LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 06-29-2015, 08:12 AM   #1
schlabs
Member
 
Registered: Aug 2007
Posts: 36

Rep: Reputation: 4
Postfix TLS under attack.


Hi, i am under attack from one IP. At this moment i close port 25 on SuSEfirewall2 to stop the attack for the momment.

All start when i found
Code:
2015-06-25T13:45:22.096356-03:00 sxxxb postfix/smtpd[13201]: warning: hostname host70.acr.org does not resolve to address 65.210.36.70: Name or service not known
2015-06-25T13:45:22.097545-03:00 sxxxb postfix/smtpd[13201]: connect from unknown[65.210.36.70]
2015-06-25T13:45:23.356258-03:00 sxxxb postfix/smtpd[13201]: disconnect from unknown[65.210.36.70]
This secuence appear repetidely continuosly.

I write a simple iptables rule to ban him:
Code:
iptables -A INPUT -s 65.210.36.70 -j DROP
But the connections still here, i dont know why.

After this the problem grow, because the attacker was trying to hack TLS library:
Code:
2015-06-26T13:25:42.240594-03:00 sxxxb postfix/smtpd[15848]: initializing the server-side TLS engine
2015-06-26T13:25:42.316748-03:00 sxxxb postfix/smtpd[15848]: warning: hostname host70.acr.org does not resolve to address 65.210.36.70: Name or service not known
2015-06-26T13:25:42.321892-03:00 sxxxb postfix/smtpd[15848]: connect from unknown[65.210.36.70]
2015-06-26T13:25:42.750335-03:00 sxxxb postfix/smtpd[15848]: disconnect from unknown[65.210.36.70]
i found in the log:
Code:
2015-06-26T19:14:48.510836-03:00 sxxxb postfix/smtpd[2261]: warning: TLS library problem: 2261:error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol:s23_srvr.c:647:
So i suspect that the attacker try to scalling privileges. Under this circunstances i shutdown my server for the weekend. ( The most secure mode of a computer ).

I found this IP as hacking IP: "http://www.abuseipdb.com/report-history/65.210.36.70" as "Continuous hacks on port 25 for usernames Dictionary attack, etc."

So for any reason postfix there is not logging the sasl autentication failures.
I perform some checks to sniff what is doing this bad IP.
Code:
tcpdump -i enp0s11 tcp port 25 -l -n -w a.txt
???^B^@^D^@^@^@^@^@^@^@^@^@??^@^@^A^@^@^@!׍U?
^@J^@^@^@J^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@<??@^@1^Fi=.iIL^X??^@^Yo?^\^@^@^@^@?^Br^P?^@^@^B^D^E?^D^B^H
1I?^@^@^@^@^A^C^C^G)׍U^_?
^@J^@^@^@J^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@<??@^@1^Fi<.iIL^X??^@^Yo?^\^@^@^@^@?^Br^P?H^@^@^B^D^E?^D^B^H
1I?^@^@^@^@^A^C^C^G9׍U!?
^@J^@^@^@J^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@<??@^@1^Fi;.iIL^X??^@^Yo?^\^@^@^@^@?^Br^P??^@^@^B^D^E?^D^B^H
1I?^@^@^@^@^A^C^C^GY׍U??^@J^@^@^@J^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@<??@^@1^Fi:.iIL^X??^@^Yo?^\^@^@^@^@?^Br^P?P^@^@^B^D^E?^D^B^H
1J^S0^@^@^@^@^A^C^C^G?׍U¢^H^@>^@^@^@>^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@0#?^@s^F??A?F^X?1?^Y???^@^@^@p^B???^@^@^B^D^E?^A^A^D^B?׍Uڣ^H^@>^@^@^@>^@^@^@^@^A\z(F^@^$
?׍U?+^D^@A^@^@^@A^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@3)?@^@s^F???F^X?1?^Y???7^Y P^X??6^@^@EHLO User
?׍Ul,^D^@6^@^@^@6^@^@^@^@^A\z(F^@^HT:K?^H^@E^@^@(I?@^@@^F?^X?A?F^@^Y1?7^Y ???P^P)૖^@^@?׍U?^D^@?^@^@^@?^@^@^@^@^A\z(F^@^HT:K?^H^@E^@^@?I?@^@@^F?^X?A?F^@^Y1?$
250-PIPELINING
250-SIZE
250-VRFY
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
?׍U?U^G^@<^@^@^@<^@^@^@^@^HT:K?^@^A\z(F^H^@E^@^@.+^]@^@s^F?cA?F^X?1?^Y???$7^Y?P^X?Y-?^@QUIT
?׍U?X^G^@E^@^@^@E^@^@^@^@^A\z(F^@^HT:K?^H^@E^@^@7I?@^@@^F?^X?A?F^@^Y1?7^Y???^DP^X)??^@^@221 2.0.0 Bye
So i suspect that the attacker is trying to login but the postfix dont log this.

The questions,
1)is how i can block this men?
2)How i can enable log of authentication under postfix?
Best Regards
Christian

Last edited by schlabs; 06-29-2015 at 08:13 AM.
 
Old 06-29-2015, 10:01 AM   #2
linom
Member
 
Registered: May 2015
Location: India
Distribution: Debian, CentOS,Redhat, Fedora, Ubuntu
Posts: 91

Rep: Reputation: 13
Hi,

You can block such IP address using the smtpd_client_restrictions in main.cf. Steps would be:
1) Create a file in /etc/postfix/ip_blacklist, add the IP in the below format
<IP-ADDRESS> REJECT
2) In main.cf, add the file path in "smtpd_client_restrictions". Do not remove any other entries.
3) Restart the postfix service.
Note: THis should create an ip_blacklist.db file in the same path.

More info About Postfix SMTPD ACCESS

Last edited by linom; 06-29-2015 at 10:04 AM.
 
1 members found this post helpful.
Old 06-29-2015, 11:55 AM   #3
schlabs
Member
 
Registered: Aug 2007
Posts: 36

Original Poster
Rep: Reputation: 4
thanks you, i added it
 
Old 06-29-2015, 01:35 PM   #4
linom
Member
 
Registered: May 2015
Location: India
Distribution: Debian, CentOS,Redhat, Fedora, Ubuntu
Posts: 91

Rep: Reputation: 13
Thumbs up

Did it resolve your issue? Keep monitoring
 
Old 06-29-2015, 05:43 PM   #5
schlabs
Member
 
Registered: Aug 2007
Posts: 36

Original Poster
Rep: Reputation: 4
seem like the attacker has borring trying to hack a computer powered down.
Today i learn that after write one rule on iptables i need write "iptables-save", and i do.
so both things, so i dont know what of both was more effective ( drop packet or borring hacker), but the attack seem stopped
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: OpenSSL Patched Against TLS Connection Downgrade Attack LXer Syndicated Linux News 0 06-16-2015 03:11 AM
Trouble with postfix and TLS aluchko Linux - Server 1 05-01-2013 07:33 AM
postfix tls verification.. Pinkdog Linux - Server 12 03-17-2010 07:10 PM
Postfix / TLS Help carlosinfl Linux - Server 1 07-22-2009 01:31 PM
Postfix TLS error grant-skywalker Debian 3 09-11-2006 01:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration