Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Strange E-Mail Logins from non existent account

Discussion in 'E-mail Discussion' started by jasgot, Mar 2, 2019.

  1. jasgot

    jasgot Well-Known Member

    Joined:
    Mar 2, 2004
    Messages:
    59
    Likes Received:
    2
    Trophy Points:
    158
    Please know, this account does NOT exist! Yet it can login!!!!!

    I have found an account that is successfully logging in to imap from one IP and failing to log in from another IP. the strange thing is, the account doesn't exist!

    Have a look at these two log entries and also at the Remote IP:

    Code:
    Mar  1 15:08:17 64 dovecot: imap-login: Login: user=<[email protected]>, method=PLAIN, rip=[Removed IP], lip=MYSERVERIP, mpid=60339, TLS, session=<ubq/9w2DxIVENzdf>
    
    Mar  1 18:08:26 64 dovecot: imap-login: Aborted login (auth failed, 1 attempts in 2 secs): user=<[email protected]>, method=PLAIN, rip=[Removed IP], lip=MYSERVERIP, TLS, session=<9bfhexCDNMpEPEey>

    The rub is that the remote IPs are both end user locations, neither are listed in CFS Allow lists, and when the customer gets to the failed IP location, everyone behind that IP gets blocked and it is creating a problem.

    What do you make of this?
     
    #1 jasgot, Mar 2, 2019
    Last edited by a moderator: Mar 4, 2019
  2. keat63

    keat63 Well-Known Member

    Joined:
    Nov 20, 2014
    Messages:
    1,291
    Likes Received:
    91
    Trophy Points:
    28
    cPanel Access Level:
    Root Administrator
    did the account ever exist ?
     
  3. cPanelLauren

    cPanelLauren Forums Analyst II Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    6,459
    Likes Received:
    503
    Trophy Points:
    263
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    That account isn't actually logging in though, the next line clearly states that the login failed:

    Code:
    Mar  1 18:08:26 64 dovecot: imap-login: Aborted login (auth failed, 1 attempts in 2 secs): user=<[email protected]>, method=PLAIN, rip=[Removed IP], lip=MYSERVERIP, TLS, session=<9bfhexCDNMpEPEey>
    
    This is just a failed auth attempt based on the log excerpt you're showing here.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice