Hola
Muchas gracias por tus comentarios. Le comentare al administrador de
la red que revise todo los equipos. He ejecutado este comando.
tail -f /var/log/zimbra.log | grep post y no paran de salirme estos
mensajes.Creo que me esta atacando desde una maquina de mi red, y la
duda que tengo es si estoy enviando SPAM. Me pierdo un poco con este
log
Muchisimas gracias, ire aplicando lo que me dices
connect from unknown[192.168.71.242]
Aug 5 19:30:23 postaz saslauthd[10414]: zmauth: authenticating
against elected url '
https://o..a.org:7071/service/admin/soap/' ...
Aug 5 19:30:23 postaz saslauthd[10414]: zmpost: url='
https://o..a.org:
7071/service/admin/soap/' returned buffer->data='<soap:Envelope
xmlns:soap="
http://www.w3.org/2003/05/soap-
envelope"><soap:Header><context xmlns="urn:zimbra"/></
soap:Header><soap:Body><soap:Fault><soap:Code><soap:Value>soap:Sender</
soap:Value></soap:Code><soap:Reason><soap:Text>authentication failed
for p..sa3</soap:Text></soap:Reason><soap:Detail><Error
xmlns="urn:zimbra"><Code>account.AUTH_FAILED</
Code><Trace>com.zimbra.cs.account.AccountServiceException
$AuthFailedServiceException: authentication failed for p..a3
ExceptionId:btpool0-7://o..
a.org:7071/service/admin/soap/:
1281029423413:31d3d76e17d11e5d Code:account.AUTH_FAILED ^Iat
com.zimbra.cs.account.AccountServiceException
$AuthFailedServiceException.AUTH_FAILED(AccountServiceException.java:
130) ^Iat com.zimbra.cs.account.AccountServiceException
$AuthFailedServiceException.AUTH_FAILED(AccountServiceException.java:
126) ^Iat com.zimbra.cs.account.auth.AuthMechanism$ZimbraAut
Aug 5 19:30:23 postaz saslauthd[10414]: auth_zimbra: p...a3 auth
failed: authentication failed for p..a3
Aug 5 19:30:23 postaz saslauthd[10414]: do_auth : auth
failure: [user=po..a3] [service=smtp] [realm=] [mech=zimbra]
[reason=Unknown]
Aug 5 19:30:23 postaz postfix/smtpd[7405]: warning:
unknown[192.168.71.242]: SASL LOGIN authentication failed:
authentication failure
Aug 5 19:35:46 postaz postfix/smtpd[12404]: lost connection after
AUTH from unknown[192.168.71.242]
Aug 5 19:35:46 postaz postfix/smtpd[12404]: disconnect from
unknown[192.168.71.242]
==========
ug 5 19:39:59 postaz postfix/smtpd[17418]: connect from
unknown[123.21.115.134]
Aug 5 19:40:01 postaz postfix/smtpd[17418]: 1712B142083:
client=unknown[123.21.115.134]
Aug 5 19:40:01 postaz zimbramon[17430]: 17430:info: 2010-08-05
19:40:01, QUEUE: 0 0
Aug 5 19:40:02 postaz postfix/cleanup[17426]: 1712B142083: message-
id=<
2010080517400...@otola.org>
Aug 5 19:40:02 postaz postfix/qmgr[10405]: 1712B142083:
from=<a...i@o..
a.org>, size=6464, nrcpt=1 (queue active)
Aug 5 19:40:02 postaz amavis[8497]: (08497-09) ESMTP::10024 /opt/
zimbra/data/amavisd/tmp/amavis-20100805T173642-08497: <a...i@o..
a.org>
-> <a...i@o..
a.org> SIZE=6464 BODY=8BITMIME Received: from
otola.org
([127.0.0.1]) by localhost (
otola.org [127.0.0.1]) (amavisd-new, port
10024) with ESMTP for <a...i@o..
a.org>; Thu, 5 Aug 2010 19:40:02
+0200 (CEST)
Aug 5 19:40:02 postaz amavis[8497]: (08497-09) Checking: K8H7DPqn1P8Y
[123.21.115.134] <a...i@o..
a.org> -> <a...i@o..
a.org>
Aug 5 19:40:02 postaz postfix/smtpd[17418]: disconnect from
unknown[123.21.115.134]
Aug 5 19:40:03 postaz postfix/smtpd[17798]: connect from
localhost.localdomain[127.0.0.1]
Aug 5 19:40:03 postaz postfix/smtpd[17798]: D332F1420CB:
client=localhost.localdomain[127.0.0.1]
Aug 5 19:40:03 postaz postfix/cleanup[17426]: D332F1420CB: message-
id=<
2010080517400...@otola.org>
Aug 5 19:40:03 postaz postfix/smtpd[17798]: disconnect from
localhost.localdomain[127.0.0.1]
Aug 5 19:40:03 postaz postfix/qmgr[10405]: D332F1420CB:
from=<a...i@o..
a.org>, size=7213, nrcpt=1 (queue active)
Aug 5 19:40:03 postaz amavis[8497]: (08497-09) FWD via SMTP:
<a...i@o..
a.org> -> <a...i@o..
