B
B
beetlezilla2017-09-13 10:45:10
postfix
beetlezilla, 2017-09-13 10:45:10

How to identify the fact of hacking a user's mailbox?

There is a postfix + dovecot + spamassassin mail server. Periodically, by brute force, they select a password for mailboxes. After several hacking facts, the following parameters were configured

  1. anvil_rate_time_unit 24h
  2. smtpd_client_message_rate_limit 1000

The number of sent letters and the chippers that came to them has been significantly reduced. But at the same time, it has now become more difficult to record the facts of hacking.
60c50d8ae51b464cb54898814ba5eac7.png12afaabf44cc43bf85e5dcb8dbb3f8bf.png
Is it possible to notify mail server administrators about reaching the limit of sent emails for a given period?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
D
Dmitry, 2017-09-13
@Tabletko

Set fail2ban to monitor the mail log and ban those IPs from which more than 5-10 incorrect login attempts per minute were made.

A
alexander, 2017-09-13
@beza2000

It's not pretty, but it's stupid to parse the log and count the necessary numbers. After analyzing the numbers, send a letter to the admins.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question