Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-21-2011, 03:18 PM
Junior Member
 
Posts: 9
Default Email Server Sending Spam

Hi,
My zimbra mail server is spamming. I know because of the reports, from daily reports.

The thing is, its an outside account of my domain, a gmail account, i already modify zmmta.cf so it only accept sending emails from my domain, but the spam continue to go out.

I try following the logs, zimbra.log, audit.log and mail.log, but i cant see which is the user account that has been compromised.

Could somebody point me in the rigth direction to determine which user account is being used to spam, any help would be apreciate it.

regards.
Reply With Quote
  #2 (permalink)  
Old 03-21-2011, 06:14 PM
Outstanding Member
 
Posts: 717
Default

In your spam reports, are you being provided with a message-id header that you can search /var/log/zimbra.log for?
__________________
01 Networks, LLC / Cybernetik.net
Zimbra NE and OSS Cloud Hosting
Shared Web Hosting
Consulting Services
Reply With Quote
  #3 (permalink)  
Old 03-21-2011, 06:24 PM
raj raj is offline
Moderator
 
Posts: 768
Default

generally a compromised account's SMTP AUTH is used to relay email (unless your internal network in infected which is in trusted network)

run the following which will spit out all the SMTP AUTH logins
Quote:
tail -n 100000 /var/log/maillog | grep "sasl_username=" > /tmp/smtpauthlogins.txt
A smapmmer's patters will be a lots of logins you can easily see it repeating many times..that account or accounts is your problem.

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
  #4 (permalink)  
Old 03-22-2011, 07:21 AM
Junior Member
 
Posts: 9
Default

Hi,
Thanks raj and Krishopper, i was able to determined the user account compromised.

I already implemented new rules about passwords and how often should the user have to change it.

thanks a lot

regards.
Reply With Quote
  #5 (permalink)  
Old 05-04-2011, 09:27 AM
Senior Member
 
Posts: 54
Default Unable to locate any entries per your post

I do not have any entries for "sasl_username=" in mail.log

I have the same issue with spamming. I can stop it from the queue, but our server contiues to send 1,000's of emails every night around 10pm and 6am local time.
__________________
Bill Rowland MCDST MCSA MCSE
Reply With Quote
  #6 (permalink)  
Old 05-04-2011, 09:37 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by browland View Post
I do not have any entries for "sasl_username=" in mail.log

I have the same issue with spamming. I can stop it from the queue, but our server contiues to send 1,000's of emails every night around 10pm and 6am local time.
You can also look at the daily mail report and determine which account is sending the most mail. You should also consider implementing a more secure password policy.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.