Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Mar 2006
    Posts
    6

    Default Brute Force

    One particular email account on my server is being brute force attacked for several days now ... It just doesn't stop ...

    cPHulk is showing all the failed logins, some ip's are being blocked;
    Have manually blocked some ip's via iptables;
    Have installed csf and lfd that is also blocking some ip's.

    The problem is that in a period of 5 minutes there are hundreds of different ip's trying to login to this mail account, the majority aren't even blocked because they only make 1 or 2 attemps and then change ...

    Any suggestions? How can I stop it?
    Thank you!

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    I know this is not what you want to hear, but killing the account might be one way to go.

  3. #3
    Member
    Join Date
    Mar 2006
    Posts
    6

    Default

    Definitely not what I wanted to hear

    You think it's possible to block all Ip's trying to login to this mail account and only allow the user IP (without affecting other users and accounts)?

    I'll try to kill temporarily the account during night, to see if they change their mind and stop.

    Thank you Infopro!

  4. #4
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  5. #5
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    Quote Originally Posted by jeck View Post
    One particular email account on my server is being brute force attacked for several days now ... It just doesn't stop ...

    The problem is that in a period of 5 minutes there are hundreds of different ip's trying to login to this mail account, the majority aren't even blocked because they only make 1 or 2 attemps and then change ...

    Any suggestions? How can I stop it?
    Use of firewall, such as what ramprage suggested, may help to further protect the server by blocking access attempts at an earlier stage before they can reach the daemons involved. If the IP changes frequently or is not in a blacklist (such as what some iptables wrapper scripts offer like CSF and APF) then other measures would need to be taken as described below.

    Making good use of available security features is an excellent way to reduce the likelihood of issues occurring. In addition to using cPHulk, I recommend ensuring that all users are able to set only complex passwords, such as an alphanumeric password, with special characters, and varying the use of uppercase and lowercase letters; an easy way to ensure users must set more complex passwords is to set a default minimum password strength via the Security Center in WHM, as seen below:
    WHM: Main >> Security >> Security Center >> Password Strength Configuration
    Documentation: Define a Minimum Password Strength < AllDocumentation/WHMDocs < TWiki

    I would also consider using SSH keys for authentication when accessing SSH and disable password authentication; this may be setup via WHM at the following menu path:
    WHM: Main >> Security >> Security Center >> SSH Password Auth Tweak
    Documentation: Tweak SSH Authentication < AllDocumentation/WHMDocs < TWiki

    If disabling password authentication, please ensure to have an SSH key created so that SSH access can still be used:

    For root:
    WHM: Main >> Security >> Manage SSH Keys
    Documentation: Manage SSH Keys < AllDocumentation/WHMDocs < TWiki

    For resellers and end-users:
    cPanel: Security >> SSH/Shell Access >> Manage SSH Keys
    Documentation: SSH/Shell Access < AllDocumentation/CpanelDocs < TWiki

Similar Threads & Tags
Similar threads

  1. Brute Force Protection
    By Mars_Taxi in forum Security
    Replies: 1
    Last Post: 01-08-2010, 10:44 PM
  2. Brute Force
    By jeck in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-16-2009, 06:38 PM
  3. Brute Force SUCKS!
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-25-2009, 11:11 AM
  4. Brute force
    By iLLuSi0nS in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 06-10-2009, 01:58 PM
  5. Brute Force Q
    By rfonseca in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-01-2005, 04:20 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube