
21st June 2008, 04:12
|
|
Member
|
|
Join Date: Oct 2007
Posts: 91
Thanks: 10
Thanked 2 Times in 2 Posts
|
|
smtp block brute force attacks
Hi guys,
I'm getting a lot of smtp brute force attacks lately and on my /var/log/secure logs they don't even list the IP of the person trying the attacks. They look like this :
Quote:
Jun 19 16:24:27 server1 saslauthd[2048]: pam_unix(smtp:auth): check pass; user unknown
Jun 19 16:24:27 server1 saslauthd[2048]: pam_unix(smtp:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Jun 19 16:24:27 server1 saslauthd[2048]: pam_succeed_if(smtp:auth): error retrieving information about user 123456
Jun 19 16:24:29 server1 saslauthd[2047]: pam_unix(smtp:auth): check pass; user unknown
Jun 19 16:24:29 server1 saslauthd[2047]: pam_unix(smtp:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Jun 19 16:24:29 server1 saslauthd[2047]: pam_succeed_if(smtp:auth): error retrieving information about user notused
Jun 19 16:24:29 server1 saslauthd[2049]: pam_unix(smtp:auth): check pass; user unknown
Jun 19 16:24:29 server1 saslauthd[2049]: pam_unix(smtp:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Jun 19 16:24:29 server1 saslauthd[2049]: pam_succeed_if(smtp:auth): error retrieving information about user Hockey
|
What's the best way to block these attacks? Thanks
|

21st June 2008, 10:42
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,908
Thanks: 693
Thanked 4,196 Times in 3,212 Posts
|
|
If you know the IP of the attacker, you might use this command:
/sbin/route add -host 123.123.123.123 reject
|

21st June 2008, 14:58
|
|
Member
|
|
Join Date: Oct 2007
Posts: 91
Thanks: 10
Thanked 2 Times in 2 Posts
|
|
Quote:
Originally Posted by till
If you know the IP of the attacker, you might use this command:
/sbin/route add -host 123.123.123.123 reject
|
Till, how do I find out the IP? Normally I also see the IP on the log file, but for these there's nothing. Thanks
|

17th November 2010, 18:30
|
|
Senior Member
|
|
Join Date: Oct 2005
Posts: 192
Thanks: 9
Thanked 1 Time in 1 Post
|
|
Quote:
Originally Posted by till
If you know the IP of the attacker, you might use this command:
/sbin/route add -host 123.123.123.123 reject
|
I tried to do this, but got
SIOCADDRT: No such device
Any suggestions?
|

18th November 2010, 16:10
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,594 Times in 2,445 Posts
|
|
There seems to be something wrong with one of your network interfaces. Did you try to reboot the server?
|

18th November 2010, 16:21
|
|
Senior Member
|
|
Join Date: Oct 2005
Posts: 192
Thanks: 9
Thanked 1 Time in 1 Post
|
|
Quote:
Originally Posted by falko
There seems to be something wrong with one of your network interfaces. Did you try to reboot the server?
|
Oddly enough, when I tried again later, it worked!
|

21st June 2008, 10:42
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,594 Times in 2,445 Posts
|
|
|

21st June 2008, 14:53
|
|
Member
|
|
Join Date: Oct 2007
Posts: 91
Thanks: 10
Thanked 2 Times in 2 Posts
|
|
Is there a fail2ban tutorial for Centos 5?
|

22nd June 2008, 13:47
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,594 Times in 2,445 Posts
|
|
Quote:
Originally Posted by tal56
Is there a fail2ban tutorial for Centos 5?
|
Unfortunately no...
|

28th August 2008, 21:05
|
|
Member
|
|
Join Date: Aug 2006
Posts: 32
Thanks: 6
Thanked 4 Times in 2 Posts
|
|
Quote:
Originally Posted by tal56
Is there a fail2ban tutorial for Centos 5?
|
I saw this post so I put up my notes. It's not a full howto, but it's close.
I run ISPC on Centos 5.2.
http://www.sonoracomm.com/support/18...t/228-fail2ban
G
Last edited by sonoracomm; 28th August 2008 at 21:46.
|
| Thread Tools |
|
|
| Display Modes |
Hybrid Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 18:21.
|
|
Recent comments
18 hours 28 min ago
18 hours 33 min ago
23 hours 32 min ago
1 day 6 hours ago
1 day 7 hours ago
1 day 8 hours ago
1 day 12 hours ago
1 day 19 hours ago
1 day 23 hours ago
2 days 43 min ago