Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-02-2011, 12:30 PM
Starter Member
 
Posts: 1
Default Hacked account sending spam

Hi,

We had a user account sending spam through our Zimbra Server 7 server. The server is configured to block account after 10 unsucessully login attempt, but the cracker got the password yet.

The messages sent by the spammer had sender with different domain configured in Zimbra. Is there any way to block the sending of messages whose sender's domain is not configured in Zimbra?

Following is the log generated in the spammer login:

Quote:
zimbra.log
Jun 1 00:17:20 mailserver postfix/smtpd[1075]: connect from unknown[189.104.113.254]
Jun 1 00:17:21 mailserver saslauthd[28352]: zmauth: authenticating against elected url 'https://mailserver.mydomain.com:7071/service/admin/soap/' ...
Jun 1 00:17:21 mailserver saslauthd[28352]: zmpost: url='https://mailserver.mydomain.com:7071/service/admin/soap/' returned buffer->data='<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope"><soap:Header><context xmlns="urn:zimbra"><change token="2393"/></context></soap:Header><soap:Body><AuthResponse xmlns="urn:zimbraAccount"><authToken>0_4a602a3a97f 18a0a88915d014f8da93c32b48002_69643d33363a32313366 393536622d653039622d346437342d626531642d3233363037 366661386665383b6578703d31333a31333037303731303431 3336393b76763d313a313b747970653d363a7a696d6272613b </authToken><lifetime>172800000</lifetime><skin>carbon</skin></AuthResponse></soap:Body></soap:Envelope>', hti->error=''
Jun 1 00:17:21 mailserver saslauthd[28352]: auth_zimbra: spamuser auth OK
Jun 1 00:17:21 mailserver postfix/smtpd[1075]: E737B778001: client=unknown[189.104.113.254], sasl_method=PLAIN, sasl_username=spamuser

mailbox.log
2011-06-01 00:17:21,327 INFO [btpool0-255://mailserver.mydomain.com:7071/service/admin/soap/] [ip=192.168.0.235;] soap - AuthRequest

audit.log
2011-06-01 00:17:21,369 INFO [btpool0-255://mailserver.mydomain.com:7071/service/admin/soap/] [name=spamuser@mydomain.com;ip=192.168.0.235;] security - cmd=Auth; account=spamuser@mydomain.com; protocol=soap;
Thanks,

Rodrigo
Reply With Quote
  #2 (permalink)  
Old 06-02-2011, 12:43 PM
raj raj is offline
Moderator
 
Posts: 768
Default

you should research about the following

Quote:
reject_sender_login_mismatch
Reject the request when $smtpd_sender_login_maps specifies an owner for the MAIL FROM address, but the client is not (SASL) logged in as that MAIL FROM address owner; or when the client is (SASL) logged in, but the client login name doesn't own the MAIL FROM address according to $smtpd_sender_login_maps.

man page: Postfix Configuration Parameters
enableing it may affact ALIASES to send email thru SMTP AUTH, so please test and research before you apply.
Will fix spammer problem for sure but it mat affact other things

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.