I think it happens during a software upgrade. LFD reports auth failed for those users trying to get pop3 mail at that time. It is within a few seconds of the same time every day. It only happens to the people checking mail during that minute or two at 4:44am.
Here is the error report:
Subject: lfd: blocked x.x.x.x
Time: Tue Oct 1 04:44:50 2013 -0400
IP: x.x.x.x
Failures: 5 (pop3d)
Interval: 300 seconds
Blocked: Yes
Log entries:
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.add.ress, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
This is what I find in cron near that time:
0 4 * * * /usr/sbin/cxs --upgrade --quiet
0 4 * * * /usr/local/cpanel/scripts/cpbackup
37 4 * * * /usr/local/cpanel/scripts/upcp --cron
is upcp causing LFD to give erroneous reports? These same accounts check their mail 24 hours a day with no issues, but at this time every day, they are tagged as trying to log in with a bad password. so every morning I have to remove them from iptables and then they are fine until 4:44am the next day.
I also see this just before the above error, everyday.
Time: Wed Oct 9 04:42:01 2013 -0400
Error: Failed to detect code [dVt8TcB7JrCPoQTRBZihM6qjtxoXu] in SYSLOG_LOG [/var/log/messages]
SYSLOG may not be running correctly on sabrina.syo.com
Thanks so much for your insight.
Jason
Here is the error report:
Subject: lfd: blocked x.x.x.x
Time: Tue Oct 1 04:44:50 2013 -0400
IP: x.x.x.x
Failures: 5 (pop3d)
Interval: 300 seconds
Blocked: Yes
Log entries:
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.add.ress, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
Oct 1 04:44:34 sabrina dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=client.ip.address, lip=host.ip.add.ress
This is what I find in cron near that time:
0 4 * * * /usr/sbin/cxs --upgrade --quiet
0 4 * * * /usr/local/cpanel/scripts/cpbackup
37 4 * * * /usr/local/cpanel/scripts/upcp --cron
is upcp causing LFD to give erroneous reports? These same accounts check their mail 24 hours a day with no issues, but at this time every day, they are tagged as trying to log in with a bad password. so every morning I have to remove them from iptables and then they are fine until 4:44am the next day.
I also see this just before the above error, everyday.
Time: Wed Oct 9 04:42:01 2013 -0400
Error: Failed to detect code [dVt8TcB7JrCPoQTRBZihM6qjtxoXu] in SYSLOG_LOG [/var/log/messages]
SYSLOG may not be running correctly on sabrina.syo.com
Thanks so much for your insight.
Jason