Results 1 to 4 of 4

Thread: Please help - my zimbra sends backscatter spam.

  1. #1
    rokka is offline Member
    Join Date
    Dec 2009
    Posts
    13
    Rep Power
    5

    Default Please help - my zimbra sends backscatter spam.

    Hi forum,

    I'm having this annoying problem how zimbra handles backscatter spam.
    Seems like my server gonna be in all blacklists soon, if I don't correct this behaviour.

    When spammer sends me a message with banned attachment (exe, src etc), zimbra sends ndr back to the spammer's victim.

    I think this is what's configured by default in zimbra, which is pretty thoughtless.

    grep 144AAD7601E /var/log/mail.log.1

    Feb 15 10:47:26 mail01 postfix/smtpd[15870]: 144AAD7601E: client=cpe-174-097-180-223.nc.res.rr.com[174.97.180.223]
    Feb 15 10:47:37 mail01 postfix/cleanup[15874]: 144AAD7601E: message-id=<01cbccfd$bb384390$dfb461ae@info56250>
    Feb 15 10:49:10 mail01 postfix/qmgr[17602]: 144AAD7601E: from=<info56250@remote_domain.com>, size=85288, nrcpt=1 (queue active)
    Feb 15 10:49:10 mail01 postfix/smtp[15907]: 144AAD7601E: to=<roman@mysuperdomain.com>, orig_to=<roman.second@mysuperdomain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=105, delays=105/0/0.01/0.27, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=16299-01, BOUNCE)
    Feb 15 10:49:10 mail01 postfix/qmgr[17602]: 144AAD7601E: removed


    grep C30F6D7602C /var/log/mail.log.1
    Feb 15 10:49:10 mail01 postfix/smtpd[15909]: C30F6D7602C: client=localhost.localdomain[127.0.0.1]
    Feb 15 10:49:10 mail01 postfix/cleanup[15874]: C30F6D7602C: message-id=<VSHO60gsHQwAKd@mail01.mysuperdomain.com>
    Feb 15 10:49:10 mail01 postfix/qmgr[17602]: C30F6D7602C: from=<>, size=4967, nrcpt=1 (queue active)
    Feb 15 10:49:12 mail01 postfix/smtp[16306]: C30F6D7602C: to=<info56250@remote_domain.com>, relay=email-vip.remote_domain.com[153.2.xxx.xxx]:25, delay=2.1, delays=0.03/0.01/0.38/1.7, dsn=2.0.0, status=sent (250 +OK message queued for delivery.)
    Feb 15 10:49:12 mail01 postfix/qmgr[17602]: C30F6D7602C: removed

    How can I disable these NDRs?

    Regards,
    --Roman

  2. #2
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,201
    Rep Power
    56

    Default

    Quote Originally Posted by rokka View Post
    How can I disable these NDRs?
    Search the forums for the word 'backscatter' and try some of the other techniques in the forums and wiki for improving the anti-spam system.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  3. #3
    rokka is offline Member
    Join Date
    Dec 2009
    Posts
    13
    Rep Power
    5

    Default

    Sigh....

    Thanks, I thought there is an option to disables ndr-s somewhere in zimbra management interface.

    Otherwise the zimbra has a quite big security breach with default settings.

    --Roman

  4. #4
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,201
    Rep Power
    56

    Default

    Quote Originally Posted by rokka View Post
    Otherwise the zimbra has a quite big security breach with default settings.
    No, it doesn't. If your server is relaying emails then it's something you would have changed in the server settings - Zimbra by default is not an open relay. Backscatter spam is not a security risk and an NDR is normal for any mail server. As I've said, read the forum threads and wiki articles on what to do about backscatter spam plus other techniques for improving the anti-spam system.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. [SOLVED] Help, I think I am running Zimbra as root!
    By primaxx in forum Administrators
    Replies: 9
    Last Post: 10-06-2010, 11:04 AM
  2. Replies: 9
    Last Post: 03-01-2008, 08:21 PM
  3. [SOLVED] Clamav problem ? What's happening ?
    By aNt1X in forum Installation
    Replies: 23
    Last Post: 02-14-2008, 05:43 AM
  4. Major Issue - 5.0RC2 NE to 5.0GA NE failed
    By DougWare in forum Installation
    Replies: 7
    Last Post: 01-06-2008, 09:56 PM
  5. svn version still won't start
    By kinaole in forum Developers
    Replies: 0
    Last Post: 10-04-2006, 06:47 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •