 840 views
Security Ubuntu 16.04

2 weeks ago, my website has been hacked by sending spoof email.
every seconds there is auth log that saying some one is trying to log in.

and my email activity spike up. and the result, my mail transaction account has been suspended.

so i destroy droplet and rebuild one, which get different ip.
it look fine for 2 weeks. but just yesterday, it happend again. all my mail transaction spike up. and has been suspended. its similar attack.

can anyone help me? what should I do..

1 Answer

Hello,

There are a few things that I could suggest:

  • Scan your local devices with a couple of antivirus programs to make sure that there is no malware

  • On your servers, make sure to use strong email passwords so that they could not be easily brute-forced

  • If you have any other software like Apache, PHP, Wordpress - make sure that it is up to date, or even better move it on a separate droplet so that it does not affect your email server directly

  • Close down any ports that are not supposed to be accessed by everyone

  • Disable SSH password authentication and use only SSH keys

  • Make sure that you’ve installed the latest patches on your system

Regards,
Bobby

Have another answer? Share your knowledge.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!