![]() |
Dovecot Auth. Failure spams Message log
Hello,
[CentOS 4.3 - LAMP - ISPc - Dovecot] My message log is spammed by Dovecot. The same line keeps repeating on and on! Code:
Aug 22 15:15:56 host1 dovecot(pam_unix)[24079]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=TIA, |
Does the log show what IP is in the rhost/lhost? If it isn't the localhost then perhaps you have a client trying to authenticate but failing just as the error shows? If it is the localhost then something indeed is wrong with the dovecot config.
I only see those errors when someone fails a login. I rarely see a persistent crack attempt but that too is always possible. You might also do a cold restart of dovecot to make it isn't a hung session. |
I have found the problem... as shown in the error message, every 3 minutes I get a new line in my log.
Code:
Aug 23 01:06:56 host1 dovecot(pam_unix)[1022]: check pass; user unknownCode:
Aug 23 01:06:59 host1 pop3-login: Disconnected [::ffff:62.58.60.226]Any advise on how to go about this... emailing this clown or iptables rule? Thanks, |
Quote:
Code:
route add -host 62.58.60.226 reject |
how do I ban complete ranges?
66.249.71.0/8 etc 66.249.71.1 -> 66.249.71.255 |
| All times are GMT +2. The time now is 04:42. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.