Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-05-2010, 01:32 PM
New Member
 
Posts: 3
Question possible to trace auth user to sent mail?

Hello,
Dealing with spambots that probably have auth user/pwd to send mail. We need to trace down what account is sending a volume of messages. Tried hunting the logs and the x- headers, but those show only localhost6, so my assumption is that webmail is being used to transmit those but I can't seem to link the outgoing mail to a given user.

Is it possible to show who is sending emails or at least trace it down?

Thanks,
--Christian

version: Zimbra Community Server 6.0.4

Last edited by gazumping; 05-05-2010 at 01:33 PM.. Reason: zimbra version
Reply With Quote
  #2 (permalink)  
Old 05-05-2010, 06:17 PM
raj raj is offline
Moderator
 
Posts: 768
Default

Quote:
tail -n 1000000 /var/log/maillog | grep "sasl_username=" > smtpauthlogins.txt
above will spit out the "smtpauthlogins.txt" open it and see which user's name (sasl_username=USER_NAME) is repeating the most, that dude has a virus infected outlook or spammer got hold of his simple password and relaying SPAM by using SMTP AUTH

change the password for that user asap.

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.