Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-19-2011, 09:48 AM
Intermediate Member
 
Posts: 15
Default Helping to prevent future phishing attacks

we recently had a compromised account that was being used to send out spam. shortly after, that account was used to send phishing emails to other local users on our domain therefore allowing the attacker to gather even more valid credentials of good accounts.

the phishing attacked asked the users to verify account information by following a link and entering their credentials. in the body of the message the URL appeared as a known/good URL: http://mail.mydomain.com , but the actual link the users were taken to was something much different.

is it possible to assign a spam score to messages that are found to have these misleading links in the body so that they are tagged as spam and not delivered? and/or how to best prevent these attacks?
Reply With Quote
  #2 (permalink)  
Old 08-19-2011, 10:24 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by r3zon8 View Post
we recently had a compromised account that was being used to send out spam. shortly after, that account was used to send phishing emails to other local users on our domain therefore allowing the attacker to gather even more valid credentials of good accounts.
You need to implement Strong Password policy, you can do that in the Admin UI.

Quote:
Originally Posted by r3zon8 View Post
the phishing attacked asked the users to verify account information by following a link and entering their credentials. in the body of the message the URL appeared as a known/good URL: http://mail.mydomain.com , but the actual link the users were taken to was something much different.
You're never going to stop 100% of this type of email, this is essentially a user education problem.

Quote:
Originally Posted by r3zon8 View Post
is it possible to assign a spam score to messages that are found to have these misleading links in the body so that they are tagged as spam and not delivered? and/or how to best prevent these attacks?
How can you determine these links are misleading? Use RBLs and some of the checks that are already in the anti-spam system, check the wiki for details of what can be done.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.