Am 10.05.2012 14:10, schrieb Giuseppe Perna: > thanks for repaly, > this is log foe webmail: > > 176.61.140.133 - - [08/May/2012:08:18:41 +0200] "GET > /src/compose.php?mail_sent=yes HTTP/1.1" 200 556825 > "https://webmail.esempio.it/src/compose.php" "Opera/9.80 (Windows NT > 6.1; U; en) Presto/2.10.229 Version/11.61" > 176.61.140.133 - - [08/May/2012:08:18:43 +0200] "POST /src/compose.php > HTTP/1.1" 302 5 "https://webmail.esempio.it/src/compose.php" > "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.10.229 Version/11.61" > 176.61.140.133 - - [08/May/2012:08:18:45 +0200] "POST /src/compose.php > HTTP/1.1" 302 5 "https://webmail.esempio.it/src/compose.php" > "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.10.229 Version/11.61" > 176.61.140.133 - - [08/May/2012:08:18:47 +0200] "POST /src/compose.php > HTTP/1.1" 302 5 "https://webmail.esempio.it/src/compose.php" > "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.10.229 Version/11.61" > 176.61.140.133 - - [08/May/2012:08:18:50 +0200] "POST /src/compose.php > HTTP/1.1" 302 5 "https://webmail.esempio.it/src/compose.php" > "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.10.229 Version/11.61" > > how can I find the account used to send spam?
only by compare timestamp since your webmail has no useful log roundcube logs as you can see below the postfix queue-id _______________ [root@arrakis:~]$ cat /var/log/roundcubemail/sendmail | grep reindl [05-Mar-2012 12:53:24 +0100]: User h.rei...@thelounge.net [**.0.0.99]; Message for h.rei...@thelounge.net; 250: 2.0.0 Ok: queued as 3666DA3
signature.asc
Description: OpenPGP digital signature