store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 25, 2013 1:57 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 
Author Message
 Post subject: RULE 60921 - Plesk/Courier authd / No such user in database
Unread postPosted: Sun Jun 17, 2012 1:03 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
Hi every 7 secs I am getting a RULE 60921 notification for the xxxxxxxxx-1 Plesk/Courier authd[36161]: No such user `joey@co.uk` in mail authorisation database

and so on.

When I go to manage the rule its displayed as null with option to actively shun as per the rule / ip.

Is their anyway to update a rule to combat this as I have been getting bombarded by these over the last few days with no option to manage the rule specifically as its denoted as null:

17 June
08:16:46
xxxxxxxxx-1
13
60921

xxxxxxxxx-1 Plesk/Courier authd[36161]: No such user `joey@ co.uk` in mail authorization database
08:16:36
xxxxxxxxx-1
13
60921

< snipped due to lots of entries >


Last edited by inquis on Sat Jun 23, 2012 8:32 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 12:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Thanks for the question, I'm not sure what you want to do. Do you want to disable the rule?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 12:42 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
mikeshinn wrote:
Thanks for the question, I'm not sure what you want to do. Do you want to disable the rule?


Hi Mike,

it different ip triggering the rule and I would like to shun the IPS but when i click on "Manage rule" their no defining rule to amend - its just listed as null.

Is their a way to create a rule where i can choose to shun etc the rule which could be named multiple mail authorisation errors or something ?


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 3:30 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
Not at this time, descriptions are lost when the rule is modified.


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 5:07 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Quote:
Is their a way to create a rule where i can choose to shun etc the rule which could be named multiple mail authorisation errors or something ?


You cant shun on that log event because there is no IP to shun. For example:

xxxxxxxxx-1 Plesk/Courier authd[36161]: No such user `joey@ co.uk` in mail authorization database

If thats all that is logged, and theres nothing else (like perhaps a different service that sees the IP) then there nothing you or we can do with that information. Its useless, theres no source information in that line, so theres nothing to shun.

Are there other log events that list the source IP by any chance?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 5:49 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
HI Mike,

sorry you do get IP addys as per below.

the rule thats triggering it is Rule:3901 - New courier (imap/pop3) connection.

I obviously wouldn't want to shun every new connection to pop3 / imap but could a new rule be tweaked that allows a user to shun an ip triggering 60921 where no such user exists in the mail authorization database ?


Attachments:
File comment: Rule 60921 trigger
ip-asl-mike.gif
ip-asl-mike.gif [ 107.21 KiB | Viewed 996 times ]
Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Mon Jun 18, 2012 5:56 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
So rule 3911 can help you out here, it will shun on multiple courier connections (20 in 30 seconds from the same IP). Just set 3911 to shun and you'll be set (3911 is a lower level alert and does not shun by default, which is also why you dont see it by default if your level is set to the default).

Unfortunately plesks authd doesnt record anything about the source (which is really silly, why bother logging the event then), so you have to shun on the courier events.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Sat Jun 23, 2012 8:40 am 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
Hi Mike,

thanks for that, after some rule tweaking and adding some extra supplementary rules I seem to have go it under control.

And yes Plesk does have some complete silly quirks for sure.

On a side not, why does a rule change to null after its edited ?

Is their a way to stop or is this hardcoded into ASL - Sorry for the silly question but just win I think I get it, I dont lol


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Sat Jun 23, 2012 10:41 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
At the moment its because we're not running it through the database. It makes a 2nd rule to override the first one, a better/longer to write/more complicated way to do it is to regenerate the rule class from the database.


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Sat Jun 23, 2012 11:47 am 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
Is this something pencilled in for the future or is the performance hit to great ?


Top
 Profile  
 
 Post subject: Re: RULE 60921 - Plesk/Courier authd / No such user in datab
Unread postPosted: Sat Jun 23, 2012 8:51 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
Yup its on the list, no performance hit. It just makes ASL Web a requirement, which we had tried to avoid in the past.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group