Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-14-2009, 09:58 PM
Member
 
Posts: 12
Default Spam Through WEBMAIL

Hello. We have a NE 5.0.16 server recently upgraded from 5.0.12. All of a sudden we were receiving TONS of spam that appeared to be coming from an internal user. I assumed some sort of spoof and/or backscatter problem. zimbra.log grew to a huge size and we are now blacklisted on several domains. So someone hit us hard.

I started to suspect that one of our accounts was actually compromised. I then looked at /opt/zimbra/jetty/logs/access_log.2009-05-14 and there were a TON of entries in there listed below:

10.0.0.170 - - [14/May/2009:03:54:31 -0400] "POST /service/admin/soap/ HTTP/1
.1" 200 520 "-" "-"
10.0.0.170 - - [14/May/2009:03:54:31 -0400] "POST /service/admin/soap/ HTTP/1
.1" 200 520 "-" "-"

There are tons of these every 20 seconds or so. All the other logs previous to this do not have these. I assume that the account that was "sending" all the spam was compromised and the spammer is using the account for sending spam. Is this possible to send that volume of spam through the Zimbra web interface? Is there a vulnerability somewhere? The passwords are pretty strong so I am surprised it was hacked.

Thanks for any input

Dave
Reply With Quote
  #2 (permalink)  
Old 02-06-2012, 11:33 PM
Active Member
 
Posts: 38
Default

How did you fix this. I am having a similar issue
Reply With Quote
  #3 (permalink)  
Old 02-06-2012, 11:39 PM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mutuku View Post
How did you fix this. I am having a similar issue
Instead of posting a 'me too' to a thread that's almost three years old how about giving some details of your problem actual problem and what's your definition of 'similar'? There's also threads in the forums that cover the details of what to do if you have a compromised account on the server and other spam problems.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.