Every day my dedicated server is attacked by somebody who attempts to login to an email account that has not been used for sometime on two of our web accounts using a variety of Google Addresses ... anywhere up to 5000 times a day
The result is to block Google from spidering our servers and sites ... the offender obviously knows a little bit about the way our email works and is running a private server.
Is it possible to stop a single email account login attempts and still set allow the IP Addresses in IP Allow? (See messages below)
-----------------------------
I'm also getting daily notification of suspicious process running under user (then proceeds through all websites on the server - only a few at the moment) /usr/sbin/pure-ftpd\00i686\00hp .......... (deleted)
"This file system shows this process is running an executable file that has been deleted. This typically happens ..... See csf.conf and the PT_DELETED text for more information .... etc"
Anything I should be concerned about with message like these?
-------------------------------------------------
**Unmatched Entries** Mostly Google IPs
Disconnected, ip=[::ffff:127.0.0.1]: 287 Time(s)
Disconnected, ip=[::ffff:209.85.200.161]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.162]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.165]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.168]: 8 Time(s)
Disconnected, ip=[::ffff:209.85.200.169]: 4 Time(s)
Disconnected, ip=[::ffff:209.85.200.170]: 2 Time(s)
Disconnected, ip=[::ffff:209.85.200.171]: 3 Time(s)
Disconnected, ip=[::ffff:209.85.200.172]: 3 Time(s)
Disconnected, ip=[::ffff:209.85.200.173]: 4 Time(s)
Disconnected, ip=[::ffff:209.85.200.174]: 5 Time(s)
Disconnected, ip=[::ffff:209.85.200.175]: 5 Time(s)
Disconnected, ip=[::ffff:72.29.95.155]: 1038 Time(s)
Disconnected, ip=[::ffff:72.29.95.172]: 1381 Time(s)
Disconnected, ip=[::ffff:74.125.46.141]: 4 Time(s)
Disconnected, ip=[::ffff:74.125.46.144]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.148]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.150]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.152]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.154]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.155]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.157]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.158]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.160]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.161]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.162]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.164]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.165]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.166]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.24]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.25]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.26]: 4 Time(s)
Disconnected, ip=[::ffff:74.125.46.27]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.28]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.30]: 5 Time(s)
Disconnected, ip=[::ffff:74.125.46.31]: 3 Time(s)
Disconnected, ip=[::ffff:74.125.46.32]: 1 Time(s)
Disconnected, ip=[::ffff:74.125.46.33]: 2 Time(s)
Disconnected, ip=[::ffff:74.125.46.34]: 7 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.161]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.162]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.168]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.171]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.172]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.173]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:209.85.200.175]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.141]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.144]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.152]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.155]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.157]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.160]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.166]: 2 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.24]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.26]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.27]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.30]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.33]: 1 Time(s)
LOGIN FAILED, user=zoe+flairpersonnel.com, ip=[::ffff:74.125.46.34]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.168]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.170]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.171]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.172]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.173]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.174]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:209.85.200.175]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.141]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.148]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.155]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.161]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.26]: 3 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.30]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.31]: 2 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.32]: 1 Time(s)
LOGIN FAILED, user=zoe+splash.net.au, ip=[::ffff:74.125.46.34]: 2 Time(s)



LinkBack URL
About LinkBacks
Every day my dedicated server is attacked by somebody who attempts to login to an email account that has not been used for sometime on two of our web accounts using a variety of Google Addresses ... anywhere up to 5000 times a day
Reply With Quote






