popeye

Well-Known Member
May 23, 2013
368
2
68
Texas
cPanel Access Level
Root Administrator
Hi does anyone know why this keeps happening below ? one of my customers keeps getting blocked


Time: Fri Jul 5 20:20:46 2013 +0100
IP: 000.000.000.00 (GB/United Kingdom/-)
Failures: 5 (smtpauth)
Interval: 3600 seconds
Blocked: Permanent Block

Log entries:

2013-07-05 20:05:47 dovecot_plain authenticator failed for ([00.000.000.00]) [000.000.000.00]:44737: 535 Incorrect authentication data ([email protected],com)
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,261
463
Hello :)

Check to see if their email account is listed in the "Login/Brute History Report" within "WHM Home » Security Center » cPHulk Brute Force Protection". It's possible there have been brute force attempts on their email account or several failed login attempts that have resulted in it getting blocked by cPhulkd.

Thank you.
 

quietFinn

Well-Known Member
Feb 4, 2006
1,899
465
438
Finland
cPanel Access Level
Root Administrator
Hi does anyone know why this keeps happening below ? one of my customers keeps getting blocked


Time: Fri Jul 5 20:20:46 2013 +0100
IP: 000.000.000.00 (GB/United Kingdom/-)
Failures: 5 (smtpauth)
Interval: 3600 seconds
Blocked: Permanent Block

Log entries:

2013-07-05 20:05:47 dovecot_plain authenticator failed for ([00.000.000.00]) [000.000.000.00]:44737: 535 Incorrect authentication data ([email protected],com)
That message is from CSF (ConfigServer Firewall).
If you go to WHM-> Plugins-> ConfigServer Security & Firewall-> Firewall Configuration-> Login Failure Blocking and Alerts
you see that you have:
LF_SMTPAUTH = 5
LF_SMTPAUTH_PERM = 1

which means that after 5 failed logins from an IP the IP is blocked permanently.
 

quietFinn

Well-Known Member
Feb 4, 2006
1,899
465
438
Finland
cPanel Access Level
Root Administrator

LDHosting

Well-Known Member
Jan 19, 2008
93
2
58
cPanel Access Level
Root Administrator
I thought it would be there settings thanks very much for the help. :)
It may be worth keeping in mind that by disabling that setting, you are also disabling LFD's ability to detect and block brute force attacks on your smtp server. Unless you have something else running to do this, such as cPHulk, bots may be able to obtain mailbox passwords via brute force attacks.