Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-05-2010, 11:59 AM
Loyal Member
 
Posts: 83
Default SPAM: Create & Use a Honeypot?

I'm just thinking out loud here.

I'm pretty happy finally with the state of my Zimbra spam filtering. Everybody here, especially DWMTRACTOR, has been very helpful in the configurations.

Now, I'm thinking about the possibility of creating a honeypot, but I'm unsure if it would be possible to do with Zimbra. If so, then I don't know exactly how to do it.

Basically, I think that we would just need to create an account and advertise it all over the blog world, maybe even send a bunch of the chain e-mail letters from it and to it, etc. But that account would have to be exempt from the normal spam. ALL mail coming to it would have to go to the inbox, and then a filter would be run to mark ALL mail as junk.

Your thoughts? Can this be done? If so, how?

kazooless
Reply With Quote
  #2 (permalink)  
Old 05-06-2010, 02:58 PM
Moderator
 
Posts: 1,432
Default

Yes, it would work, now that Bug 37164 - mail filed into Junk by Filters is not used to train anti-spam has been fixed.

Simply advertise your bogus email account, and create a filter as you say, that files all incoming mail into Junk. You'll also want to give the account a COS that purges Junk more frequently than normal, just to keep the account from filling up.

The only issue here is that if a message is marked as spam by Zimbra's SpamAssassin, then it will go straight to Junk and it will NOT be used to train the antispam system except if it has certain characteristics. (I believe the criteria are: must score 3 or higher in both header and body tests. See AutolearningNotWorking - Spamassassin Wiki and my posts in More Spam after upgrading to 6.0.5)

You could probably find a way to force autotraining for all mail that comes to your honeypot account. Possibly if you set zimbraSpamApplyUserFilters TRUE on a given account or COS via zmprov (as described at Bug 34039 - RFE: Option to apply mail filters on Junk Folder), you could have that interact with 37164.

If you do this, then you can take advantage of the honeypot in another way: use it as a "spamtrap". Although this term is sometimes used synonymously with honeypot, here the idea is somewhat different. What you would do is create a SpamAssassin rule that assigns a high score to any mail that is addressed to the spamtrap address. This way if a spammer tries to deliver an email to multiple addresses in a single SMTP transaction, the presence of the spamtrap address in the list will be an immediate indicator of spamminess.

If you try any of these ideas, please post a followup in this thread to let us know how it goes!
__________________
Elliot Wilen
Berkeley, CA

Don't forget to enter your Zimbra version in your forum profile.
Reply With Quote
  #3 (permalink)  
Old 05-06-2010, 04:17 PM
Loyal Member
 
Posts: 83
Default

This sounds pretty good and I just might try it, though some of it might be a little past my expertise. The COS change and training on the junk folder stuff. It would be nicer if there were an option to turn off SA alltogether for the honeypot user account.

Thanks again,

Kazooless
Reply With Quote
  #4 (permalink)  
Old 05-06-2010, 05:56 PM
raj raj is offline
Moderator
 
Posts: 768
Default

read about @spam_lovers_maps for amavis-new and then go do the setting in
/opt/zimbra/conf/amavis.conf.in

you will have to restart zimbra services for it to apply and you may save the copy in case it gets overwritten during zimbra upgrades.

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider

Last edited by raj; 05-06-2010 at 06:06 PM..
Reply With Quote
  #5 (permalink)  
Old 05-06-2010, 05:58 PM
Loyal Member
 
Posts: 83
Default

Cool! Will do. Thanks.

kazooless
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.