a.org>,BODY=8BITMIME 250 2.0.0 Ok,
id=08497-09, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as
D332F1420CB
Aug 5 19:40:03 postaz amavis[8497]: (08497-09) Passed SPAMMY,
[123.21.115.134] [123.21.115.134] <a...i@o..
a.org> ->
<a...i@o..
a.org>, Message-ID: <
2010080517400...@otola.org>,
mail_id: K8H7DPqn1P8Y, Hits: 13.123, size: 6459, queued_as:
D332F1420CB, 1430 ms
Aug 5 19:40:03 postaz postfix/smtp[17696]: 1712B142083:
to=<a...i@o..
a.org>, relay=127.0.0.1[127.0.0.1]:10024, delay=3.4,
delays=1.9/0/0/1.4, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=08497-09,
from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as D332F1420CB)
Aug 5 19:40:03 postaz postfix/qmgr[10405]: 1712B142083: removed
Aug 5 19:40:04 postaz postfix/lmtp[17799]: D332F1420CB:
to=<a...i@o..
a.org>, relay=
otola.org[10.100.100.25]:7025, delay=0.22,
delays=0.02/0.08/0.03/0.09, dsn=2.1.5, status=sent (250 2.1.5 Delivery
OK)
Aug 5 19:40:04 postaz postfix/qmgr[10405]: D332F1420CB: removed
Aug 5 19:40:06 postaz zmmailboxdmgr[17902]: status requested
Aug 5 19:40:06 postaz zmmailboxdmgr[17902]: status OK
Aug 5 19:40:23 postaz postfix/anvil[7429]: statistics: max connection
rate 2/60s for (smtp:213.177.195.111) at Aug 5 19:32:57
Aug 5 19:40:23 postaz postfix/anvil[7429]: statistics: max connection
count 1 for (smtp:192.168.71.242) at Aug 5 19:30:23
Aug 5 19:40:23 postaz postfix/anvil[7429]: statistics: max cache size
1 at Aug 5 19:30:23
Aug 5 19:40:56 postaz zmmailboxdmgr[18935]: status requested
Aug 5 19:40:56 postaz zmmailboxdmgr[18935]: status OK
Aug 5 19:40:56 postaz zmmailboxdmgr[19000]: status requested
Aug 5 19:40:56 postaz zmmailboxdmgr[19000]: status OK
Aug 5 19:40:59 postaz postfix/smtpd[17418]: warning:
94.181.32.1:
hostname
net32.181.94-1.chel.ertelecom.ru verification failed: Name or
service not known
Aug 5 19:40:59 postaz postfix/smtpd[17418]: connect from
unknown[94.181.32.1]
Aug 5 19:40:59 postaz postfix/smtpd[17418]: NOQUEUE: reject: RCPT
from unknown[94.181.32.1]: 550 5.1.1 <al...i@o..
a.org>: Recipient
address rejected:
otola.org; from=<
ala...@otola.org>
to=<
ala...@otola.org> proto=SMTP
helo=<
net32.181.94-1.chel.ertelecom.ru>
Aug 5 19:40:59 postaz postfix/smtpd[17418]: lost connection after
RCPT from unknown[94.181.32.1]
Aug 5 19:40:59 postaz postfix/smtpd[17418]: disconnect from
unknown[94.181.32.1]
Aug 5 19:41:24 postaz postfix/smtpd[17418]: connect from
a95-93-67-176.cpe.netcabo.pt[95.93.67.176]
Aug 5 19:41:24 postaz postfix/smtpd[17418]: NOQUEUE: reject: RCPT
from
a95-93-67-176.cpe.netcabo.pt[95.93.67.176]: 554 5.7.1 Service
unavailable; Client host [95.93.67.176] blocked using sbl-
xbl.spamhaus.org;
http://www.spamhaus.org/query/bl?ip=95.93.67.176;
from=<
teguqi...@netcabo.pt> to=<
ocasi...@otola.org> proto=ESMTP
helo=<
netcabo.pt>
Aug 5 19:41:24 postaz postfix/smtpd[17418]: disconnect from
a95-93-67-176.cpe.netcabo.pt[95.93.67.176]
Aug 5 19:41:44 postaz slapd[4827]: slap_queue_csn: queing 0x429f75d0
20100805174144.101724Z#000000#000#000000
Aug 5 19:41:44 postaz slapd[4827]: slap_graduate_commit_csn: removing
0x4399ab0 20100805174144.101724Z#000000#000#000000
Aug 5 19:42:06 postaz zmmailboxdmgr[19783]: status requested
Aug 5 19:42:06 postaz zmmailboxdmgr[19783]: status OK
Aug 5 19:42:15 postaz zmmailboxdmgr[20367]: status requested
Aug 5 19:42:15 postaz zmmailboxdmgr[20367]: status OK
Aug 5 19:42:16 postaz zmmailboxdmgr[20432]: status requested
Aug 5 19:42:16 postaz zmmailboxdmgr[20432]: status OK
Aug 5 19:42:22 postaz slapd[4827]: slap_queue_csn: queing 0x410b25d0
20100805174222.802371Z#000000#000#000000
Aug 5 19:42:22 postaz slapd[4827]: slap_graduate_commit_csn: removing
0x4399300 20100805174222.802371Z#000000#000#000000