Skip to main content

How to block hundreds of incoming mails to not existing accounts

Comments

11 comments

  • keat63
    you could start by adding a number of custom blacklists in exim config. I use these. (attached) You could also potentially blacklist them in CSF firewall if: 1. you have CSF installed 2. The IP's are the same or fall within a class C.
    0
  • keat63
    Actually, I have something very similar going on. I checked over 500 IP's and there is little to no pattern going on in there. The only difference between what you posted and what's going on on mine is my RBL's are blocking most of them and any that get through go in to a black hole. Look at the time stamps and notice the pattern. Mine are coming at 11 seconds past every minute, with sometimes as many as 6 each time.
    0
  • Gino Viroli
    The IP sending these mails are: 185.222.211.10 185.222.211.11 185.222.211.12 The fun part is they are all listed in Service Configuration > Exim Configuration Manager > Manage Custom RBLs" but apparently EXIM does not reject them. 59335
    0
  • keat63
    Yours is an easy fix. Add 185.222.211.0/24 to your CSF deny IP list. if they come back when the list has rotated add: '# do not delete' to the end. Mine is looking impossible but i have a plan.
    0
  • cPanelMichael
    Hello @Gino Viroli, Do you mind opening a Exim CVE-2019-10149), our Technical Analysts can take a closer look to confirm that's the case. You can post the ticket number here once it's opened and I'll link this thread to it. Thank you.
    0
  • Gino Viroli
    Hello @Gino Viroli, Do you mind opening a Exim CVE-2019-10149), our Technical Analysts can take a closer look to confirm that's the case. You can post the ticket number here once it's opened and I'll link this thread to it. Thank you.

    "Your Support Request ID is: 12571987" FYI: # rpm -q exim exim-4.92-1.cp1178.x86_64
    0
  • Gino Viroli
    The
    "Your Support Request ID is: 12571987" FYI: # rpm -q exim exim-4.92-1.cp1178.x86_64

    They told me server is fine and safe.
    0
  • keat63
    do you have CSF firewall installed ?
    0
  • Gino Viroli
    do you have CSF firewall installed ?

    Yes, why? I have already blocked the IPs that send these junk messages, I just thought the mail server would understand that is extreme junk and reject it without even logging it. I was wrong, it rejects it, but it still logs it filling pages of log. :-D Now that I banned the IP via the Firewall they obviously can't even contact my server, but they can use another IP and start over. It would have been useful a cPanel alert, because I found out about this spammer only when I looked at the WHM Mail log.
    0
  • keat63
    There's a CSF forum with a few custom regex rules, maybe there's something in there you could modify. A new rule based on traffic volumes or such like. Only trouble is, don't expect any help from that forum. You've more chance of having someone help with a custom regex on this forum.
    0
  • kamello
    Have the same problem... the ips changes and its difficult to block this kind of attack. I think we need to make some filter like: <> If somebody knows how to do it, please help us. Thanks in advance!
    0

Please sign in to leave a comment.