Community Forums
Connect with us on LinkedIn
Community Notice
Closed Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 18
  1. #1
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default I am getting hit with a distributed dictionay email attack

    I am getting hit with a distributed dictionay email attack

    I installed the anti-dictionary attack software but it just keeps coming from new IPs

    # cat /etc/exim_deny | uniq | wc -l
    1058

    Its been running about an hour now and is still increasing.

    What should I do?

    Is it good to block that many ips? Will that slow down delivery of regular mail?

  2. #2
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,310
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by EdRooney
    I installed the anti-dictionary attack software but it just keeps coming from new IPs
    Meaning the one that Chirpy provides?

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    That number should be fine. So long as you have installed the recommended hourly cron job it will rotate the IP addresses. You're likely to have a far greater load on your server if you didn't have the ACL in place.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    Is that a lot? Have you seen more than 1000 ips blocked per hour before?

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Yes. I have a server that at one time was getting around 3000 attacks an hour. It was the reason I wrote the ACL in the first place.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    Cool, how many does that server get now?

  7. #7
    Member
    Join Date
    Nov 2003
    Posts
    521

    Default

    1. How did you know you was under this type of attack?
    2. Considering so many IP's are being blocked, would it be a good idea to unblock the ips in a few months or so considering some of those ip's may have been dynamic or spoofed?

    Thank you in advance for your replies.

  8. #8
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    1. How did you know you was under this type of attack?
    >>I watched the exim main log

    2. Considering so many IP's are being blocked, would it be a good idea to unblock the ips in a few months or so considering some of those ip's may have been dynamic or spoofed?
    >>It depends, if they are dynamically generated, in a few months it is quite possible to have legimate people or quite possiably the entire internet blocked.

    I am thinking of keeping them blocked for few days.

  9. #9
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    My dictionary attack ACL unblocks the IP's within an hour (depending on how often you have thge file rotated via the cron job) since, as you say, they're mostly dynamic. It's highly unlikely that the IP addresses were spoofed, but that's neither here nor there.

    I just checked and that server only gets the normal number now (10-20 an hour) so they've been seen off for now
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  10. #10
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    Quote Originally Posted by chirpy
    I just checked and that server only gets the normal number now (10-20 an hour) so they've been seen off for now
    You rule!!! Chirpy for president!

  11. #11
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,310
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by EdRooney
    You rule!!! Chirpy for president!
    Better nominate him for Prime Minister instead.

  12. #12
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    You really shouldn't be accepting mail from dynamic ips anyways... so I don't see that as a concern? Spoofed ips could be a problem though.

    Or is the block rule added to iptables without specifiying a port (ie 25) so it would then block http as well?

  13. #13
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    How do I block spoofed IPs? I'm at over 15,000 and rapidly increasing

    # cat exim_deny | wc -l
    15437

  14. #14
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    How long does it take beofre the dictionary attackers realize they are blocked and move on to someone elses domain?

  15. #15
    Member
    Join Date
    Dec 2001
    Posts
    1,558

    Default

    Sometimes.. weeks.

    The point of the dictionary attack is to limit the number of useless messages flowing to the inbox.. its up you you as an admin to deal with it as you see fit. They'll still hammer the server ( thats what they're trying to do ).
    Beau Henderson

Closed Thread
Page 1 of 2 1 2 LastLast
Similar Threads & Tags
Similar threads

  1. distributed attack on the email server today.
    By jols in forum E-mail Discussions
    Replies: 0
    Last Post: 05-18-2011, 07:00 PM
  2. is cPanel distributed?
    By shaaad in forum New User Questions
    Replies: 5
    Last Post: 04-04-2007, 05:10 AM
  3. Distributed system
    By asaxena in forum Database Discussions
    Replies: 5
    Last Post: 05-27-2006, 01:48 AM
  4. Getting hit with email virus attachments of 75K, how can I block this?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 11-24-2005, 07:23 PM
  5. Distributed DNS
    By Olate in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-05-2005, 12:41 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube