LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-03-2011, 12:40 PM   #1
foxy188
LQ Newbie
 
Registered: Sep 2011
Posts: 10

Rep: Reputation: Disabled
What do you call this? Spoofing? Need Advice


Hi All,

I am extremely new with Linux and need your advice. Recently some idiot tried to use non-existence username through pop3 davecot. Basically, I have nearly 3000+ over entries. Enclosed attachment for your review.

Has anyone got a good idea how to stop this joker/idiot from trying to hack? Do you call this spoofing?

Can davecot prevent such an attempt in this situation?

Steven
Attached Thumbnails
Click image for larger version

Name:	hacking?.jpg
Views:	18
Size:	148.4 KB
ID:	8106  
 
Old 10-03-2011, 03:35 PM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Like it or not, this is going to be a common event when running a mail server and is an example of the importance of using good, strong passwords. Should an intruder manage to guess a user account name, they will undoubtedly being attempting to guess the password. This is commonly referred to as a "brute force" or "dictionary" attack.

There is an application called fail2ban, which will greatly slow them down. Fail2ban works by monitoring your logs for failure expressions such as the ones in your log entry. When a set number, typically 3-5 failures occur within a short period of time, the offending IP address is placed on a (temporary) ban list via hosts.deny and / or iptables (firewall). This will block all connections from the perpetrator for the specified amount of time. So, for example, you could limit them to 3 attempts every 4 hours, which means that attempting to guess an acceptable user name and password is going to take prohibitively long time. The idea is to make the cost of entry such that it is not worth the expenditure of the effort.

If the problem persists, you can block that particular IP and or ISP. While a persistent attacker will work around this, it may be enough to make them go away.

Edit: one thing to note, is that this attack is an attempt to get at the user's mailboxes, through Dovecot (your POP/IMAP) server, which is different than via your SMTP server. Depending on your setup, you may be able to increase the restrictions, such as limiting the addresses (such as to your local LAN) that Dovecot will even listen to.

Last edited by Noway2; 10-03-2011 at 03:37 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Gnu Free Call, the freedom to call out when you really need to LXer Syndicated Linux News 0 04-04-2011 10:10 AM
asterisk call out script - help understanding call files winairmvs Linux - Software 0 10-28-2010 04:52 PM
How can i make centos 4.5's system call using vDSO(call *%gs:0x10) instead of int80 tclwp Red Hat 3 08-06-2007 12:07 AM
How can I script an autologin, automatically call kde(or simillar) and call an app aboaventura Slackware 8 02-03-2007 11:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration