Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

additions to CSF LFD custom regex #1

Open
jult opened this issue Jun 7, 2023 · 0 comments
Open

additions to CSF LFD custom regex #1

jult opened this issue Jun 7, 2023 · 0 comments

Comments

@jult
Copy link

jult commented Jun 7, 2023

in /var/log/dovecot.log

2023-06-07 22:40:53 auth: Info: passwd-file([email protected],154.127.86.66): unknown user
2023-06-07 22:41:00 auth: Info: passwd-file([email protected],185.247.64.171): unknown user

in /var/log/exim4/rejectlog

2023-06-07 22:41:04 dovecot_login authenticator failed for ([185.247.64.172]) [185.247.64.171]: 535 Incorrect authentication data (set_id=[email protected])
2023-06-07 22:41:06 dovecot_login authenticator failed for ([5.32.22.218]) [5.32.22.218]: 535 Incorrect authentication data (set_id=[email protected])
2023-06-07 22:41:09 dovecot_login authenticator failed for (localhost) [46.148.40.148]: 535 Incorrect authentication data (set_id=s68)
2023-06-07 22:41:09 dovecot_login authenticator failed for ([220.162.202.86]) [220.162.202.86]: 535 Incorrect authentication data (set_id=[email protected])

The unknown user ones for dovecot can be csf -d IP-blocked immediately, as far as I'm concerned, The rejectlog ones as well.
There's no proper way to fight bought bot-net attacks otherwise. Especially on servers with users that are long time users, there's not going to be an issue banning at once.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant