Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Dec 2004
    Posts
    69

    Default Being dictionary spammed. Solutions?

    Hi,

    I have an account on my server that has been getting dictionary spammed over the last few days. I have RBL's in place so most of them don't get through, and the ones that do get through are rejected (no valid RCPT). I've set BFD to block port 25 on the offending IP after 10 failed attempts, but the spammer later switches to another IP and starts again, and gets blocked again, then switches to another IP, etc. etc. I'm guessing he's just using zombie machines.

    Does anyone have a solution for this, or at least something better than what I'm doing now? I don't even know where to start

    Thanks

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    http://www.configserver.com/free/eximdeny.html

    Rememboer to replace any occurences of :blackhole: or /dev/null in /etc/valiases/* with :fail: and I'd recommend deleting the BFD exim check as it's not such a great idea (as I've mentioned in previous posts).
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Dec 2004
    Posts
    69

    Default

    Awesome! Thanks Chripy

  4. #4
    Member
    Join Date
    Dec 2004
    Posts
    69

    Default

    A quick question regarding this mod, Chirpy:

    Since installing this, it's added 5 IP addresses to my /etc/exim_deny file, however, a search through my exim_rejectlog (greping for "dictionary attack") only turns up 3 IPs and none of those 3 are in the exim_deny file.

    Am I missing something?

    [EDIT]I just saw the addition to your last post, and I've already checked for :blackhole:'s, but it appears that they're all set to :fail: already [/EDIT]
    Last edited by nothsa; 02-19-2005 at 05:12 PM.

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Try searching your exim_mainlog instead of exim_rejectlog instead.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    Member lostinspace's Avatar
    Join Date
    Jul 2003
    Location
    Colorado Springs, CO
    Posts
    124

    Default

    Curious,

    Is there a way to set :fail: globally for existing accounts? I know I can use the tweak settings to do this for new accounts.

  7. #7
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. being spammed, looks like Cpanel exploit ?
    By mtindor in forum E-mail Discussions
    Replies: 6
    Last Post: 11-12-2007, 04:49 AM
  2. I'm being spammed by user's of cPanel Forums!
    By DReade83 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-09-2007, 02:05 PM
  3. Am I spamming or am I being spammed
    By lamp in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-23-2006, 01:59 PM
  4. Still getting Spammed
    By equivity in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-02-2003, 07:40 PM
  5. Spammed non-stop by my own servers
    By LS_Drew in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 03-28-2003, 02:21 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube