Help identifying sender

Help identifying sender

Postby Willy92 » Tue Jun 28, 2011 7:46 pm

We have had a bad week with hammer attacks on our pop3 and webmail. We have locked that down but it appears at least one account has been compromised. We see traffic in the outmail log that shows mail being sent, but need to identify what account is sending it. Is there any easy way, without enabling debug mode in logging. In debug mode re rapidly get overloaded with huge log files.

Maybe the better way to ask is this--> If we feel that an account has been exploited - either by virus or poor password, whats the easiest way to check which accounts are sending which mail - we have a couple hundred accounts on about 30 domains.
Willy92
 
Posts: 8
Joined: Wed May 11, 2011 6:28 am

Re: Help identifying sender

Postby rob » Wed Jun 29, 2011 10:46 am

If you suspect an account has been comprised you need to trace the suspicious mail through the outgoing mail logs. First, examine the contents of the outmail logs and identify which are the suspecious addresses (usually this is revealed by large volumes of recipients being sent to the same domain, often to email services such as yahoo/hotmail/aol/msn/gmail). You then need to identify in the smtp logs those addreses when they first arrived in the mail server, once you have done this, you will now have the source IP addresses and also the option of looking at what user is logging to send these addresses.

In the meantime and to reduce the impact of this type of attack, it is probably worth enablign the mail sending limits in your group settings. This will prevent any one user from sending too many mails via your system.
rob
 
Posts: 415
Joined: Mon Sep 10, 2007 2:34 pm

Re: Help identifying sender

Postby Willy92 » Fri Jul 01, 2011 5:18 pm

Thanks. We had done that, it helped to quickly see that someone was sending way too much mail. Many of the emails sent were returned with 500 series errors, account did not exist...They went back into the outgoing queue and hept getting retried. Is there a way to have bounces from non existant addresses not retried?
Willy92
 
Posts: 8
Joined: Wed May 11, 2011 6:28 am

Re: Help identifying sender

Postby rob » Thu Jul 07, 2011 9:43 am

Presently the outgoing mail system will retry to redeliver bounced mail for the entire queue length regardless of the error message. In the future we will be adding an option to give up on mails that receive permanent error messages but presently there isn't a way to set the system to do this now.
rob
 
Posts: 415
Joined: Mon Sep 10, 2007 2:34 pm


Return to General

Who is online

Users browsing this forum: No registered users and 9 guests

cron