GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » Abused: Full queue folder & ban IP question
Abused: Full queue folder & ban IP question [message #105968] Sun, 01 September 2013 17:01 Go to next message
Spacey is currently offline  Spacey
Messages: 143
Registered: July 2011
Hi,

unfortunately one of my kerio mailaccounts has been bruteforced, hacked or whateverd - lots of spam was sended via that auth'ed account. I changed the password and now no more new spam is accepted. Already hardened my SMTP sending rules few minutes ago. Got a few questions:

1) Now I see in my security log the SMTP attempts from the bad guys -> mostly russian or polish IPs. Is there any chance to ban them within kerio? So that they're not able even to try to login? Didn't find anything...

2) My "/usr/local/kerio/mailserve/store/queue/" subfolders were full of spam - I moved the old queue directory to a save location and created a new one so Kerio can work with a clean queue folder. Kerio itself seems to work fine.

-> Problem was & is: I wasn't able to view the queue via the webinterface (it loaded the "show queue" screen forever). Is there any tool to view and handle a large queue folder? I want to view that folder any check out if there's anything importand non spam in it.

Thanks & Regards!
Re: Abused: Full queue folder & ban IP question [message #105972 is a reply to message #105968] Sun, 01 September 2013 21:07 Go to previous messageGo to next message
camisy is currently offline  camisy
Messages: 119
Registered: August 2012
re 1: I don't think this is necessary, if you block a specific IP spammers will simply use another one of their proxy or zombie PCs. Should your connect be running on Linux take a look at fail2ban if you feel better then.
Re: Abused: Full queue folder & ban IP question [message #105976 is a reply to message #105972] Sun, 01 September 2013 22:46 Go to previous messageGo to next message
Spacey is currently offline  Spacey
Messages: 143
Registered: July 2011
It's an OSX Server... OK, fail2ban would run on that one as well. Thanks for the idea!

For 2) I'll try to create a new user (since I don't want to sync/imap all the spam on my client) and create there a new folder and put all the eml's into it. Maybe that'll work - tomorrow...
Re: Abused: Full queue folder & ban IP question [message #105989 is a reply to message #105976] Mon, 02 September 2013 10:08 Go to previous messageGo to next message
Spacey is currently offline  Spacey
Messages: 143
Registered: July 2011
Just putting the .eml files into an user directory doesn't work unfortunately.

Besides another question:

Is there an option that the server only allows to send emails from addresses that exist on the server?

Example: xyz<_at_>domain.com does not exist either as an username or an email alias and so Kerio won't allow to use that address as a "sent from"?
Re: Abused: Full queue folder & ban IP question [message #105990 is a reply to message #105968] Mon, 02 September 2013 10:14 Go to previous messageGo to next message
camisy is currently offline  camisy
Messages: 119
Registered: August 2012
Sender anti spoofing will come in 8.2: http://download.kerio.com/dwn/beta-connect/connect-8.2.0-169 4/kerio-connect-notes-en-8.2.0-1694-b3.pdf
Re: Abused: Full queue folder & ban IP question [message #105991 is a reply to message #105989] Mon, 02 September 2013 10:15 Go to previous messageGo to next message
Pavel Dobry (Kerio) is currently offline  Pavel Dobry (Kerio)
Messages: 2057
Registered: October 2003
Location: Czech Republic
Spacey wrote on Mon, 02 September 2013 10:08


Is there an option that the server only allows to send emails from addresses that exist on the server?

Example: xyz<_at_>domain.com does not exist either as an username or an email alias and so Kerio won't allow to use that address as a "sent from"?

Yes. There is such option in upcoming Kerio Connect 8.2.


Re: Abused: Full queue folder & ban IP question [message #105992 is a reply to message #105991] Mon, 02 September 2013 10:18 Go to previous message
Spacey is currently offline  Spacey
Messages: 143
Registered: July 2011
Great to hear!
Guess 8.2 isn't far away when it's already b3 state....
Previous Topic: Internal only Out of Office
Next Topic: no webmail address autofill
Goto Forum:
  


Current Time: Tue May 30 14:23:38 CEST 2023

Total time taken to generate the page: 0.05611 seconds