Overslaan naar inhoud
  • +31 653-919-302
Cafayate.Net
  • 0
  • 0
  • Aanmelden
  • Nederlands English (US) Español (AR)
  • Contact
  • Startpagina
  • Blog
  • Vacatures
  • Contact
Cafayate.Net
  • 0
  • 0
    • Startpagina
    • Blog
    • Vacatures
    • Contact
  • +31 653-919-302
  • Nederlands English (US) Español (AR)
  • Aanmelden
  • Contact

HOWTO: Protect against postfix AUTH DoS attacks

  • Alle blogs
  • Tech Blog
  • HOWTO: Protect against postfix AUTH DoS attacks
  • 5 maart 2021 in
    Administrator

     

    I have tons of

    Oct 19 06:30:50 mail postfix/smtpd[14043]: connect from unknown[151.237.190.118]
    Oct 19 06:30:50 mail postfix/smtpd[14043]: lost connection after AUTH from unknown[151.237.190.118]
    Oct 19 06:30:50 mail postfix/smtpd[14043]: disconnect from unknown[151.237.190.118]
    Oct 19 06:30:50 mail postfix/smtpd[14043]: connect from unknown[151.237.190.118]
    Oct 19 06:30:50 mail postfix/smtpd[14043]: lost connection after AUTH from unknown[151.237.190.118]
    Oct 19 06:30:50 mail postfix/smtpd[14043]: disconnect from unknown[151.237.190.118]
    Oct 19 06:30:51 mail postfix/smtpd[14043]: connect from unknown[151.237.190.118]
    Oct 19 06:30:51 mail postfix/smtpd[14043]: lost connection after AUTH from unknown[151.237.190.118]
    Oct 19 06:30:51 mail postfix/smtpd[14043]: disconnect from unknown[151.237.190.118]

    in my logs. If you are on the same boat and want to block such attacks, you can use fail2ban:

    1/ add following section to the end of your /etc/fail2ban/jail.local

    [postfix-auth]
    enabled     = true
    filter      = postfix.auth
    action      = iptables-multiport[name=postfix, port="http,https,smtp,submission,pop3,pop3s,imap,imaps,sieve", protocol=tcp]
    #           sendmail[name=Postfix, [email protected]]
    logpath     = /var/log/mail.log

    2/ create new file /etc/fail2ban/filter.d/postfix.auth.conf

    [Definition]
    failregex = lost connection after AUTH from (.*)\[<HOST>\]
    ignoreregex =

    3/ Restart fail2ban. Attacker will be blocked after five attempts.

     

    in Tech Blog
    Mastering file searches on Linux

    Ontworpen voor bedrijven

    We zijn een team van gepassioneerde mensen met als doel levens te verbeteren met vernieuwende producten. We ontwikkelen geweldige oplossingen voor al je zakelijke uitdagingen. Onze producten zijn ontworpen voor kleine tot middelgrote bedrijven die hun prestaties willen optimaliseren.

    Neem contact op

    Plantexel
    Pedernera
    Salta Capital 
    Argentina

    • +31 653-919-302
    • [email protected]
    Volg ons
    Copyright © Plantexel
    Nederlands | English (US) | Español (AR)