Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-15-2010, 03:20 PM
Active Member
 
Posts: 48
Default Two dots in a domain makes Zimbra go something something

Feb 15 15:13:22 mail postfix/smtpd[14464]: connect from mail.mydomain.com[172.24.0.4]

Feb 15 15:13:22 mail postfix/smtpd[14464]: warning: Illegal address syntax from mail.mydomain.com[172.24.0.4] in RCPT command: <dsaid@mydomain..com>

Feb 15 15:13:22 mail postfix/smtpd[14464]: disconnect from mail.mydomain.com[172.24.0.4]

So I notice this morning that somehow a user managed to make a typo. Just a simple little mistake that put an extra dot in the user's email address.

Now, every second or two I see that message above in my zimbra.log file. It's around 5 gigs already, just from the last day or two. The load on the system is up around 20.0 and the network connections are almost totally maxxed out, I actually get "connection refused" to the web server now and then.

Two questions then I guess:
How do I kill this message from the queue? It's already been SENT by the offending local user, but I see it nowhere in postfix-2.6.whatever/spool/

Is this really all it takes to bring Zimbra to a halt? Wow. That's the easiest DoS attack ever. Just send an email to the local domain with extra dots!

It shouldn't have been accepted for delivery in the first place.

Any help is most appreciated, I am not very familiar with how Zimbra is storing it's mail that it tries to deliver locally and though I am a commercial user it has been most than 5 hours since I opened a U1 "omg help" ticket, appears that nobody is home over at Zimbra today. (it's a holiday, mail servers never break on holidays)
__________________
Using:
zcs-7.1.4_GA_2555.RHEL6_64.20120105094542

On:
CentOS 6.1
Dual Xeon.Dell SC1425
Reply With Quote
  #2 (permalink)  
Old 02-17-2010, 06:28 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

You can get rid of messages from the queue by following the following article: Ajcody-MTA-Postfix-Topics - Zimbra :: Wiki - the inevitable warning, make sure you know exactly which message you're deleting and read the article in full before trying.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.