I checked my exim_mainlog and i'm constantly getting this:
Is there a way to auto detect the IP and add auto block it?
I tried to mess around with the
cPHulk Brute Force Protection
But I don't think its doing much or i'm configuring it wrong. I even add that IP to the blacklist but I still see it in the mail log.
Anyone know the correct way to set this up?
Code:
2018-07-13 13:14:18.693 [16555] SMTP connection from [103.225.140.126]:51134 I=[192.254.130.159]:26 (TCP/IP connection count = 3)
2018-07-13 13:14:18.781 [19770] list matching forced to fail: failed to find host name for 103.225.140.126
2018-07-13 13:14:18.781 [19770] list matching forced to fail: failed to find host name for 103.225.140.126
2018-07-13 13:14:22.462 [19770] dovecot_plain authenticator failed for (10.12.22.73) [103.225.140.126]:51134 I=[192.254.130.159]:26: 535 Incorrect authentication data ([email protected])
2018-07-13 13:14:22.701 [19770] SMTP connection from (10.12.22.73) [103.225.140.126]:51134 I=[192.254.130.159]:26 lost D=4.006s
2018-07-13 13:14:22.701 [19770] no MAIL in SMTP connection from (10.12.22.73) [103.225.140.126]:51134 I=[192.254.130.159]:26 D=4.007s C=EHLO,STARTTLS,EHLO,AUTH
I tried to mess around with the
cPHulk Brute Force Protection
But I don't think its doing much or i'm configuring it wrong. I even add that IP to the blacklist but I still see it in the mail log.
Anyone know the correct way to set this up?
Last edited by a moderator: