Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 07-10-2007, 08:27 PM
Active Member
 
Posts: 39
Default

So what you are telling me is that anyone can spam us by telnet'ing into our domain, running code that email users only our domain and there is nothing I can do about it?
Reply With Quote
  #12 (permalink)  
Old 07-10-2007, 08:37 PM
Former Zimbran
 
Posts: 5,606
Default

Quote:
Originally Posted by OfMacAndMen View Post
So what you are telling me is that anyone can spam us by telnet'ing into our domain, running code that email users only our domain and there is nothing I can do about it?
Well, if your intention is to block port 25, you'll never get mail.

SPAM is analyzed based upon factors. You message was short, and didn't include any spam characteristics.

You can telnet to our server, yahoo's, Microsoft's, Apple's, etc. You can't block telnet access to port 25. That's how SMTP works.

Once the message is received, is when it's judged to be spam.
Reply With Quote
  #13 (permalink)  
Old 07-10-2007, 08:40 PM
Active Member
 
Posts: 39
Default

What stop hackers & spammer from using this to flood your network with spam or DOS attacks?
Reply With Quote
  #14 (permalink)  
Old 07-10-2007, 08:45 PM
Advanced Member
 
Posts: 193
Default

Quote:
Originally Posted by OfMacAndMen View Post
So what you are telling me is that anyone can spam us by telnet'ing into our domain, running code that email users only our domain and there is nothing I can do about it?
OfMacAndMen, I humbly suggest that you conduct a little audit of your network by sniffing what is being done by each workstation in your network. Some of your workstations may have been acting as a redirector (infected by some sort of intelligent trojan, like that from ISOhunt) that is why you appear to have an open relay. (i'm not exactly saying that you have this, but it won't hurt to try it.)

We have a similar case in one of our clients and it gave us pain why such a volume of spam even open relay is off and bandwidth activity is very high.

When we found out and identified those workstation, we isolated them from the network, and everything normalized. (And we re-formatted those stations tagged as redirector).

Hope this helps.
Reply With Quote
  #15 (permalink)  
Old 07-10-2007, 08:46 PM
Advanced Member
 
Posts: 193
Default

Quote:
Originally Posted by OfMacAndMen View Post
What stop hackers & spammer from using this to flood your network with spam or DOS attacks?
Did you make your telnet test outside of your network, as in totally outside of your network?
Reply With Quote
  #16 (permalink)  
Old 07-10-2007, 08:48 PM
Active Member
 
Posts: 39
Default

Yes. not even the same ISP
Reply With Quote
  #17 (permalink)  
Old 07-10-2007, 08:48 PM
Former Zimbran
 
Posts: 5,606
Default

That's where the DNS checks section of the Zimbra admin comes in. Things like reverse lookup, and EHLO help to stop those type of things.

Mail servers are multi-threaded, which means that more than one server can connect to port 25 at a time.

If you have those DNS Checks, you reduce the chance of spam getting in.

As far as DDoS attacks, it would take a lot (I mean a lot) to take a mail server down.

It should be noted that this behavior is not unique to Zimbra. The reasons you list are exactly why many people are not favorous of SMTP. . but that be the way it be.

See this for more info:
Simple Mail Transfer Protocol - Wikipedia, the free encyclopedia
Reply With Quote
  #18 (permalink)  
Old 07-10-2007, 08:51 PM
Former Zimbran
 
Posts: 5,606
Default

Guys-
It's not an open relay. If it were, abuse net would say it.

If the e-mail rcpt to is on the server, the mail will be delivered. That's how it works.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.