Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-25-2010, 07:45 AM
Junior Member
 
Posts: 5
Default Spam relay via Zimbra

Hi, since nearly one month, my zcs server send a lot of mail from yahoo.de hotmail.de to others hotmail or yahoo mail address.
Last day there were nearly 5000 mails queued.

Here is the log

an 24 08:55:49 ******34 postfix/smtpd[10993]: connect from mail.pca.com[208.179.88.50]
Jan 24 08:55:50 ******34 postfix/smtpd[10993]: lost connection after EHLO from mail.pca.com[208.179.88.50]
Jan 24 08:55:50 ******34 postfix/smtpd[10993]: disconnect from mail.pca.com[208.179.88.50]
Jan 24 08:55:50 ******34 postfix/smtpd[15781]: connect from mail.pca.com[208.179.88.50]
Jan 24 08:55:50 ******34 postfix/smtpd[11002]: lost connection after EHLO from host82-159-static.184-82-b.business.telecomitalia.it[82.184.159.82]
Jan 24 08:55:50 ******34 postfix/smtpd[11002]: disconnect from host82-159-static.184-82-b.business.telecomitalia.it[82.184.159.82]
Jan 24 08:55:51 ******34 postfix/smtpd[15781]: setting up TLS connection from mail.pca.com[208.179.88.50]
Jan 24 08:55:51 ******34 postfix/smtpd[15781]: Anonymous TLS connection established from mail.pca.com[208.179.88.50]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Jan 24 08:55:52 ******34 postfix/smtpd[10993]: connect from host82-159-static.184-82-b.business.telecomitalia.it[82.184.159.82]
Jan 24 08:55:52 ******34 postfix/smtpd[15781]: 96C8FD1802A: client=mail.pca.com[208.179.88.50], sasl_method=PLAIN, sasl_username=test
Jan 24 08:55:53 ******34 postfix/cleanup[14255]: 96C8FD1802A: message-id=<20100124075552.96C8FD1802A@******34.com>
Jan 24 08:55:53 ******34 postfix/qmgr[5957]: 96C8FD1802A: from=<webbanke102r@cua.com.au>, size=2685, nrcpt=1 (queue active)
Jan 24 08:55:53 ******34 postfix/smtpd[15781]: disconnect from mail.pca.com[208.179.88.50]
Jan 24 08:55:53 ******34 postfix/smtpd[5765]: connect from localhost.localdomain[127.0.0.1]
Jan 24 08:55:53 ******34 postfix/smtpd[5765]: 6B25ED1802E: client=localhost.localdomain[127.0.0.1]
Jan 24 08:55:53 ******34 postfix/cleanup[14255]: 6B25ED1802E: message-id=<20100124075552.96C8FD1802A@******34.com>
Jan 24 08:55:53 ******34 postfix/qmgr[5957]: 6B25ED1802E: from=<webbanke102r@cua.com.au>, size=3141, nrcpt=1 (queue active)
Jan 24 08:55:53 ******34 postfix/smtp[18494]: 96C8FD1802A: to=<goldfinger737@hotmail.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.1, delays=0.73/0/0/0.35, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=08364-14, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 6B25ED1802E)
Jan 24 08:55:53 ******34 postfix/qmgr[5957]: 96C8FD1802A: removed
Jan 24 08:55:53 ******34 postfix/smtpd[5765]: disconnect from localhost.localdomain[127.0.0.1]
Jan 24 08:55:53 ******34 postfix/smtp[16854]: 6B25ED1802E: to=<goldfinger737@hotmail.com>, relay=smtp.free.fr[212.27.48.4]:25, delay=0.1, delays=0.01/0.01/0.07/0, dsn=4.7.0, status=deferred (host smtp.free.fr[212.27.48.4] refused to talk to me: 421 4.7.0 smtp3-g21.free.fr Error: too many connections from 78.***.***.***)

Please help me i'm forced to delete mails manually...
Reply With Quote
  #2 (permalink)  
Old 01-25-2010, 09:47 AM
Moderator
 
Posts: 7,928
Default

Welcome to the forums

Please check Email Server Test - Online SMTP diagnostics tool - MxToolbox to see whether you are a open relay or not.
__________________
Reply With Quote
  #3 (permalink)  
Old 01-25-2010, 01:45 PM
Junior Member
 
Posts: 5
Default

Thanks,

But my server is not an open spam relay...
Do you know what else can do this ?
Reply With Quote
  #4 (permalink)  
Old 01-25-2010, 06:06 PM
Moderator
 
Posts: 7,928
Default

One of your accounts may have been compromised. Are you running Apache on your ZCS server aswell ?
__________________
Reply With Quote
  #5 (permalink)  
Old 01-25-2010, 10:38 PM
Junior Member
 
Posts: 5
Default

Hi, thanks, I deleted a "test" account with a simple password, I hope it is this... I'll see.
But I'haven't an apache server running, why this question ?
Reply With Quote
  #6 (permalink)  
Old 01-28-2010, 10:54 AM
Special Member
 
Posts: 110
Default I have the same issue How can I tell which account has been compromised

Hi

I have a Zimbra server verion 5.0.6 on Centos.

This has been working well for some years, however I am getting thousands of spam mails sent through the system these state they come from one hotmail.com account and in the mail.log it said the mail was from 127.0.0.1.

How can I find which compromised mail account or of the listed IP ranges the compromise is coming from.

Currently I run a script to constantly delete anything from the mail queue contating that email address but this is not the answer

I have tested and it does not appear to be an open relay

Thanks
Reply With Quote
  #7 (permalink)  
Old 01-28-2010, 11:28 AM
Moderator
 
Posts: 7,928
Default

If you check the headers of one of the emails and look at X-Originating-IP you should then be able to scan /opt/zimbra/log/audit.log to see which account that IP accessed.
__________________
Reply With Quote
  #8 (permalink)  
Old 02-13-2010, 05:34 AM
Special Member
 
Posts: 110
Default

Hi this is still a big problem for me. I am not sure how to look at the mail headers postqueue -p gives some information about deffered mail.

Am I meant to get the ID for the mail from postqueue -p then look in the
/opt/zimbra/data/postfix/spool/deffer folder

Whikst I can find more info in here I can not see X-Originating-IP in any of these.

Where should I be looking?
Reply With Quote
  #9 (permalink)  
Old 02-13-2010, 06:16 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

Quote:
Originally Posted by mintra View Post
Hi this is still a big problem for me. I am not sure how to look at the mail headers postqueue -p gives some information about deffered mail.

Am I meant to get the ID for the mail from postqueue -p then look in the
/opt/zimbra/data/postfix/spool/deffer folder

Whikst I can find more info in here I can not see X-Originating-IP in any of these.

Where should I be looking?
You can also look in your daily mail report and see who is sending the greatest number of emails.
__________________
Regards


Bill
Reply With Quote
  #10 (permalink)  
Old 02-13-2010, 06:39 AM
Moderator
 
Posts: 7,928
Default

Quote:
Originally Posted by mintra View Post
Hi this is still a big problem for me. I am not sure how to look at the mail headers postqueue -p gives some information about deffered mail.

Am I meant to get the ID for the mail from postqueue -p then look in the
/opt/zimbra/data/postfix/spool/deffer folder

Whikst I can find more info in here I can not see X-Originating-IP in any of these.

Where should I be looking?
So post the headers from one of those deferred emails so we may take a look.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.