Results 1 to 3 of 3

Thread: [SOLVED] Admin account - brute force attempts? Lockout?

Threaded View

  1. #1
    Join Date
    Jun 2011
    Sin City
    Rep Power

    Default [SOLVED] Admin account - brute force attempts? Lockout?


    very new to Zimbra (and *nix) no please forgive any newbie errors or mistakes...

    I have installed, and finally set up a ZCS open source edition on Ubuntu 10.04

    Put it online earlier, created domains, domain aliases, users, forwards -
    most of the basic stuff we would need a mail serve to do...

    Everything working fine, e-mails sent and received for domain and alias domain (very happy)
    decided to enable the "lockout" feature, set the attempts to 3, and time to 15 minutes

    After about 1 hour or so, I decided to check the admin e-mail to see if
    if there were any important notifications sent.

    web mail interface reported an "incorrect password"
    (I know I have the correct password entered)
    web admin interface also showed incorrect password error...

    Q: is this the type of message a user would see if the account is in lockout?

    Q: where in the logs can I look to find out if this was a brute force attempt that caused a lockout (if this was the case)
    Is this a Zimbra log? or is it logged in Linux?

    if the admin account is locked out, how can it be re-set?
    through the root user?
    (was able to ssh to the server, with Ubuntu username / password, and successfully super user'd to root)

    at any rate, got paranoid about this and took the server offline (we have another mail server in use - zimbra is hopefully going to be it's replacement)
    I'd like to learn how to check to see if it is a brute force attack, or hack by examining the logs...

    Oh, finally...

    how exactly does one paste the large amounts of text (i.e. logs) in the forum, where the text pasted has the scroll bars
    next to it?


    Last edited by billinvegas; 06-29-2011 at 12:18 AM. Reason: additional info

Similar Threads

  1. Replies: 0
    Last Post: 05-25-2011, 11:14 AM
  2. Admin account getting locked out
    By pbrunnen in forum Administrators
    Replies: 0
    Last Post: 05-18-2011, 05:54 AM
  3. Allow single account to be domain admin over multiple domains
    By in forum Administrators
    Replies: 2
    Last Post: 03-19-2008, 12:36 PM
  4. restore admin account
    By preem in forum Administrators
    Replies: 2
    Last Post: 01-19-2007, 06:56 AM
  5. Admin Account
    By rmvg in forum Users
    Replies: 4
    Last Post: 09-18-2005, 11:03 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts