Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-02-2009, 12:18 PM
Junior Member
 
Posts: 8
Default Spam problem

I have hundreds of thousands of e-mails from the same address, when I look at /opt/Zimbra/data/postfix/spool/incoming and active. These are killing my e-mail server so the the users can not get e-mails.
I am at a loss as to what I need to do I have searched the forums but am not finding what I need.

I added the address to the salocal.cf.in as a blacklist line and restarted the zmamavisdctl. This did not seem to help.

I have attached a copy of the message including header. How do I get this problem fixed so that e-mail will start flowing again?

I can only access the zimbra from the server it self as I do not know what the password is for the Zimbra online console is.

However I have root access and can su as zimbra.

Please someone point me to somthing that may help.

Thanks
GC
Attached Files
File Type: txt message header.txt (6.2 KB, 8 views)
Reply With Quote
  #2 (permalink)  
Old 12-02-2009, 01:42 PM
Trained Alumni
 
Posts: 74
Default

can you zmcontrol stop and go to /opt/Zimbra/data/postfix/spool/incoming and active and rm -rf all of the spams and start zimbra again?
Reply With Quote
  #3 (permalink)  
Old 12-03-2009, 04:09 AM
Moderator
 
Posts: 7,928
Default

Quote:
Originally Posted by mtorres View Post
can you zmcontrol stop and go to /opt/Zimbra/data/postfix/spool/incoming and active and rm -rf all of the spams and start zimbra again?
And delete valid email aswell

Check the headers and see whether the connecting IP is a valid MTA or not ... Why not just block it at your perimeter ?
__________________
Reply With Quote
  #4 (permalink)  
Old 12-03-2009, 11:42 AM
y@w y@w is offline
Moderator
 
Posts: 658
Default

Quote:
Originally Posted by uxbod View Post
And delete valid email aswell

Check the headers and see whether the connecting IP is a valid MTA or not ... Why not just block it at your perimeter ?
Agreed. If they're only coming from one IP, it's much better to stop these messages as far away from your server as possible.
__________________
What a n00b!
Reply With Quote
  #5 (permalink)  
Old 12-03-2009, 11:46 AM
Junior Member
 
Posts: 8
Default

I had already blocked at the perimeter. but had thousands of e-mails already on the server that were trying to resend to other e-mail address. I had to empty the defer, deferred, active, and incoming directories for the problem to stop.

Does'nt antispam on Zimbra prevent this spam storm problems?
Reply With Quote
  #6 (permalink)  
Old 12-03-2009, 03:24 PM
Trained Alumni
 
Posts: 74
Default

Quote:
Originally Posted by uxbod View Post
And delete valid email aswell

Check the headers and see whether the connecting IP is a valid MTA or not ... Why not just block it at your perimeter ?
Yeah, that is the best, just block it at the firewall. But, I was in a jam one time like the o.p and I had to empty the active/incoming etc. folders for mail to start flowing again. Not the best, but it worked for me in a jam.
Reply With Quote
  #7 (permalink)  
Old 12-03-2009, 03:30 PM
Trained Alumni
 
Posts: 74
Default

Quote:
Originally Posted by GaryC View Post
I had already blocked at the perimeter. but had thousands of e-mails already on the server that were trying to resend to other e-mail address. I had to empty the defer, deferred, active, and incoming directories for the problem to stop.

Does'nt antispam on Zimbra prevent this spam storm problems?
Hi Gary,

zimbra out of the box has some good anti-spam measures, but for me, I have searched the forums and read different wikis on tweaking it. I also blocked most foreign IP's at the firewall (although most spam comes from the U.S, it helped a lot). After just tweaking for a while and using some rbl's I can truthfully say that it is VERY rare if a spam gets through *knocks on wood*.
Reply With Quote
  #8 (permalink)  
Old 12-04-2009, 02:26 AM
Moderator
 
Posts: 7,928
Default

Quote:
Originally Posted by GaryC View Post
Does'nt antispam on Zimbra prevent this spam storm problems?
It depends on the type of SPAM ... What RBLs are you using ?
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.