- Mitglied seit
- 11. Nov 2010
- Beiträge
- 117
- Punkte für Reaktionen
- 0
- Punkte
- 0
Nabend Zusammen,
ich habe gerade mal meine Mail-Logs gecheckt und da ist mir folgendes aufgefallen:
Da hat doch tatsächlich jemand versucht meinen mühevoll eingerichteten Mailserver mit eigener Domain zu kapern.
Gibt es eine Möglichkeit solche fehlerhaften Loginversuche über den DSM eigenen Autoblock zu sperren? Oder kann ich im dovecot maximal mögliche Logins einer IP festlegen?
Danke,
Alex
ich habe gerade mal meine Mail-Logs gecheckt und da ist mir folgendes aufgefallen:
Rich (BBCode):
Mar 22 19:34:38 meineDS postfix/smtpd[20763]: connect from unknown[112.65.158.88]
Mar 22 19:34:39 meineDS postfix/smtpd[20763]: lost connection after CONNECT from unknown[112.65.158.88]
Mar 22 19:34:39 meineDS postfix/smtpd[20763]: disconnect from unknown[112.65.158.88]
Mar 22 19:37:59 meineDS postfix/anvil[20765]: statistics: max connection rate 1/60s for (192.168.1.251:smtp:112.65.158.88) at Mar 22 19:34:39
Mar 22 19:37:59 meineDS postfix/anvil[20765]: statistics: max connection count 1 for (192.168.1.251:smtp:112.65.158.88) at Mar 22 19:34:39
Mar 22 19:37:59 meineDS postfix/anvil[20765]: statistics: max cache size 1 at Mar 22 19:34:39
Mar 22 19:42:40 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<admin>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:42:45 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<abuse>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:42:50 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<mail>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:42:56 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:02 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:07 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<info>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:13 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<service>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:20 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<service>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:25 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<adam>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:33 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<adm>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:39 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:44 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test1>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:50 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<david>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:43:59 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<david>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:04 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<info>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:09 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<internet>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:16 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<welcome>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:26 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<alex>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:32 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<alan>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:38 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<web>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:44 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<lisa>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:44:53 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<sharon>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:02 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<office>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:07 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<postmaster>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:14 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<susan>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:22 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<susan>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:27 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<michael>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:33 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<tester>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:39 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<cindy>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:45 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<mike>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:45:51 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<sales>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:01 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<web>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:05 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<richard>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:10 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<operator>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:15 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<george>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:22 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<admin>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:28 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<admin>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:34 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<admin>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:40 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<oracle>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:46 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<sunny>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:52 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<webmaster>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:46:58 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<testing>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:47:04 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<testuser>, method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Mar 22 19:47:08 meineDS dovecot: pop3-login: Disconnected (auth failed, 1 attempts): method=PLAIN, rip=112.65.158.88, lip=192.168.1.251
Da hat doch tatsächlich jemand versucht meinen mühevoll eingerichteten Mailserver mit eigener Domain zu kapern.
Gibt es eine Möglichkeit solche fehlerhaften Loginversuche über den DSM eigenen Autoblock zu sperren? Oder kann ich im dovecot maximal mögliche Logins einer IP festlegen?
Danke,
Alex