LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (http://www.linuxquestions.org/questions/linux-security-4/)
-   -   SMTP Relay Attempts - how do I block then! (http://www.linuxquestions.org/questions/linux-security-4/smtp-relay-attempts-how-do-i-block-then-942668/)

Smokin... 05-01-2012 02:00 AM

SMTP Relay Attempts - how do I block then!
 
Hi All

I run a Debian Mail Server, primarily using Postfix, Courier and Amavis.

I have checked it's 'Open Relay' status, it's as tight as a drum!

For at least the last couple of weeks, my Server has been under a sustained attack attempting to relay emails.

Below is a section of my mail.log from yesterday.

How can I stop this it is chewing up my bandwidth and filling my logs!

Kind regards
Nick
--- mail.log -----------------

Apr 30 08:50:25 needles postfix/smtp[16824]: 5C1BD1448337: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
Apr 30 08:50:26 needles postfix/smtp[16824]: 5C1BD1448337: to=<nick.adie46@speenpula.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=310927, delays=310915/0.01/12/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
Apr 30 08:50:30 needles postfix/smtp[16823]: 44F9B1448332: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie50@wotanrine.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
Apr 30 08:50:31 needles postfix/smtp[16823]: 44F9B1448332: to=<nick.adie50@wotanrine.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=407936, delays=407919/0.02/18/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie50@wotanrine.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
Apr 30 08:55:13 needles postfix/qmgr[8814]: 7BAEF144828B: from=<>, size=3460, nrcpt=1 (queue active)
Apr 30 08:55:20 needles postfix/smtp[16829]: 7BAEF144828B: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
Apr 30 08:55:21 needles postfix/smtp[16829]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=134753, delays=134745/0.02/7.6/0.12, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1

...

May 1 04:43:19 needles postfix/smtp[19795]: 7BAEF144828B: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 04:43:20 needles postfix/smtp[19795]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=206032, delays=206025/0.02/7.1/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:13:13 needles postfix/qmgr[18718]: 398231448330: from=<>, size=3477, nrcpt=1 (queue active)
May 1 05:13:13 needles postfix/qmgr[18718]: EEC1C1448339: from=<>, size=3511, nrcpt=1 (queue active)
May 1 05:13:24 needles postfix/smtp[19810]: EEC1C1448339: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:13:26 needles postfix/smtp[19810]: EEC1C1448339: to=<nick.adie88@hewameta.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=29821, delays=29808/0.01/13/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:13:29 needles postfix/smtp[19809]: 398231448330: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:13:30 needles postfix/smtp[19809]: 398231448330: to=<nick.adie41@gidekias.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=50823, delays=50805/0.02/17/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:23:13 needles postfix/qmgr[18718]: E0D69144833C: from=<>, size=3471, nrcpt=1 (queue active)
May 1 05:23:22 needles postfix/smtp[19819]: E0D69144833C: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie07@unethqutes.in>: Recipient address rejected: unverified address: unknown user: "nick.adie07@unethqutes.in" (in reply to RCPT TO command)
May 1 05:23:24 needles postfix/smtp[19819]: E0D69144833C: to=<nick.adie07@unethqutes.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=378617, delays=378607/0.02/10/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie07@unethqutes.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:28:13 needles postfix/qmgr[18718]: 5F0E51448336: from=<>, size=3481, nrcpt=1 (queue active)
May 1 05:28:19 needles postfix/smtp[19824]: 5F0E51448336: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie38@fampbung.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:28:21 needles postfix/smtp[19824]: 5F0E51448336: to=<nick.adie38@fampbung.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=399348, delays=399340/0.02/7.8/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie38@fampbung.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:48:13 needles postfix/qmgr[18718]: 5C1BD1448337: from=<>, size=3464, nrcpt=1 (queue active)
May 1 05:48:13 needles postfix/qmgr[18718]: 0422B1448338: from=<>, size=3518, nrcpt=1 (queue active)
May 1 05:48:25 needles postfix/smtp[19839]: 0422B1448338: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie34@mirsences.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:48:26 needles postfix/smtp[19839]: 0422B1448338: to=<nick.adie34@mirsences.in>, relay=eforward3.registrar-servers.com[205.251.134.191]:25, delay=26387, delays=26375/0.01/12/0.11, dsn=4.1.1, status=deferred (host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie34@mirsences.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:48:29 needles postfix/smtp[19838]: 5C1BD1448337: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:48:31 needles postfix/smtp[19838]: 5C1BD1448337: to=<nick.adie46@speenpula.in>, relay=eforward1.registrar-servers.com[69.160.33.82]:25, delay=386412, delays=386394/0.02/18/0.18, dsn=4.1.1, status=deferred (host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie46@speenpula.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 05:53:13 needles postfix/qmgr[18718]: 7BAEF144828B: from=<>, size=3460, nrcpt=1 (queue active)
May 1 05:53:20 needles postfix/smtp[19844]: 7BAEF144828B: host eforward1.registrar-servers.com[69.160.33.82] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 05:53:21 needles postfix/smtp[19844]: 7BAEF144828B: to=<nick.adie84@girgenra.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=210233, delays=210225/0.02/7.5/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie84@girgenra.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 06:23:13 needles postfix/qmgr[18718]: 398231448330: from=<>, size=3477, nrcpt=1 (queue active)
May 1 06:23:13 needles postfix/qmgr[18718]: EEC1C1448339: from=<>, size=3511, nrcpt=1 (queue active)
May 1 06:23:29 needles postfix/smtp[19868]: 398231448330: host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 06:23:29 needles postfix/smtp[19869]: EEC1C1448339: host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command)
May 1 06:23:29 needles postfix/smtp[19868]: 398231448330: to=<nick.adie41@gidekias.in>, relay=eforward3.registrar-servers.com[205.251.134.191]:25, delay=55022, delays=55005/0.02/16/0.12, dsn=4.1.1, status=deferred (host eforward3.registrar-servers.com[205.251.134.191] said: 450 4.1.1 <nick.adie41@gidekias.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))
May 1 06:23:30 needles postfix/smtp[19869]: EEC1C1448339: to=<nick.adie88@hewameta.in>, relay=eforward2.registrar-servers.com[38.101.213.202]:25, delay=34025, delays=34007/0.01/17/0.11, dsn=4.1.1, status=deferred (host eforward2.registrar-servers.com[38.101.213.202] said: 450 4.1.1 <nick.adie88@hewameta.in>: Recipient address rejected: unverified address: Address verification in progress (in reply to RCPT TO command))

