Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 06-29-2009, 02:02 AM
Moderator
 
Posts: 7,928
Default

Also, if you have a website hosted on the same server as your Zimbra installation check if you are using a form2email script and if so that it has some sort of validation method.
__________________
Reply With Quote
  #12 (permalink)  
Old 06-29-2009, 02:49 AM
Intermediate Member
 
Posts: 21
Default

Thank you uxbod and phoenix.
It seems everything is OK after I checked my server by ./chkrootkit and /var/log/secure.
I have deleted all the spam mails in the queue and change the mail account's password that could be compromised.
What I want to know is how I can avoid the same thing if another mail account is compromised in the future.
Is there any measure can be done such as some setting in zimbra or postfix?
Reply With Quote
  #13 (permalink)  
Old 06-29-2009, 02:55 AM
Moderator
 
Posts: 7,928
Default

Use complex passwords and ensure that within the Admin GUI you have set that if somebody enters a incorrect password three time the account is locked out.
__________________
Reply With Quote
  #14 (permalink)  
Old 06-29-2009, 02:55 AM
Intermediate Member
 
Posts: 21
Default

Quote:
Originally Posted by uxbod View Post
Also, if you have a website hosted on the same server as your Zimbra installation check if you are using a form2email script and if so that it has some sort of validation method.
There is no any website hosted on my zimbra server.
Reply With Quote
  #15 (permalink)  
Old 06-29-2009, 02:55 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

Quote:
Originally Posted by higeon View Post
What I want to know is how I can avoid the same thing if another mail account is compromised in the future.
Is there any measure can be done such as some setting in zimbra or postfix?
There's nothing you can do against an account being compromised except to use strong passwords and set them to expire regularly and make sure you enforce the policy, users don't like that but in the interests of safety for your server (and users) you must set and follow good practice.
__________________
Regards


Bill
Reply With Quote
  #16 (permalink)  
Old 06-29-2009, 03:12 AM
Intermediate Member
 
Posts: 21
Default

Is it possible to set zimbra/postfix to restrict the number of sending mails in one connection or restrict the number of mails can be sent in a period of time such as a minute?

And can it be restricted that the "from" mail addresses of the sending mails must be my domain's accounts?
Reply With Quote
  #17 (permalink)  
Old 06-29-2009, 03:25 AM
Moderator
 
Posts: 7,928
Default

You could use something like PolicyD to limit the amount of emails sent.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.