<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with nobody</title>
      <link>http://ask.metafilter.com/tags/nobody</link>
      <description>Questions tagged with 'nobody' at Ask MetaFilter.</description>
	  <pubDate>Tue, 13 Feb 2007 20:32:40 -0800</pubDate> <lastBuildDate>Tue, 13 Feb 2007 20:32:40 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>What if?</title>
	<link>http://ask.metafilter.com/56968/What%2Dif</link>	
	<description>What is the origin of the phrase: &quot;what if they had ____ and nobody came?&quot;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.56968</guid>
	<pubDate>Tue, 13 Feb 2007 20:32:40 -0800</pubDate>
	<category>came</category>
	<category>nobody</category>
	<category>revolution</category>
	<dc:creator>Krrrlson</dc:creator>
	</item>
	<item>
	<title>&apos;nobody&apos; spam</title>
	<link>http://ask.metafilter.com/37472/nobody%2Dspam</link>	
	<description>How can I determine exactly from where or how a server&apos;s email queue is being filled with outgoing spam from user &apos;nobody&apos;? Here&apos;s the basic set up:&lt;br&gt;
Redhat 9.0&lt;br&gt;
Apache 1.3.34&lt;br&gt;
Exim 4.52&lt;br&gt;
Cpanel - latest version&lt;br&gt;
(note: I&apos;m looking at about 1,500 of these set ups, so massive changes aren&apos;t going to be possible, including the use of phpsuexec.)&lt;br&gt;
&lt;br&gt;
So the deal is, a spam complaint comes in pegging a certain IP address as the culprit.  I match it up with the actual server and find a mail queue with 60,000 outgoing messages, 59,995 of which are spam.  The outgoing address is nobody@hostname.com (of course), since Apache runs as user nobody.&lt;br&gt;
&lt;br&gt;
Occassionally, I can match up the timestamp of an email to an Apache log entry, showing me that a certain &quot;contact us&quot; script, or something of the sort, is being exploited.  At that point, the&quot;fix&quot; is easy.  But more often than not, especially when the cPanel installation has about 250 accounts, trying to find THE insecure script responsible for the creation of thousands of outgoing emails is like looking for a needle in a hystack.&lt;br&gt;
&lt;br&gt;
Does anyone have any suggestions on how I can attack this problem more efficiently and productively?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.37472</guid>
	<pubDate>Wed, 03 May 2006 06:54:05 -0800</pubDate>
	<category>apache</category>
	<category>cpanel</category>
	<category>email</category>
	<category>exim</category>
	<category>nobody</category>
	<category>redhat</category>
	<category>server</category>
	<category>spam</category>
	<dc:creator>Witty</dc:creator>
	</item>
	
	</channel>
</rss>

