* dovecot 설치 후 무수히 들어오는 brute force.
# cat /var/log/maillog
dovecot: pop3-login: Disconnected: user=<info@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<admin@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<test@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<server@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<sales@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<account@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<sales@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<support@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<sales@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<spam@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<monitor@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<info@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<postmaster@xxx.com>, method=PLAIN, rip=75.145.57.65...
dovecot: pop3-login: Disconnected: user=<comercial@xxx.com>, method=PLAIN, rip=75.145.57.65...
pop3 포트를 바꾸면 해결될지...(기본:110)
# vi /etc/dovecot.conf
protocol pop3 {
listen = *:10110
}
* smtp 인증으로 들어오는 이건...
# cat /var/log/messages
saslauthd[2672]: do_auth : auth failure: [user=fgjfg] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
saslauthd[2673]: do_auth : auth failure: [user=fgjfg] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
saslauthd[2672]: do_auth : auth failure: [user=fgjfg] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
saslauthd[2673]: do_auth : auth failure: [user=fgjfg] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
이건 뭐... 그냥 방치해야되나...
WRITTEN BY
- 손가락귀신
정신 못차리면, 벌 받는다.