Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


MichaelNZ

1594 posts

Uber Geek
+1 received by user: 485

Trusted
Net Trust Ltd

#248336 20-Mar-2019 13:52
Send private message

What systems are people using to detect and track down spamming accounts (usually compromised) on a multi-user mail server?





WFH Linux Systems and Networks Engineer in the Internet industry | Specialising in Mikrotik | APNIC member | Open to job offers | ZL2NET


Create new topic
danfaulknor
974 posts

Ultimate Geek
+1 received by user: 533

Trusted
Prodigi
Subscriber

  #2202514 20-Mar-2019 17:57
Send private message

Generally, I'd do this with outbound spam filtering. Use the reporting functionality to get counts of spam per user. You might even be able to alert if the rate goes above a certain number.





they/them

 

Prodigi - Optimised IT Solutions
WebOps/DevOps, Managed IT, Hosting and Internet/WAN.




vulcannz
436 posts

Ultimate Geek
+1 received by user: 136
Inactive user


  #2202863 21-Mar-2019 14:16
Send private message

This the difference between an simple anti-spam service and a complete Email Security service. Vendors like Barracude, Fortinet, and Sonicwall do some very good solutions, not to pricey and cloud based.


gbwelly
1263 posts

Uber Geek
+1 received by user: 776


  #2202864 21-Mar-2019 14:23
Send private message

MichaelNZ:

 

What systems are people using to detect and track down spamming accounts (usually compromised) on a multi-user mail server?

 

 

 

 

Um, make the accounts not compromised?

 

Probably difficult to help without knowing more. Are you running an ISP or is this a corporate mail server on the LAN? Are we talking SMTP?

 

I really think if you are relying on a spam filter for OUTBOUND mail, then you might want to re-architect how you are doing things.

 

 










danfaulknor
974 posts

Ultimate Geek
+1 received by user: 533

Trusted
Prodigi
Subscriber

  #2202867 21-Mar-2019 14:34
Send private message

gbwelly:

 

I really think if you are relying on a spam filter for OUTBOUND mail, then you might want to re-architect how you are doing things.

 

 

 

 

I'd be really interested to hear how to architect things for user-controlled mailboxes that will stop spam without filtering.

 

The host/owner of the IPs has a vested interest in stopping spam from going out from their IPs.

 

Selling mailboxes, shared hosting, servers etc means you give that control over to the users. Outbound spam filtering is a necessity in these cases as you can write all the terms of service you like, but you can send hundreds of thousands of emails in a few hours if you're not filtering somehow.





they/them

 

Prodigi - Optimised IT Solutions
WebOps/DevOps, Managed IT, Hosting and Internet/WAN.


vulcannz
436 posts

Ultimate Geek
+1 received by user: 136
Inactive user


  #2202869 21-Mar-2019 14:37
Send private message

gbwelly:

 

MichaelNZ:

 

What systems are people using to detect and track down spamming accounts (usually compromised) on a multi-user mail server?

 

 

 

 

Um, make the accounts not compromised?

 

Probably difficult to help without knowing more. Are you running an ISP or is this a corporate mail server on the LAN? Are we talking SMTP?

 

I really think if you are relying on a spam filter for OUTBOUND mail, then you might want to re-architect how you are doing things.

 

 

 

 

Outbound antispam solutions are quite common (along with other features such as DLP, routing rules, encryption etc).

 

 


irpegg
146 posts

Master Geek
+1 received by user: 102


  #2202924 21-Mar-2019 17:51
Send private message

ELK Stack, love it

 

 

 

https://www.elastic.co/elk-stack


 
 
 

Support Geekzone with one-off or recurring donations Donate via PressPatron.
gbwelly
1263 posts

Uber Geek
+1 received by user: 776


  #2203207 22-Mar-2019 07:10
Send private message

danielfaulknor:

 

Selling mailboxes, shared hosting, servers etc means you give that control over to the users.

 

 

That is why I asked if he's running an ISP. Corporate network it's quite easy to prevent this with only a sick with a nail in it or a HR lady.

 

 

 

 








MichaelNZ

1594 posts

Uber Geek
+1 received by user: 485

Trusted
Net Trust Ltd

  #2203234 22-Mar-2019 09:18
Send private message

Thanks for the responses.

 

This is for a customer who has a mail server which services lots of subscribers.

 

Their current method of looking for the source of problems is like needle in a haystack.





WFH Linux Systems and Networks Engineer in the Internet industry | Specialising in Mikrotik | APNIC member | Open to job offers | ZL2NET


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.