Search found 83 matches

by GlooM
Fri Aug 23, 2019 6:50 am
Forum: Administrators
Topic: Reject blank "to"
Replies: 0
Views: 323

Reject blank "to"

Hello! -)!

How can I tune anti-spam filters to block all letters with blank field "to" (to=<>).
by GlooM
Thu Aug 08, 2019 7:08 pm
Forum: Administrators
Topic: New type of spammers
Replies: 2
Views: 328

Re: New type of spammers

Is there any way to protect against these connections from other servers to mine?
by GlooM
Thu Aug 08, 2019 6:15 pm
Forum: Administrators
Topic: New type of spammers
Replies: 2
Views: 328

New type of spammers

Hello everyone! Since last month I have faced new types to spam. I administer the server with ~2000 users and they often receive fishing emails. Previously, compromised accounts were used to send spam via smtp-bots. Hacked accounts were identified by analyzing zimbra logs (sasl_username parameter - ...
by GlooM
Fri Apr 19, 2019 1:25 pm
Forum: Administrators
Topic: zimbra not listen in 443 port
Replies: 6
Views: 5029

Re: zimbra not listen in 443 port

Yes, there is a files zmswatch and zmswatch.out virustotal says its a bitcoin miner As I understand it, the hacking technique is the same. zmswatch - miner, Ajax.jsp - shell? Last patch is required to solve the problem. But this is not the same as described here: https://lorenzo.mile.si/zimbra-cve-...
by GlooM
Thu Apr 18, 2019 7:03 pm
Forum: Administrators
Topic: zimbra not listen in 443 port
Replies: 6
Views: 5029

Re: zimbra not listen in 443 port

seryoga_p wrote:fixed
1. upgrade to 8.7.11
2. Patch P10
now everything is working


Hello Seryoga -)!
Please, check this question: viewtopic.php?f=15&t=66031&p=289821#p289821
I think I was hacked the same way. Do you have a file : /opt/zimbra/log/zmswatch?
by GlooM
Thu Apr 18, 2019 7:00 pm
Forum: Administrators
Topic: zmswatch high cpu usage
Replies: 8
Views: 12240

Re: zmswatch high cpu usage

Update!

viewtopic.php?t=66005

Ajax.jsp - The content of the file is exactly like the author of the question!
by GlooM
Thu Apr 18, 2019 2:59 pm
Forum: Administrators
Topic: zmswatch high cpu usage
Replies: 8
Views: 12240

Re: zmswatch high cpu usage

Unfortunately, downtime is critical. Will it be enough to install Patch-11 for version 8.7.11? I read this instructions : https://lorenzo.mile.si/zimbra-cve-2019-9670-being-actively-exploited-how-to-clean-the-zmcat-infection/961/ And find modified file: 93393769 4 -rw-r----- 1 zimbra zimbra 332 apr ...
by GlooM
Thu Apr 18, 2019 2:37 pm
Forum: Administrators
Topic: zmswatch high cpu usage
Replies: 8
Views: 12240

Re: zmswatch high cpu usage

I can't be certain as I haven't run that version of ZCS for a long time but I doubt that was it's original location or even that name. The file I have on my current ZCS 8.8.12 is in this folde and, as you can see, it's named differently: Thanks for the answer! I see that this file was created on Ap...
by GlooM
Thu Apr 18, 2019 2:17 pm
Forum: Administrators
Topic: zmswatch high cpu usage
Replies: 8
Views: 12240

Re: zmswatch high cpu usage

I want to add information.
The zmswatch process was launched from /opt/zimbra/log/zmswatch

Is that normal? Binary file placed in logs folder?
by GlooM
Thu Apr 18, 2019 6:42 am
Forum: Administrators
Topic: zmswatch high cpu usage
Replies: 8
Views: 12240

zmswatch high cpu usage

Hello! Release 8.7.11.GA.1854.UBUNTU16.64 UBUNTU16_64 FOSS edition. Yesterday, I noticed that a virtual machine consumes a lot of CPU resources. When executing a command "top" in operating system, I see: "7209 zimbra 20 0 420652 11772 1128 S 399,7 0,0 2342:20 zmswatch". This is 4...

Go to advanced search