Topic: Continuing frustration with Brute force attempts
This morning it happened again. POP was knocked out by continued hammering per the following in dovecot log (to the tune of 8000+ entries), where "somedomain" is MY domain:
Feb 27 06:12:50 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<support@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:50 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<info@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:53 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<help@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:55 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<support@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:55 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<help@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:56 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<info@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:57 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<support@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:57 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<help@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
Feb 27 06:12:58 pop3-login: Info: Aborted login (auth failed, 1 attempts): user=<Administrator@somedomain.net>, method=PLAIN, rip=217.33.154.50, lip=10.X.X.X.X
My firewall status is as follows:
sudo ufw status
Status: activeTo Action From
-- ------ ----
110/tcp LIMIT Anywhere
995/tcp LIMIT Anywhere
465/tcp LIMIT Anywhere
25/tcp LIMIT Anywhere
Apache LIMIT Anywhere
The LIMIT is set to the default: 6 per 30 seconds. How on earth is this happening? Why isn't the firewall stopping this ridiculous behavior? As you can see it's the exact same IP address every time...so that should trigger the limit, no?
So, IRedmail community, any help is GREATLY appreciated. Thoughts?
Thank you in advance.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.