I'm running a postfix installation on ubuntu 10.04 LTS with multiple domains. The relay access requires authentication with STARTTLS. This morning one of the user accounts logged in and sent hundreds of spam mails as I can see from the log. The actual owner of this account informed me of receiving multiple DSN Mails. The logs do not show any signs of a bruteforce attack for the password, so I'm guessing there are only 2 options left:
a) The users password has been stolen (i've already changed it and since then no further incedences occured) b) There's something wrong with the authentication mechanism.
Does anybody have further suggestions on how to investigate on such a topic?
Here is a snippet of the log, when the authentication happend:
Apr 28 09:17:44 vs1909 postfix/smtpd[13325]: connect from unknown[217.76.201.194]
Apr 28 09:17:45 vs1909 postfix/smtpd[13325]: 1458F1409A: client=unknown[217.76.201.194], sasl_method=PLAIN, sasl_username=mail@xxxxxx.tld