Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 10-31-2011, 09:14 AM
Member
 
Posts: 10
Default

I have seen these messages before, but I believe it is more serious than we take it for. As far as it goes for my situation I had investigated and found that this is a hack attempt to my admin console. My question is does anyone know if there is a vulnerability in the zimbra system where someone can login to the zimbra admin although the port is blocked? I have blocked the admin port from being accessed from outside our network however the log is showing that an outside IP is trying to access this port.
Reply With Quote
  #12 (permalink)  
Old 10-31-2011, 09:43 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by zeirum View Post
I have seen these messages before, but I believe it is more serious than we take it for. As far as it goes for my situation I had investigated and found that this is a hack attempt to my admin console. My question is does anyone know if there is a vulnerability in the zimbra system where someone can login to the zimbra admin although the port is blocked?
That would be a vulnerability in your firewall not Zimbra.

Quote:
Originally Posted by zeirum View Post
I have blocked the admin port from being accessed from outside our network however the log is showing that an outside IP is trying to access this port.
If the port is blocked by your firewall then it's not possible that an external source can connect directly to your Zimbra server admin port.
__________________
Regards


Bill
Reply With Quote
  #13 (permalink)  
Old 10-31-2011, 10:45 AM
Member
 
Posts: 10
Default

Ok yeah I've found another forum with someone experiencing similar issues.

honey auth failed: authentication failed for honey

And they mention that the attacker is trying to get through using the soap interface. As I have mention I just wanted to know what's the possible threat from this kind of attack and if anyone is aware of this.

I am assuming and hoping that nothing can happen once the attacker doesn't have valid credentials.
Reply With Quote
  #14 (permalink)  
Old 10-31-2011, 11:24 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by zeirum View Post
Ok yeah I've found another forum with someone experiencing similar issues.

honey auth failed: authentication failed for honey

And they mention that the attacker is trying to get through using the soap interface.
That wasn't quite the information you gave in your first post.

Quote:
Originally Posted by zeirum View Post
As I have mention I just wanted to know what's the possible threat from this kind of attack and if anyone is aware of this.
Yes, everyone that runs a server that's visible on the internet is aware of 'attacks' against the server - it's called life.

Quote:
Originally Posted by zeirum View Post
I am assuming and hoping that nothing can happen once the attacker doesn't have valid credentials.
Of course nothing can happen if they don't have valid credentials. It would also depend on what protection you have on your server (or network), whether you have strong passwords enforced (you should have) on the Zimbra server and whether you're on the most recent version of Zimbra.

You should update your forum profile with the output of the following command:

Code:
zmcontrol -v
__________________
Regards


Bill
Reply With Quote
  #15 (permalink)  
Old 10-31-2011, 07:48 PM
Junior Member
 
Posts: 6
Default

Quote:
Originally Posted by zeirum View Post
Ok yeah I've found another forum with someone experiencing similar issues.

honey auth failed: authentication failed for honey

And they mention that the attacker is trying to get through using the soap interface. As I have mention I just wanted to know what's the possible threat from this kind of attack and if anyone is aware of this.

I am assuming and hoping that nothing can happen once the attacker doesn't have valid credentials.
Welcome to real world my friend..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.