acid_kewpie 05-01-2012 02:22 AM

there's not a huge amount you can do, but one thing I'd suggest is using fail2ban to trawl the logs and block specific client IP's doing this, there is a bit of replication of IP's in there from what I can see, so that's a start.

descendant_command 05-01-2012 02:39 AM

+1

fail2ban IS the droid you are looking for :)

I don't think it has a jail for postfix by default, but plenty of examples about.

Noway2 05-01-2012 09:20 AM

Use of Address Verification, while being an effective tool against SPAM, is not without issues. If you haven't already have a look at the Postfix documentation on the subject: http://www.postfix.org/ADDRESS_VERIFICATION_README.html There is little you can do to stop the attempts to probe your system as a potential open relay except use tools like fail2ban or the BSD version of spamd, but if you are experiencing performance issues because of this check you may want to try alternative tactics. For example, my list of checks is contained below (which is a little bit DNS heavy because of the fact that I have the RBL checks early on). The important point is that the order of your checks can also have an impact on performance and it may be possible to reject spam with a light weight check before running heavier one.

Note that I am using reject_unauth_destination (which stops open relaying). I am also using reject_unknown_recipient_domain, which is a form of address verification, but it is checked after verification that it is an authorized destination. In the sender restrictions, I am using things like reject_non_fqdn_sender and reject_unknown_sender_domain, which send a 550 level reject code in response to crap generated from worms like Conficker.
Code:

smtpd_recipient_restrictions =
#  reject_rbl_client dnsbl.sorbs.net -- this catches more spam, but also creates quite a few false positives
  reject_rbl_client zen.spamhaus.org
  reject_rbl_client bl.spamcop.net
  permit_mynetworks
  permit_sasl_authenticated
  check_policy_service inet:127.0.0.1:60000
  permit_mx_backup
  reject_unauth_destination
  reject_unknown_recipient_domain
  permit


smtpd_sender_restrictions =
  permit_mynetworks
  reject_non_fqdn_sender
  reject_unknown_sender_domain
  check_sender_access hash:/etc/postfix/sender_access


leslie_jones 05-01-2012 12:50 PM

There don't appear to be relay attempts at all.

You appear to have this enabled:

http://www.postfix.org/ADDRESS_VERIFICATION_README.html

Basically, an inbound message claiming to be from "nick.adie38@fampbung.munged" will result in the Postfix SMTP deamon attempting to verify that sender address by connecting to the MX responsible for the domain and running an SMTP session up to RCPT TO - where it will typically quit.

Disable that feature (which I personally would not use) and your problem should go.

Relay attempts manifest themselves in the logs with this: "Relay access denied" and this will give you handle on if you have a problem with that:

zgrep -e "Relay access denied" /var/log/mail* (or the location of your mail log)

djsoundfx 05-15-2012 12:30 PM

You definitely need to modify your configurations and add fail2ban or spamd but it would also be possible (since it seems like these are all coming from the same repeated ip addresses) that you could block this at a firewall level as well and that may help free up some of your bandwidth as well. I would certainly consider that as well.


All times are GMT -5. The time now is 10:16 AM.