Skip to main content

Exim dictionary attack to non existant domain on server

Comments

6 comments

  • ruzbehraja
    They may have left their DNS / A Records pointing to your server. What you could do, in the cPanel DNS is, add that domain and set all A records for it to "127.0.0.1". When the attackers try to resolve that domain name, it will lead them to their own machine's loopback :)
    0
  • sahostking
    Checked and see no dns. But will create an account for it and then do just that.
    0
  • mtindor
    Checked and see no dns. But will create an account for it and then do just that.

    I don't even think you have to add a new account for it. Within WHM, just create a new zone for that domain. Better to have just a zone file exist rather than a whole hosting account. Just my two thoughts. Mike
    0
  • ruzbehraja
    I don't even think you have to add a new account for it. Within WHM, just create a new zone for that domain. Better to have just a zone file exist rather than a whole hosting account. Just my two thoughts. Mike

    I agree on this.
    0
  • cPanelMichael
    They may have left their DNS / A Records pointing to your server. What you could do, in the cPanel DNS is, add that domain and set all A records for it to "127.0.0.1". When the attackers try to resolve that domain name, it will lead them to their own machine's loopback :)

    Hello, I agree, this seems like the most plausible reason this is happening. You may also want to consider reaching out to the contact address for that domain name in it's WHOIS lookup to let them know of the situation. Thank you.
    0
  • sahostking
    The domain was somewhere else - It seems they are attacking the hostname or IP of the server somehow and doing a dictionary attack against it for that domain. Seems to have stopped but still get a little connections now and again.
    0

Please sign in to leave a comment.