Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Huge increase of Dovecot Brute Force

Discussion in 'Security' started by hello-electro, Apr 22, 2017.

Tags:
  1. hello-electro

    hello-electro Member

    Joined:
    Aug 9, 2016
    Messages:
    17
    Likes Received:
    1
    Trophy Points:
    3
    Location:
    Maryland
    cPanel Access Level:
    Root Administrator
    Anyone else getting bruteforce notices against dovecot? I am up to about 1 per 3 minute. Its coming from a botnet, so no way for me to just block a single IP. There is only a minor mention of a timing vulnerability that i can find online. Is cPanel folks aware of this, or have any suggestions to ensure the bruteforce doesn't lead to a successful comprimise?
     
  2. BlackRain

    BlackRain Well-Known Member

    Joined:
    May 28, 2003
    Messages:
    51
    Likes Received:
    0
    Trophy Points:
    156
    Location:
    USA
    cPanel Access Level:
    Root Administrator
    Yep. I have noticed the same activity from IP's all over the world trying to brute force Dovecot credentials. There must be an exploit in the wild. Have not seen any notice from Cpanel about this issue.
     
  3. hello-electro

    hello-electro Member

    Joined:
    Aug 9, 2016
    Messages:
    17
    Likes Received:
    1
    Trophy Points:
    3
    Location:
    Maryland
    cPanel Access Level:
    Root Administrator
    I have a link to what may be a known exploit (nothing I discovered), though its a few weeks old at this point, so the attempts may just be residual at this point. I'm going to send the cPanel folks a support ticket with it.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    38,658
    Likes Received:
    1,425
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    Internal case CPANEL-12790 was opened to inquire about that specific vulnerability. We'll update the version of Dovecot offered through cPanel with any security-related patches once Dovecot publishes them upstream.

    In addition to using cPHulk, you may also want to consider using a third-party application such as CSF to help protect against brute force attempts:

    ConfigServer Security & Firewall (csf)

    Thank you.
     
  5. BlackRain

    BlackRain Well-Known Member

    Joined:
    May 28, 2003
    Messages:
    51
    Likes Received:
    0
    Trophy Points:
    156
    Location:
    USA
    cPanel Access Level:
    Root Administrator
    Already use CPHulk and CSF, yet we are getting hundreds of Dovecot brute forces attempts (mostly from China and dubious EU server farms).

    We have black listed those IP ranges yet new ones keep popping up.

    We don't use any server side email so it's a wasted attempt on their part.

    So that leads me to believe there is an exploit out there.
     
  6. Jasminder pal Singh

    Jasminder pal Singh Registered

    Joined:
    May 30, 2017
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Punjab
    cPanel Access Level:
    Root Administrator
    Hey ,
    Any update on this yet ?
     
  7. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    38,658
    Likes Received:
    1,425
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    The particular vulnerability referenced earlier in this thread is addressed by Dovecot in Dovecot 2.2.30:

    Internal case CPANEL-13448 is open for the inclusion of this version of Dovecot into cPanel & WHM. I'll update this thread with more information on the status of this case as it becomes available.

    Thank you.

    Edit: Dovecot 2.2.31 is now included with cPanel version 66:

    Implemented case CPANEL-14248: Update dovecot to 2.2.31-1.cp1162.
     
    #7 cPanelMichael, Jun 1, 2017
    Last edited: Jul 18, 2017
Loading...

Share This Page