SMTP Relay Attempts - how do I block then!
Hi All
I run a Debian Mail Server, primarily using Postfix, Courier and Amavis. I have checked it's 'Open Relay' status, it's as tight as a drum! For at least the last couple of weeks, my Server has been under a sustained attack attempting to relay emails. Below is a section of my mail.log from yesterday. How can I stop this it is chewing up my bandwidth and filling my logs! Kind regards Nick --- mail.log ----------------- Apr 30 08:50:25 needles postfix/smtp[16824]: 5C1BD1448337: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) Apr 30 08:50:26 needles postfix/smtp[16824]: 5C1BD1448337: to=<nick.adie46@speenpula.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=310927, delays=310915/0.01/12/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) Apr 30 08:50:30 needles postfix/smtp[16823]: 44F9B1448332: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie50@wotanrine.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) Apr 30 08:50:31 needles postfix/smtp[16823]: 44F9B1448332: to=<nick.adie50@wotanrine.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=407936, delays=407919/0.02/18/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie50@wotanrine.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) Apr 30 08:55:13 needles postfix/qmgr[8814]: 7BAEF144828B: from=<>, size=3460, nrcpt=1 (queue active) Apr 30 08:55:20 needles postfix/smtp[16829]: 7BAEF144828B: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) Apr 30 08:55:21 needles postfix/smtp[16829]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=134753, delays=134745/0.02/7.6/0.12, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 ... May 1 04:43:19 needles postfix/smtp[19795]: 7BAEF144828B: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 04:43:20 needles postfix/smtp[19795]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=206032, delays=206025/0.02/7.1/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:13:13 needles postfix/qmgr[18718]: 398231448330: from=<>, size=3477, nrcpt=1 (queue active) May 1 05:13:13 needles postfix/qmgr[18718]: EEC1C1448339: from=<>, size=3511, nrcpt=1 (queue active) May 1 05:13:24 needles postfix/smtp[19810]: EEC1C1448339: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:13:26 needles postfix/smtp[19810]: EEC1C1448339: to=<nick.adie88@hewameta.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=29821, delays=29808/0.01/13/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:13:29 needles postfix/smtp[19809]: 398231448330: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:13:30 needles postfix/smtp[19809]: 398231448330: to=<nick.adie41@gidekias.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=50823, delays=50805/0.02/17/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:23:13 needles postfix/qmgr[18718]: E0D69144833C: from=<>, size=3471, nrcpt=1 (queue active) May 1 05:23:22 needles postfix/smtp[19819]: E0D69144833C: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie07@unethqutes.in>: Recipient address rejected: unverified address: unknown user: "nick.adie07@unethqutes.in" (in reply to RCPT TO command) May 1 05:23:24 needles postfix/smtp[19819]: E0D69144833C: to=<nick.adie07@unethqutes.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=378617, delays=378607/0.02/10/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie07@unethqutes.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:28:13 needles postfix/qmgr[18718]: 5F0E51448336: from=<>, size=3481, nrcpt=1 (queue active) May 1 05:28:19 needles postfix/smtp[19824]: 5F0E51448336: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie38@fampbung.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:28:21 needles postfix/smtp[19824]: 5F0E51448336: to=<nick.adie38@fampbung.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=399348, delays=399340/0.02/7.8/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie38@fampbung.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:48:13 needles postfix/qmgr[18718]: 5C1BD1448337: from=<>, size=3464, nrcpt=1 (queue active) May 1 05:48:13 needles postfix/qmgr[18718]: 0422B1448338: from=<>, size=3518, nrcpt=1 (queue active) May 1 05:48:25 needles postfix/smtp[19839]: 0422B1448338: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie34@mirsences.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:48:26 needles postfix/smtp[19839]: 0422B1448338: to=<nick.adie34@mirsences.in>, relay=eforward3.registrar-servers.com[205.251.134.191]:25, delay=26387, delays=26375/0.01/12/0.11, dsn=4.1.1, status=deferred (host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie34@mirsences.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:48:29 needles postfix/smtp[19838]: 5C1BD1448337: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:48:31 needles postfix/smtp[19838]: 5C1BD1448337: to=<nick.adie46@speenpula.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=386412, delays=386394/0.02/18/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 05:53:13 needles postfix/qmgr[18718]: 7BAEF144828B: from=<>, size=3460, nrcpt=1 (queue active) May 1 05:53:20 needles postfix/smtp[19844]: 7BAEF144828B: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 05:53:21 needles postfix/smtp[19844]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=210233, delays=210225/0.02/7.5/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 06:23:13 needles postfix/qmgr[18718]: 398231448330: from=<>, size=3477, nrcpt=1 (queue active) May 1 06:23:13 needles postfix/qmgr[18718]: EEC1C1448339: from=<>, size=3511, nrcpt=1 (queue active) May 1 06:23:29 needles postfix/smtp[19868]: 398231448330: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 06:23:29 needles postfix/smtp[19869]: EEC1C1448339: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command) May 1 06:23:29 needles postfix/smtp[19868]: 398231448330: to=<nick.adie41@gidekias.in>, relay=eforward3.registrar-servers.com[205.251.134.191]:25, delay=55022, delays=55005/0.02/16/0.12, dsn=4.1.1, status=deferred (host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) May 1 06:23:30 needles postfix/smtp[19869]: EEC1C1448339: to=<nick.adie88@hewameta.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=34025, delays=34007/0.01/17/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)) |
there's not a huge amount you can do, but one thing I'd suggest is using fail2ban to trawl the logs and block specific client IP's doing this, there is a bit of replication of IP's in there from what I can see, so that's a start.
|
+1
fail2ban IS the droid you are looking for :) I don't think it has a jail for postfix by default, but plenty of examples about. |
Use of Address Verification, while being an effective tool against SPAM, is not without issues. If you haven't already have a look at the Postfix documentation on the subject: http://www.postfix.org/ADDRESS_VERIFICATION_README.html There is little you can do to stop the attempts to probe your system as a potential open relay except use tools like fail2ban or the BSD version of spamd, but if you are experiencing performance issues because of this check you may want to try alternative tactics. For example, my list of checks is contained below (which is a little bit DNS heavy because of the fact that I have the RBL checks early on). The important point is that the order of your checks can also have an impact on performance and it may be possible to reject spam with a light weight check before running heavier one.
Note that I am using reject_unauth_destination (which stops open relaying). I am also using reject_unknown_recipient_domain, which is a form of address verification, but it is checked after verification that it is an authorized destination. In the sender restrictions, I am using things like reject_non_fqdn_sender and reject_unknown_sender_domain, which send a 550 level reject code in response to crap generated from worms like Conficker. Code:
smtpd_recipient_restrictions = |
There don't appear to be relay attempts at all.
You appear to have this enabled: http://www.postfix.org/ADDRESS_VERIFICATION_README.html Basically, an inbound message claiming to be from "nick.adie38@fampbung.munged" will result in the Postfix SMTP deamon attempting to verify that sender address by connecting to the MX responsible for the domain and running an SMTP session up to RCPT TO - where it will typically quit. Disable that feature (which I personally would not use) and your problem should go. Relay attempts manifest themselves in the logs with this: "Relay access denied" and this will give you handle on if you have a problem with that: zgrep -e "Relay access denied" /var/log/mail* (or the location of your mail log) |
You definitely need to modify your configurations and add fail2ban or spamd but it would also be possible (since it seems like these are all coming from the same repeated ip addresses) that you could block this at a firewall level as well and that may help free up some of your bandwidth as well. I would certainly consider that as well.
|
All times are GMT -5. The time now is 09:19 AM. |