[sdnog] out going spam

Frank Habicht geier at geier.ne.tz
Wed May 18 09:40:35 SAST 2016


Hi,

I believe you should try to find out how the spam got into your server.
Was someone logged in and generated it on the server?
Were the emails generated from a web-script that generates emails, and
was run by remote users?
Or were the emails submitted into your MTA through SMTP on ports 25 or
587 (or 465) ?
with authentication?
using compromised credentials of one of your users?

I think going through the zimbra logs is the best way forward.


Now:
At my work we have clients of internet connectivity and they run their
own Zimbra server, and some of them also have spamming problems.
Does anyone know the locations of all the relevant log files (MTA,
email) on Zimbra? Because our clients need our help directing them there...

Greetings,
Frank


On 5/18/2016 10:27 AM, Sahlih Shihab wrote:
> Dear All SDNOGER
> Greetings
> I have a big problem with my Zimbra mail server, my mail server send a
> lot spam to out side wold, i do not know how to solve this issue and
> prevent it from happening again, so I need your help
> pleeeeeeeeeeeeeeeeeeeease
> Thank
> 
> -- 
> Sudanese Research and Education Network <http://www.sudren.edu.sd/>
> 	
> 	
> *Salih S. M. Abdelhameed **| Head of Electronics Service Unit *
> Sudanese Research and Education Network *|* Address
> Nile St. *|* University of Khartoum  
> Tel: +2491556620 <callto:+249155662069>71 *|* Mob: +24912
> <callto:+249123788848>3788843
> WebsiteGB <http://www.sudren.edu.sd/>   email
> <mailto:salih.shihab at sudren.edu.sd> 
> <http://www.companysig.com/>
> 
> ------------------------------------------------------------------------
> 
> 
> 
> _______________________________________________
> sdnog mailing list
> sdnog at sdnog.sd
> http://lists.sdnog.sd/mailman/listinfo/sdnog
> 



More information about the sdnog mailing list