Path: csiph.com!fu-berlin.de!news.servidellagleba.it!bofh.it!news.nic.it!robomod From: "Maurizio Caloro" Newsgroups: linux.debian.user Subject: AW: Knocking on the door Date: Sat, 18 May 2024 15:30:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-user-request@lists.debian.org Sat May 18 13:22:50 2024 Old-Return-Path: X-Amavis-Spam-Status: No, score=-7.1 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FOURLA=0.1, LDO_WHITELIST=-5] autolearn=ham autolearn_force=no X-Policyd-Weight: using cached result; rate: -4.6 Dkim-Filter: OpenDKIM Filter v2.11.0 nmail.caloro.ch 4F0D042F20 Reply-To: Dmarc-Filter: OpenDMARC Filter v1.4.2 nmail.caloro.ch A3B2E42F1C Authentication-Results: nmail; dmarc=fail (p=quarantine dis=none) header.from=caloro.ch Dkim-Filter: OpenDKIM Filter v2.11.0 nmail.caloro.ch A3B2E42F1C Authentication-Results: nmail.caloro.ch; dkim=none; dkim-atps=neutral Organization: Caloro.ch MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Thread-Index: AQHl92kPr9M2S+MVZS1F3ccLanIuxQL8Jg9ZsW55UqA= Content-Language: de-ch X-Mailing-List: archive/latest/811463 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/001601daa926$6d027560$47076020$@caloro.ch Approved: robomod@news.nic.it Lines: 78 Sender: robomod@news.nic.it X-Original-Cc: "'Charles Curley'" , X-Original-Date: Sat, 18 May 2024 15:22:26 +0200 X-Original-Message-ID: <001601daa926$6d027560$47076020$@caloro.ch> X-Original-References: <89598D0F-23F2-43A7-A0CC-4AA9F4D0BACC@caloro.ch> <20240517104439.01d4bff5@hawk.localdomain> Xref: csiph.com linux.debian.user:269449 Hello Thanks for reply yes, i have put now this, I have peace now =F0=9F=98=8A #cat postfix-addon.conf [INCLUDES] before =3D common.conf [Definition] _daemon =3D postfix/smtpd failregex =3D ^%(__prefix_line)sNOQUEUE: reject: RCPT from = \S+\[\]: 554 5\.2\.1 .*$ ^%(__prefix_line)sNOQUEUE: reject: RCPT from \S+\[\]: 450 4\.6\.1 = : Helo command rejected: Host not found; to=3D<> from=3D<> = bcc=3D<> Yproto=3DESMTP helo=3D *$ ^%(__prefix_line)sNOQUEUE: reject: VRFY from \S+\[\]: 550 5\.4\.1 = .*$ ^%(__prefix_line)sNOQUEUE: reject: RCPT from \S+\[\]: 454 4\.7\.2 = :*$ reject: RCPT from (.*)\[\]: 550 5.2.1 reject: RCPT from (.*)\[\]: 450 4.6.1 reject: RCPT from (.*)\[\]: 554 5.4.1 reject: RCPT from unknown\[\]: 454 4.7.2 connect from unknown\[\] ignoreregex =3D -- you cannot fail unless you quit! -----Urspr=C3=BCngliche Nachricht----- Von: Charles Curley =20 Gesendet: Freitag, 17. Mai 2024 18:45 An: Debian Users Betreff: Re: Knocking on the door On Fri, 17 May 2024 15:49:52 +0200 Maurizio Caloro wrote: >=20 > Hello >=20 >=20 > Please i know that this arn't the Dovecot forum, but let me try, on=20 > the log's i have always knocking "unknown user" attempts. >=20 >=20 > > May 15 22:39:31 Dovecot/auth-worker(2602036): Info: conn=20 > > unix:auth-worker (pid=3D2602030,uid=3D113): > > auth-worker<49>:sql(bin@domain.ch,194.169.175.10): unknown user I only see one record here. fail2ban requires multiple attempts within a = certain period before it will ban the source address.=20 >=20 >=20 > yes i try with fail2ban, but i didn't see or found the right regex, so = > that this will be blocked please has any from you solve this knocking=20 > task? Are you sure you want to worry about it? dovecot seems to be doing its = job by refusing access to unknown users. If you see repeated attempts from the same source, you might want to = craft a firewall rule to ban that source (or than network). Show us the files you have modified so we can see what you are doing. >=20 >=20 > thanks > -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/