NotReal wrote:
I recently had over 53,000 login attempts in a little over 3 hours
from a single IP address on my sendmail mail server. There were some
names that must have been obtained from email lists, but 99% were
almost every name you could possibly think of. I am guessing they
were probably looking for a way to gain access to relay spam, but
regardless of the reason, I would like to figure out a way to limit
or stop such attempts. As near as I can tell there is no way of configuring sendmail to limit logins to the LAN (whitelist), but I
would rank my sendmail skills closer to novice than guru. As a
result I thought I would risk ridicule and ask here to be sure before
looking at solutions such as fail2ban.
Thanks to all who replied and I have read your comments and
suggestions.
I did block that particular IP address at the firewall but I suspect it
is a case of closing the barn door after the horse has gone. The next
time any similar attack occurs, it will probably come from a new IP
address.
I like the suggestion to limit authentication only on port 587 as I
suspect most users are currently using port 587 when authenticating to
receive mail. It will definitely take some reading on my part though
as there are some unknowns about how that would work when sending mail,
but it seems like a worthwhile approach.
I have never heard of crowdsec but I will look into that as well. I
currently use fail2ban on a decoy SSH server feeding blocklist.de so I
am familiar with how to set that up, but perhaps crowdsec has some
features that are not available in fail2ban and tcpwrappers that were
also suggested.
As for Henning and Mr. Sendmail, Claus, their suggestions will take
some more study of sendmail to fully understand and appreciate, but I
will endeavour to do that if only for the learning experience.
Thanks again to all.
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)