Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 27
  1. #1
    Member sh4ka's Avatar
    Join Date
    May 2005
    Posts
    434

    Exclamation Exim Dictionary Attack ACL for cPanel

    Have anyone tried script "Exim Dictionary Attack ACL" for cPanel (http://www.configserver.com/free/eximdeny.html).. Any suggestions about it ?

  2. #2
    Member
    Join Date
    Apr 2004
    Posts
    90

    Default

    Quote Originally Posted by sh4ka
    Have anyone tried script "Exim Dictionary Attack ACL" for cPanel (http://www.configserver.com/free/eximdeny.html).. Any suggestions about it ?
    Works great! Chirpy is awesome.

  3. #3
    Member
    Join Date
    Oct 2001
    Posts
    348

    Default

    Just do it, don't worry about it, it is good.

  4. #4
    Member sh4ka's Avatar
    Join Date
    May 2005
    Posts
    434

    Smile

    Oki doki.. I saw the same red "doggie" :P on the site of this script but I never imagine that that was chirpy's website, anyway.. I'll try it. thanks guys.

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It's in my forum signature
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    Member sh4ka's Avatar
    Join Date
    May 2005
    Posts
    434

    Default

    Chirpy, is that a dog or a pony ???

  7. #7
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    looks like a corgi to me

  8. #8
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It's an English Bull Terrier - we have 2 of the little mosters

    hint: click on the logo on the configserver site.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  9. #9
    Member rs-freddo's Avatar
    Join Date
    May 2003
    Location
    Australia
    Posts
    836
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hey Chirpy,

    any way to "permanently" ban the dictionary attack servers. I've had a dictionary attack going on for 3 weeks now. They seem to just be recycling the servers after your script drops them. I don't want to really "permanently" ban them - just set the number of days to keep a server banned.
    Michael

  10. #10
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    If it's for one or two servers it's probably best to drop in a custom ACL for them:

    Code:
      drop hosts = 11.22.33.44 : 11.22.33.55 : 11.22.33.66
           message = Spam or Mail Bombing activity
    Stick that just before the exim deny ACL drops.

    Alternatively, if you want the blanket ban to last longer, remove the symlink in /etc/cron.daily/exim_deny.pl and create a crontab to run that at the frequency that you want (e.g. every 3 days, etc).
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  11. #11
    Member rs-freddo's Avatar
    Join Date
    May 2003
    Location
    Australia
    Posts
    836
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Thanks Chirpy,

    I'm embarrassed it was as simple as changing the cron job....
    It's about 50 servers hammering me, so cron is the way to go.
    Michael

  12. #12
    Member bijo's Avatar
    Join Date
    Aug 2004
    Location
    India
    Posts
    475

    Default

    Quote Originally Posted by chirpy
    It's an English Bull Terrier - we have 2 of the little mosters

    hint: click on the logo on the configserver site.
    Thank you Jonathan

    Finally we can see your photo from that link
    http://chirpy.com
    Bijo
    Yahoo: "bijo505"
    Msn: "bijo_baby@hotmail.com"
    AIM: "bijobaby"

    http://slashome.com

  13. #13
    Member Murtaza_t's Avatar
    Join Date
    Jan 2005
    Location
    Earth
    Posts
    471

    Default

    Thanks Bijo.... I really wanted to see the head that carries those brains...

  14. #14
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I can wholeheartedly recommend the dictionary ACL. A few months back one of our resellers moved a domain getting 70,000 spams a day with blackhole settings to our server. The jump in CPU usage was incredible - for just that one domain. After changing the default destination for the domain from blackhole to fail the server CPU load went back to normal almost immediately although it took a few days for the dictionary ACL to work it's magic and persuade the spammers to play elsewhere. I don't know how anyone could operate a server without the dictionary attack ACL.

  15. #15
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    I would also agree, using the "Exim Dictionary Attack ACL" is a must have for any Server.

    Touch of class on Chirpy's part, to provide it for Free. Even muddlehead's like myself can install it.
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

Similar Threads & Tags
Similar threads

  1. Exim Dictionary Deny ACL for cPanel Servers
    By chirpy in forum cPanel and WHM Discussions
    Replies: 137
    Last Post: 09-17-2007, 04:50 PM
  2. Dictionary Attack
    By noimad1 in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 03-06-2007, 03:55 AM
  3. Replies: 7
    Last Post: 12-30-2005, 07:25 PM
  4. Dictionary attack
    By rmbnet in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 06-29-2004, 07:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube