Failed Dovecot Logins
My users don't use webmail, and all have static configured office PC's, so have no requirement to know thier own email password, for this reason I'm utilising CSF, where I have IMAP, SMTP or POP3 login failure configured for 1 strike and your'e blocked.
This works, and i see IP's being blocked daily.
However, occasionally, I see CPHULK protecting me against failed Dovecot logins.
This is configured for 4 strikes and your'e out.
Can anyone explain why Dovecot is not being triggered by CSF but pop3, SMPT and IMAP are.
-
However, occasionally, I see CPHULK protecting me against failed Dovecot logins. This is configured for 4 strikes and your'e out. Can anyone explain why Dovecot is not being triggered by CSF but pop3, SMPT and IMAP are.
Hello, Could you provide some more details about the specific cPHulk log entry in-question? POP3 and IMAP are both handled with Dovecot. Thank you.0 -
Here is one from last night. Brute Force attempt against "backuppc@www.mydoamin.uk". A device at the "xxx.xxx.xx.xxx" IP address has made a large number of invalid login attempts against the account "backuppc@www.mydomain.uk". This brute force attempt has exceeded the maximum number of failed login attempts that the system allows. For security purposes, the system has temporarily blocked this IP address in order to prevent further attempts. Service: dovecot Local IP Address: xxx.xxx.xxx.xxx Local Port: 110 Remote IP Address: xxx.xxx.xxx.xxx Remote Port: 38072 Authentication Database: mail Username: backuppc@www.mydomain.uk Number of authentication failures: 40 -
CPHULK Screen Shot 0 -
Hello, Port 110 is utilized for POP3 connections. Do you see any corresponding entries for the offending IP address in /var/log/maillog? Thank you. 0 -
I think I may have figured this out. CPHULK is configured to check for failed logins over a set period, and CSF was configured for 2 strikes on POP3, not 1. If the hacker had a failed login, then went away for a while, CSF wouldn't pick him up. If he came back for another attempt, again CSF wouldn't detect him. He could do this 4 times before CPHulk picked him up. 0 -
Hello Keat, For your information, CPHULK is used for brute-force detection and failed login blocking and CSF is prepared with advanced options. The CSF will automatically detects DOS Attacks, DDOS Attacks as well as Brute-force detection and failed login attempts. 0
Please sign in to leave a comment.
Comments
6 comments