Results 1 to 5 of 5

Thread: My Zimbra Sending Spam to The world

  1. #1
    Mido3mad is offline Active Member
    Join Date
    Mar 2010
    Location
    Egypt
    Posts
    41
    Rep Power
    5

    Default My Zimbra Sending Spam to The world

    Hi all,

    the problem is 1 of our mail account has been hacked and we see this account sending spam and some domains block us from sending mails to it

    we change the password and locked the account

    but there is anther account called aa@bb.mydomain.com still sending spam --

    I dont have username called aa or domain called bb

    and I test my mail system and its not open relay


    can Anybody help me please what is the reason of that?

  2. #2
    Yves Pires is offline Senior Member
    Join Date
    Jun 2011
    Posts
    52
    Rep Power
    4

    Default

    check /opt/zimbra/log/audit.log

    you need to check which account have too many logins entries even at 0:00 to 6:00 am

  3. #3
    Mido3mad is offline Active Member
    Join Date
    Mar 2010
    Location
    Egypt
    Posts
    41
    Rep Power
    5

    Default

    I Check this audit and found hacked account was sending messages and I Locked this account

    the problem is that zimbra sending spam from accounts not listed in my list of accounts ,strange accounts like aa@bb.mydomain.com ( i dont have bb domain )

    us@mydomain.com ( i dont have this account in my list )

    So they dont login to the mail and i dont know how they sending messages without be from my users

  4. #4
    shanxt is offline Active Member
    Join Date
    Jul 2012
    Location
    Bangalore, India
    Posts
    34
    Rep Power
    3

    Default

    If the logs are showing that the spam is originating from your server, then it's definitely being sent by the server. It's possible that they are spoofing the header messages of the emails. To check this, search for the 'sasl_username' keyword, or try reading an email from the queue and analyse its header files. Also find the IP from your Zimbra or firewall logs, and ban the IP.

    To read the mail from queue, take a look at the 'postcat' command.

  5. #5
    Mido3mad is offline Active Member
    Join Date
    Mar 2010
    Location
    Egypt
    Posts
    41
    Rep Power
    5

    Default

    Thanks for you answer
    The Problem has been solved by

    Going to /opt/zimbra/conf/zmmta.cf

    and change smtpd_reject_recipents value to yes ( after any upgrade you should do the same )
    then restart postfix and the spam stop now

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 4
    Last Post: 06-09-2012, 09:43 PM
  2. Barracuda spam filter not sending to Zimbra
    By digidt in forum Administrators
    Replies: 3
    Last Post: 04-11-2012, 10:05 AM
  3. Help... my Zimbra is sending SPAM to the world!!!
    By dwidman in forum Administrators
    Replies: 3
    Last Post: 06-21-2010, 11:45 PM
  4. ZIMBRA sending spam
    By koby in forum Installation
    Replies: 3
    Last Post: 09-29-2006, 07:22 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •