<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — Got hit by a dictionary attack - iRedMail survived fine.]]></title>
		<link>https://forum.iredmail.org/topic11708-got-hit-by-a-dictionary-attack-iredmail-survived-fine.html</link>
		<atom:link href="https://forum.iredmail.org/feed-rss-topic11708.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in Got hit by a dictionary attack - iRedMail survived fine..]]></description>
		<lastBuildDate>Mon, 25 Sep 2017 02:26:12 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Got hit by a dictionary attack - iRedMail survived fine.]]></title>
			<link>https://forum.iredmail.org/post58863.html#p58863</link>
			<description><![CDATA[<p>Please kindly help: My iredadmin has lots of bother mails from chiness everyday, So i want to block it, so what should to do?</p>]]></description>
			<author><![CDATA[null@example.com (sophearyat96)]]></author>
			<pubDate>Mon, 25 Sep 2017 02:26:12 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58863.html#p58863</guid>
		</item>
		<item>
			<title><![CDATA[Re: Got hit by a dictionary attack - iRedMail survived fine.]]></title>
			<link>https://forum.iredmail.org/post51384.html#p51384</link>
			<description><![CDATA[<p>Spammers like this usually tried from lots of different IPs to avoid been banned.</p><p>The most important point is always forcing your end users to use a strong password. Fail2ban helps a lot in this case, but as you can see, spammer has lots of IP addresses to try to crack your password, so the final step is user&#039;s strong password.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 15 Sep 2016 07:46:56 +0000</pubDate>
			<guid>https://forum.iredmail.org/post51384.html#p51384</guid>
		</item>
		<item>
			<title><![CDATA[Got hit by a dictionary attack - iRedMail survived fine.]]></title>
			<link>https://forum.iredmail.org/post51379.html#p51379</link>
			<description><![CDATA[<p>==== Required information ====<br />- iRedMail version (check /etc/iredmail-release): 0.9.2<br />- Linux/BSD distribution name and version: Ubuntu 14.04<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL<br />- Web server (Apache or Nginx):Nginx<br />- Manage mail accounts with iRedAdmin-Pro? Yes, v2.1.3 (MySQL)<br />====</p><p>About 2PM EST yesterday 13-Sep-2016,&nbsp; the server started showing a lot of these type of messages in the log where the from= and to= were the same as below&nbsp; (I&#039;ve hidden the domain name). The filtering I have in place took care of most of the hits, and fail2ban did the rest.</p><p> iredmail postfix/smtpd[24204]: NOQUEUE: reject: RCPT from unknown[58.187.8.162]: 554 5.7.1 &lt;unknown[58.187.8.162]&gt;: ..... ; from=&lt;abab61n@****&gt; to=&lt;abab61n@****&gt; proto=ESMTP helo= .....</p><p>I ended up with a bit more than 1500 IPs banned in 24 hours. I ran the following grep on the mail log to get a list of IPs that were participating, and was surprised to get more than 15000 IPs. Someone has a very large SPAM operation.</p><p>grep -E &quot;from=(&lt;[a-zA-Z0-9.-]+@****&gt;)\ +to=\1&quot; &lt; /var/log/mail.log | grep -o -E &quot;[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}&quot; | sort | uniq -c &gt; bad_ip_list.txt</p><p>None of the 300+ customers (probably closer to 500, but I don&#039;t know how many are actively being used like the postmaster or webmaster accounts etc), or 50+ other domains complained about not being able to get email. The only thing that alerted me to a problems was the following logwatch entry below that I have never seen. I actually thought I might have done something accidentally. </p><p>--------------------- Postfix Begin ------------------------ </p><p>&nbsp; &nbsp; &nbsp; &nbsp; 2&nbsp; &nbsp;*Warning: Process limit reached, clients may delay </p><p>Yes, I checked, and my process limit is still set at 100.</p><p>Note this log entry was at about the 2/3 point of the attack. I&#039;m not sure what tomorrows log will show, but I&#039;ll post if it&#039;s interesting.</p><p>Now I have a list of IPs that were part of the attack, any ideas what to do with them? I&#039;m thinking of feeding them to iptables for a week or so, but I doubt it would do much good.</p>]]></description>
			<author><![CDATA[null@example.com (SteveInAkron)]]></author>
			<pubDate>Thu, 15 Sep 2016 03:37:33 +0000</pubDate>
			<guid>https://forum.iredmail.org/post51379.html#p51379</guid>
		</item>
	</channel>
</rss>
