Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-27-2010, 06:29 AM
Member
 
Posts: 13
Default Problem: server being used for sending spam

Hello,
First sorry for my English, is the first time that I participate in the forum.

I have a serious problem with my mail server, it is being used for sending a large amount of spam. Everything has already been verified, they can be sure. What happens is that an external IP can somehow generate messages that are sent from localhost and send to multiple recipients. But there is no authentication whatsoever, it is as if the server had been hacked, just that even tools rootkit detect anything.
The server is a Debian with version 5 6.0.4_GA_2038.DEBIAN5 DEBIAN5 FOSS edition, is there any bug that allows it?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 07-27-2010, 06:38 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by darlanart View Post
Hello,
First sorry for my English, is the first time that I participate in the forum.

I have a serious problem with my mail server, it is being used for sending a large amount of spam. Everything has already been verified, they can be sure. What happens is that an external IP can somehow generate messages that are sent from localhost and send to multiple recipients. But there is no authentication whatsoever, it is as if the server had been hacked, just that even tools rootkit detect anything.
The server is a Debian with version 5 6.0.4_GA_2038.DEBIAN5 DEBIAN5 FOSS edition, is there any bug that allows it?

Thanks!
Have you verified that your server is not an open relay by using one of the internet test sites? When you've done that you need to post some information about what exactly is happening and some headers from a spam email. You might also want to search the forums for some other posts on this topic.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 07-27-2010, 06:50 AM
Member
 
Posts: 13
Default

Quote:
Originally Posted by phoenix View Post
Have you verified that your server is not an open relay by using one of the internet test sites? When you've done that you need to post some information about what exactly is happening and some headers from a spam email. You might also want to search the forums for some other posts on this topic.
Thanks for your reply Bill.

Yes, I tested the openrelay, but is not the problem. You can see the problem here:
PSBL spamtrap mail for 201.22.249.72
Reply With Quote
  #4 (permalink)  
Old 07-27-2010, 07:00 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by darlanart View Post
Thanks for your reply Bill.

Yes, I tested the openrelay, but is not the problem. You can see the problem here:
PSBL spamtrap mail for 201.22.249.72
Then you should check the log files (and check your daily admin mail report) to see if any of the accounts on your server are sending large numbers of email as you might have a compromised account. You could also take a look at some of these threads.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 07-27-2010, 12:13 PM
Member
 
Posts: 13
Default

Quote:
Originally Posted by phoenix View Post
Then you should check the log files (and check your daily admin mail report) to see if any of the accounts on your server are sending large numbers of email as you might have a compromised account. You could also take a look at some of these threads.
Bill,

The first of senders is "Atendimento@bradesco.com.br", a user does not exist on my server, my server does not belong to this domain, and logs everything appears as if you were sending localhost.
Reply With Quote
  #6 (permalink)  
Old 07-28-2010, 05:09 AM
Member
 
Posts: 13
Default

Any ideia?
Reply With Quote
  #7 (permalink)  
Old 07-28-2010, 05:16 AM
raj raj is offline
Moderator
 
Posts: 768
Default

hi..spammer has compromised the password of one of your account and is using SMTP AUTH to login and then REALY as many as email they want.
the actual address used to AUTH will not show up in the MAIL HEADER..you need to research the maillogs or zimbra.log to see what user is connecting a lot and other log information.

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.