Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-03-2009, 10:27 AM
Loyal Member
 
Posts: 87
Default Need help ASAP, compromised server?

I checked my Deferred email this am and I have like 4000 messages from an account info@domain.com. I deleted those 4k msgs then they just kept flooding in. This was not a problem last night. Any ideas where to look? I deleted the account in question.

All of the msgs were from one account (a generic account used for inquiries and such) and to massive amounts of random addresses.

Any help is appreciated.
Reply With Quote
  #2 (permalink)  
Old 12-03-2009, 01:05 PM
Moderator
 
Posts: 1,147
Default

Sounds like the password for that account got cracked and it was used to send out spam until you stopped it.

Other then increasing security on generic accounts like that (if a user doesn't need to log into it then use a super long password), there isn't too much that I can think of to do.
Reply With Quote
  #3 (permalink)  
Old 12-04-2009, 03:42 AM
Moderator
 
Posts: 7,928
Default

Did you check the headers to see whether they were actually being sent from your server; as they may have been backscatter.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.