By oline
2 weeks ago, my website has been hacked by sending spoof email. every seconds there is auth log that saying some one is trying to log in.
and my email activity spike up. and the result, my mail transaction account has been suspended.
so i destroy droplet and rebuild one, which get different ip. it look fine for 2 weeks. but just yesterday, it happend again. all my mail transaction spike up. and has been suspended. its similar attack.
can anyone help me? what should I do…
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
Hello,
There are a few things that I could suggest:
Scan your local devices with a couple of antivirus programs to make sure that there is no malware
On your servers, make sure to use strong email passwords so that they could not be easily brute-forced
If you have any other software like Apache, PHP, Wordpress - make sure that it is up to date, or even better move it on a separate droplet so that it does not affect your email server directly
Close down any ports that are not supposed to be accessed by everyone
Disable SSH password authentication and use only SSH keys
Make sure that you’ve installed the latest patches on your system
Regards, Bobby
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.