Control Spamming activity on existing server and Migration to new parallel server

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
nuc_infra
Posts: 11
Joined: Thu Apr 22, 2021 6:43 am

Control Spamming activity on existing server and Migration to new parallel server

Post by nuc_infra »

Need following help:

Request 1:
I have my old server xyz.in on Linode (cloud) instance and has old versions Zimbra 8.0 on Ubuntu 12. I have about 300 IDs. I have recently identified that the server is hacked and is used to spam emails. Hacker his creating Admin User IDs, might be through a script and sending emails using our server. Email IDs such as googlepromotion, googleawardwinning and etc.

Could someone help me to stop this permanently.

Request 2:
I have created a parallel instance with updated ZCS 8.8.15 on Ubuntu 18 Lts. I have setup the server with same domain name as I have older one but tagged to new domain name for testing purpose. After I shutdown the older server, I could send emails internally, I could send emails from external to internal, but I could not send emails from internal to external. Ex: i could send emails from xyz.in to xyz.in, i could send email from gmail.com to xyz.in but i could not send xyz.in to gmail.com

Could someone help me in fixing this issue.
Also let me know, is there any way I could run both the email servers parallely to avoid downtime to user as such.

Getting following bounce back email when I am sending email to external domain:
host 127.0.0.1[127.0.0.1] said: 554 5.4.0 id=17935-02 -
Rejected by next-hop MTA on relaying, from MTA(smtp:[127.0.0.1]:10025): 554
5.4.0 Error: too many hops (in reply to end of DATA command)
phoenix
Ambassador
Ambassador
Posts: 27278
Joined: Fri Sep 12, 2014 9:56 pm
Location: Liverpool, England

Re: Control Spamming activity on existing server and Migration to new parallel server

Post by phoenix »

nuc_infra wrote: I have recently identified that the server is hacked and is used to spam emails. Hacker his creating Admin User IDs, might be through a script and sending emails using our server. Email IDs such as googlepromotion, googleawardwinning and etc.
That's the very reason you should keep your server updated and you should keep any eye on the forums for notifications of any problems.

My advice would be to look at the ZEXTRAS site and take a look at how to migrate to a new server with the ZEXTRAS Backup and that will tell you all you need to know, it's a paid for product but you do get a thirty days trial. ;) The one thing I'm not sure about is whether your old version of Ubuntu is supported but it should have that on the site as well.
Regards

Bill

Rspamd: A high performance spamassassin replacement

Per ardua ad astra
nuc_infra
Posts: 11
Joined: Thu Apr 22, 2021 6:43 am

Re: Control Spamming activity on existing server and Migration to new parallel server

Post by nuc_infra »

Thank you. Do we have any other solution other than zextras. I just need help in checking the configuration part or on resolving the error while sending external mails. Need to fix this little urgent.
nuc_infra
Posts: 11
Joined: Thu Apr 22, 2021 6:43 am

Re: Control Spamming activity on existing server and Migration to new parallel server

Post by nuc_infra »

I have created a parallel instance with updated ZCS 8.8.15 on Ubuntu 18 Lts. I have setup the server with same domain name as I have older one but tagged to new domain name for testing purpose. After I shutdown the older server, I could send emails internally, I could send emails from external to internal, but I could not send emails from internal to external. Ex: i could send emails from xyz.in to xyz.in, i could send email from gmail.com to xyz.in but i could not send xyz.in to gmail.com

Could someone help me in fixing this issue.
Also let me know, is there any way I could run both the email servers parallely to avoid downtime to user as such.

Getting following bounce back email when I am sending email to external domain:
host 127.0.0.1[127.0.0.1] said: 554 5.4.0 id=17935-02 -
Rejected by next-hop MTA on relaying, from MTA(smtp:[127.0.0.1]:10025): 554
5.4.0 Error: too many hops (in reply to end of DATA command)

need help in this please...
Post Reply