Skip to main content

Failed Dovecot Logins

Comments

6 comments

  • cPanelMichael
    However, occasionally, I see CPHULK protecting me against failed Dovecot logins. This is configured for 4 strikes and your'e out. Can anyone explain why Dovecot is not being triggered by CSF but pop3, SMPT and IMAP are.

    Hello, Could you provide some more details about the specific cPHulk log entry in-question? POP3 and IMAP are both handled with Dovecot. Thank you.
    0
  • keat63
    Here is one from last night.
    Brute Force attempt against "backuppc@www.mydoamin.uk". A device at the "xxx.xxx.xx.xxx" IP address has made a large number of invalid login attempts against the account "backuppc@www.mydomain.uk". This brute force attempt has exceeded the maximum number of failed login attempts that the system allows. For security purposes, the system has temporarily blocked this IP address in order to prevent further attempts. Service: dovecot Local IP Address: xxx.xxx.xxx.xxx Local Port: 110 Remote IP Address: xxx.xxx.xxx.xxx Remote Port: 38072 Authentication Database: mail Username: backuppc@www.mydomain.uk Number of authentication failures: 4
    0
  • keat63
    CPHULK Screen Shot
    0
  • cPanelMichael
    Hello, Port 110 is utilized for POP3 connections. Do you see any corresponding entries for the offending IP address in /var/log/maillog? Thank you.
    0
  • keat63
    I think I may have figured this out. CPHULK is configured to check for failed logins over a set period, and CSF was configured for 2 strikes on POP3, not 1. If the hacker had a failed login, then went away for a while, CSF wouldn't pick him up. If he came back for another attempt, again CSF wouldn't detect him. He could do this 4 times before CPHulk picked him up.
    0
  • CrazyforLinux
    Hello Keat, For your information, CPHULK is used for brute-force detection and failed login blocking and CSF is prepared with advanced options. The CSF will automatically detects DOS Attacks, DDOS Attacks as well as Brute-force detection and failed login attempts.
    0

Please sign in to leave a comment.