Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-10-2009, 07:24 AM
Elite Member
 
Posts: 281
Default [SOLVED] Checking all reply-to addresses and password requirements

Ok. so a while back we had a spammer gain access to some accounts due to easy passwords. They had went in and changed the forwarding address on these accounts so any mail coming to these accounts got forwarded to them also. I had went in and changed the ones I knew got hacked but I found out yesterday that they had also changed the reply-to address so when these people used the web interface to sent out email, any replies went to the spammer and not back to the account holder.

I have over 300 accounts so is there anyway using the CLI to scan all accounts and give me the forwarding addresses on the accounts as well as the reply-to addresses? Some of the account will have forwarding addresses that are good so I know some will get returned but I can work through that list

Also, if I go in and change the password requirements to be more strict, will that break current passwords if they don't meet the requirements? My hope there is to set the passwords to expire in like 15 days and force everyone to change their password to something harder to hack.

Thanks.

dj
Reply With Quote
  #2 (permalink)  
Old 04-10-2009, 08:13 AM
raj raj is offline
Moderator
 
Posts: 768
Default

su - zimbra
zmprov sa -v zimbraPrefMailForwardingAddress=* | grep -e "uid" -e "zimbraPrefMailForwardingAddress"


will list the information you asking for..you will need to figure out which ones are good or bad

* i dont know the attribute for Reply-to Address..may be someone can post here

Password stuff can be changed in Amin interface


Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
  #3 (permalink)  
Old 04-10-2009, 08:16 AM
Elite Member
 
Posts: 281
Default

Quote:
Originally Posted by raj View Post
su - zimbra
zmprov sa -v zimbraPrefMailForwardingAddress=* | grep -e "uid" -e "zimbraPrefMailForwardingAddress"


will list the information you asking for..you will need to figure out which ones are good or bad

Password stuff can be changed in Amin interface


Raj
Thanks for the CLI info. I will try that here in a bit to see I know the password stuff can be change in the admin panel but the question is still will it keep people from logging in if I change it now? If i change it to be 20 characters long, will people with only 10 be kept from logging in? That's just an example

dj
Reply With Quote
  #4 (permalink)  
Old 04-10-2009, 08:25 AM
Elite Member
 
Posts: 281
Default

Quote:
Originally Posted by raj View Post
su - zimbra
zmprov sa -v zimbraPrefMailForwardingAddress=* | grep -e "uid" -e "zimbraPrefMailForwardingAddress"


will list the information you asking for..you will need to figure out which ones are good or bad

* i dont know the attribute for Reply-to Address..may be someone can post here

Password stuff can be changed in Amin interface


Raj
Ok. That's not returning any information for me. I will double check it to make sure I have it right but as of now, no go

dj
Reply With Quote
  #5 (permalink)  
Old 04-10-2009, 11:37 AM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by dljordaneku View Post
Ok. so a while back we had a spammer gain access to some accounts due to easy passwords. They had went in and changed the forwarding address on these accounts so any mail coming to these accounts got forwarded to them also. I had went in and changed the ones I knew got hacked but I found out yesterday that they had also changed the reply-to address so when these people used the web interface to sent out email, any replies went to the spammer and not back to the account holder.

I have over 300 accounts so is there anyway using the CLI to scan all accounts and give me the forwarding addresses on the accounts as well as the reply-to addresses? Some of the account will have forwarding addresses that are good so I know some will get returned but I can work through that list

Also, if I go in and change the password requirements to be more strict, will that break current passwords if they don't meet the requirements? My hope there is to set the passwords to expire in like 15 days and force everyone to change their password to something harder to hack.

Thanks.

dj
You can create a new COS that requires password complexity and password expiration/rotation, and then apply it to the domains impacted.

If the existing COS has no password expiration, the users will be prompted to change their password immediately. Not sure what happens if the existing COS does have password expiration requirements, but you can test easily.

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #6 (permalink)  
Old 04-14-2009, 08:22 AM
Elite Member
 
Posts: 281
Default

Quote:
Originally Posted by LMStone View Post
You can create a new COS that requires password complexity and password expiration/rotation, and then apply it to the domains impacted.

If the existing COS has no password expiration, the users will be prompted to change their password immediately. Not sure what happens if the existing COS does have password expiration requirements, but you can test easily.

Hope that helps,
Mark
Ok. Thanks. This gives me something to work from. I am still trying to get the scripts to run for the forwarding and reply addresses. Still can't get the earlier one to work.

dj
Reply With Quote
  #7 (permalink)  
Old 04-14-2009, 08:43 AM
Elite Member
 
Posts: 281
Default

Ok. I guess I was just typing something wrong the other day or moving to a better vmware box did the trick but I am now able to pull the accounts with a forwarding address. No spammers but I did find some I need to fix.

Now just have to get the replyto figured out

dj
Reply With Quote
  #8 (permalink)  
Old 04-14-2009, 11:03 AM
Elite Member
 
Posts: 281
Default

Quote:
Originally Posted by raj View Post
su - zimbra
zmprov sa -v zimbraPrefMailForwardingAddress=* | grep -e "uid" -e "zimbraPrefMailForwardingAddress"


will list the information you asking for..you will need to figure out which ones are good or bad

* i dont know the attribute for Reply-to Address..may be someone can post here

Password stuff can be changed in Amin interface


Raj
YEA. I got it Thanks Raj for the first script. I just changed zimbraPrefMailForwardingAddress to zimbraPrefReplyToAddress and it returned those accounts to me

dj
Reply With Quote
  #9 (permalink)  
Old 04-14-2009, 12:28 PM
raj raj is offline
Moderator
 
Posts: 768
Default

glad it worked

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.