Brute force attack on Dovecot not detected
Posted: 01 May 2011, 16:41
Our server has been grinding to a halt because of brute force login attempts on POP3 and CSF isn't detecting it.
Example of mail log:
May 1 03:49:17 vendsmart dovecot: auth(default): pam(alex,::ffff:205.217.244.10): PAM child process 7194 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(customer,::ffff:205.217.244.10): PAM child process 7205 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(accounts,::ffff:205.217.244.10): PAM child process 6014 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(adm,::ffff:205.217.244.10): PAM child process 6015 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(access,::ffff:205.217.244.10): PAM child process 5974 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(account,::ffff:205.217.244.10): PAM child process 5977 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(agent,::ffff:205.217.244.10): PAM child process 7193 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(alex,::ffff:205.217.244.10): PAM child process 7194 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(mail,::ffff:205.217.244.10): PAM child process 7304 timed out, killing it
Example of mail log:
May 1 03:49:17 vendsmart dovecot: auth(default): pam(alex,::ffff:205.217.244.10): PAM child process 7194 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(customer,::ffff:205.217.244.10): PAM child process 7205 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(accounts,::ffff:205.217.244.10): PAM child process 6014 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(adm,::ffff:205.217.244.10): PAM child process 6015 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(access,::ffff:205.217.244.10): PAM child process 5974 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(account,::ffff:205.217.244.10): PAM child process 5977 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(agent,::ffff:205.217.244.10): PAM child process 7193 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(alex,::ffff:205.217.244.10): PAM child process 7194 timed out, killing it
May 1 03:49:17 vendsmart dovecot: auth(default): pam(mail,::ffff:205.217.244.10): PAM child process 7304 timed out, killing it