store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 2:17 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 
Author Message
 Post subject: SMTPAUTH attacks.
Unread postPosted: Thu Sep 24, 2009 11:48 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Hi,
I have seen recently a very high activity from hackers trying to hack smtp passwords accounts. I have set my firewall to block any of this type of activity and the list of IPs is growing, be careful.

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Sep 25, 2009 8:31 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
ASL has rules for this currently


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Thu Jan 28, 2010 5:47 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Dec 16, 2008 8:01 am
Posts: 353
Location: United Kingdom
I have a lot of smtp_auth failed password attempts from an IP in China.
Scott said in teh post above that there were rules which would stop this and block the IPs. Am I correct in that assumption? And if so, can I stop it?
Not sure if it could be linked but I am getting thousands of OSSEC messages in /var/log/httpd/error_log saying
child pid xxxxx exit signal Segmentation fault (11)

I think I may need mod_whatkilledus but I'm not sure how to install it, run the app and then interpret the results to see where the problem lies.

Can someone help please?


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Thu Jan 28, 2010 9:02 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
The segfault in the httpd log won't be related to email (unless they are trying to get in via webmail maybe?) - at least I don't think so.

I've not seen any element of ASL reporting or acting on multiple failed smtp (or FTP) attempts ... what part should do that?

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Jan 29, 2010 4:09 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Dec 16, 2008 8:01 am
Posts: 353
Location: United Kingdom
Thanks faris,
Regarding the segfault, I'd love to know how I can try to find out what caused it.

On the maillog, I may be wrong but I read in http://www.atomicorp.com/forums/viewtop ... rute+force (first 2 posts) something which suggested to me that these IPs could be blocked. Maybe I misread that topic?

And below, Scott seemed to suggest that ASL has rules to block hackers trying to hack smtp passwords.


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Jan 29, 2010 8:10 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
I've just not seen these features at work, nor any config for them.

I use BFD (configured to use ASL to block, so that I can easily unblock via the ASL gui) but I don't really like it.

Scott/Mike .. what's the lowdown on this? Is there something in ASL acting on multiple auth failures? I'm pretty sure (but not absolutely sure) that ossec notifies me of multiple FTP failures, but I've never seen ASL block as a result. And never anything on smtp failures.

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Jan 29, 2010 9:23 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Are you using plesk 9.3 by any chance? Looks like they changed the logging format enough to break the rules.


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Jan 29, 2010 9:58 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Dec 16, 2008 8:01 am
Posts: 353
Location: United Kingdom
I'm using Plesk 9.2.3, with CentOS5 and ASL if that helps Scott


Top
 Profile  
 
 Post subject: Re: SMTPAUTH attacks.
Unread postPosted: Fri Jan 29, 2010 10:55 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
I'm not. I'm on 8.6.

I've gone back and had a look at the two most recent incidents. In both cases BFD detected the issue but there's nothing from ossec.

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group