Go Back   cPanel Forums > General Discussion > cPanel Newbies

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-17-2009, 04:15 AM
Registered User
 
Join Date: Mar 2009
Posts: 2
madamsplash is on a distinguished road
Exclamation Annoying Email Login attempts using Google IP Addresses

Every day my dedicated server is attacked by somebody who attempts to login to an email account that has not been used for sometime on two of our web accounts using a variety of Google Addresses ... anywhere up to 5000 times a day

The result is to block Google from spidering our servers and sites ... the offender obviously knows a little bit about the way our email works and is running a private server.

Is it possible to stop a single email account login attempts and still set allow the IP Addresses in IP Allow? (See messages below)

-----------------------------

I'm also getting daily notification of suspicious process running under user (then proceeds through all websites on the server - only a few at the moment) /usr/sbin/pure-ftpd\00i686\00hp .......... (deleted)

"This file system shows this process is running an executable file that has been deleted. This typically happens ..... See csf.conf and the PT_DELETED text for more information .... etc"

Anything I should be concerned about with message like these?

-------------------------------------------------

**Unmatched Entries** Mostly Google IPs
Disconnected, ip=[::ffff:127.0.0.1]: 287 Time(s)
Disconnected, ip=[::ffff:209.85.200.161]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.162]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.165]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.168]: 8 Time(s)
Disconnected, ip=[::ffff:209.85.200.169]: 4 Time(s)
Disconnected, ip=[::ffff:209.85.200.170]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.171]: 3 Time(s)
Disconnected, ip=[::ffff:209.85.200.172]: 3 Time(s)
Disconnected, ip=[::ffff:209.85.200.173]: 4 Time(s)
Disconnected, ip=[::ffff:209.85.200.174]: 5 Time(s)
Disconnected, ip=[::ffff:209.85.200.175]: 5 Time(s)
Disconnected, ip=[::ffff:72.29.95.155]: 1038 Time(s)
Disconnected, ip=[::ffff:72.29.95.172]: 1381 Time(s)
Disconnected, ip=[::ffff:74.125.46.141]: 4 Time(s)
Disconnected, ip=[::ffff:74.125.46.144]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.148]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.150]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.152]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.154]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.155]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.157]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.158]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.160]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.161]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.162]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.164]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.165]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.166]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.24]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.25]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.26]: 4 Time(s)
Disconnected, ip=[::ffff:74.125.46.27]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.28]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.30]: 5 Time(s)
Disconnected, ip=[::ffff:74.125.46.31]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.32]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.33]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.34]: 7 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.161]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.162]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.168]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.171]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.172]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.173]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.175]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.141]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.144]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.152]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.155]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.157]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.160]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.166]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.24]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.26]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.27]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.30]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.33]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.34]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.168]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.170]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.171]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.172]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.173]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.174]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.175]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.141]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.148]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.155]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.161]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.26]: 3 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.30]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.31]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.32]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.34]: 2 Time(s)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 03-17-2009, 06:14 PM
LiNUxG0d's Avatar
Registered User
 
Join Date: Jun 2003
Location: Gatineau, Quebec, Canada
Posts: 197
LiNUxG0d is on a distinguished road
Smile

Hey there,

Is it possible that - and I'm just speculating - this user has their webmail client open on GMail and the IMAP/POP is trying to get mail from your server, but their username/password is wrong? Just thinking out loud since really it seems to be the same user @ multiple domains that's failing... the user on Google's end may not even realize their password is incorrect.

If not, then you may have a really awesome hacker on your hands with lots of rooted boxes in Google's server fleet... which I doubt.

If you think the idea of Webmail fetching mail and failing isn't quite right, I would suggest you e-mail abuse@google.com or something to that effect.

Their whois data: http://who.is/whois-ip/ip-address/74.125.46.141/

A company of that size probably has staff dedicated to this kind of thing.

Warmest regards,
__________________
http://www.boxadmins.com/
We manage your cPanel servers because you simply don't have the time.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-17-2009, 10:20 PM
Registered User
 
Join Date: Mar 2009
Posts: 2
madamsplash is on a distinguished road
Cool Lol - Probably an awesome hacker ...

We had an employee named Zoe - she lasted one day - one of our former designers had/has a girlfriend named Zoe and I was approached by a Zoe to become a Web Designer.

This person is probably a local dinasoar (bit like moire) from the days when we could all download the software to turn our pc's into internet servers and give it whatever IP address we liked ... Looks like I am alone in the Universe with this cretin

Had hoped I could nullify login attempts to the email addresses without blocking from the server entirely ...

Have advised Google - thanks for looking, and if you have any ideas - please advise.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:50 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc