I'm running a postfix/dovecot mail server. This morning, I discovered it was unresponsive. Turned out, /var/log was full. It appears one of the users has had their account hacked and it's being used to send spam.
There are about half-a-million entries like this:
Apr 28 04:12:06 ip-10-0-200-85 postfix/qmgr[3813]: E49F58330A: from=<user@mmydomain.com>, size=2353, nrcpt=20 (queue active)
I've temporarily turned off postfix and dovecot, which is fine for the moment as there are only 6 of us using it. But, what steps should I take beyond having the user's password reset? Might there be things in the outbound postfix queue from this user that I should delete (and how would I do that?)? Any other steps I should take?