Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-15-2011, 12:12 PM
Intermediate Member
 
Posts: 15
Default Need help with tracking down compromised account(s)

couple accounts i have found are spamming and causing the barracudas to crawl..

i started by deleting the accounts but i still see one of those accounts sending mail out..? doesnt quite make sense to me.

what should be my next steps to identify and close those accounts that are spamming
Reply With Quote
  #2 (permalink)  
Old 07-15-2011, 12:32 PM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

You haven't really given much information about the problem but you might want to start by looking at some of these threads: site:zimbra.com +"compromised account" - Yahoo! Search Results
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 07-15-2011, 12:36 PM
Active Member
 
Posts: 38
Default

watch --interval=1 'tail -n1000 /var/log/auth.log | grep 'auth_zimbra:''

change pass of compromised account should stop spam, also make strong password rules.
Reply With Quote
  #4 (permalink)  
Old 07-15-2011, 12:48 PM
raj raj is offline
Moderator
 
Posts: 768
Default

run the following as ROOT
Quote:
tail -n 100000 /var/log/maillog | grep "sasl_username=" > smtpauthlogins.txt
see which sasl_username=xxxxxxxxxxxx is repeating a lot..that is the compromised account as spammers will log-in tons of times.

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
  #5 (permalink)  
Old 07-15-2011, 01:40 PM
Intermediate Member
 
Posts: 15
Default

Quote:
Originally Posted by Yves Pires View Post
watch --interval=1 'tail -n1000 /var/log/auth.log | grep 'auth_zimbra:''

change pass of compromised account should stop spam, also make strong password rules.
i agree, i even went as far as deleting the acct and i still see spam being sent from that particular account.
Reply With Quote
  #6 (permalink)  
Old 07-15-2011, 01:41 PM
Intermediate Member
 
Posts: 15
Default

Quote:
Originally Posted by raj View Post
run the following as ROOT


see which sasl_username=xxxxxxxxxxxx is repeating a lot..that is the compromised account as spammers will log-in tons of times.

Raj

my /var/log/maillog is empty
Reply With Quote
  #7 (permalink)  
Old 07-15-2011, 02:00 PM
Intermediate Member
 
Posts: 15
Default

also, something common is that each account that seems to be spamming is using ZCO/Outlook for email.

ive had each of the offices scan the owners machine for malware/spyware and they are reporting all the machines are clean now.
Reply With Quote
  #8 (permalink)  
Old 07-15-2011, 02:12 PM
Intermediate Member
 
Posts: 15
Default

excerpt form audit..

2011-07-14 17:23:23,405 INFO [btpool0-3723://localhost/service/soap/AuthRequest] [name=trbrown@mydomain.com;oip=41.220.69.33;ua=zcli ent/6.0.7_GA_2473.RHEL4;] security - cmd=Auth; account=trbrown@mydomain.com; protocol=soap;


seem to be connecting from Nigeria...
Reply With Quote
  #9 (permalink)  
Old 07-15-2011, 11:20 PM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by r3zon8 View Post
i agree, i even went as far as deleting the acct and i still see spam being sent from that particular account.
A deleted account is completely removed from the server (including all email) so it can't be sending email from that account - it doesn't exist.

I guess you have strong password enforcement on your server (if you don't, you should)?
__________________
Regards


Bill

Last edited by phoenix; 07-16-2011 at 10:50 PM..
Reply With Quote
  #10 (permalink)  
Old 07-16-2011, 04:10 PM
Intermediate Member
 
Posts: 15
Default

Quote:
Originally Posted by phoenix View Post
A deleted account is completely removed from the server (including and email) so it can't be sending email from that account - it doesn't exist.
makes sense...but how is it these accounts are still generating outgoing mail?

2011-07-16 07:56:09,359 INFO [btpool0-808://localhost/service/soap/SendMsgRequest] [name=jdolan@mydomain.com;mid=396;oip=74.115.0.36;u a=zclient/6.0.7_GA_2473.RHEL4;] mailop - adding contact llerarhynez@yahoo.com: id=22350, folderId=13, folderName=Emailed Contacts.

excerpt from mailbox.log. heres that account authenticating this morning over zclient. originating ip is an anonymous proxy. they spam from 8am to 5pm then stop.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.