I’m getting lots and lots of these types of login attempts;

warning: unknown[45.125.65.52]: SASL LOGIN authentication failed: UGFzc3dvcmQ6  
              (postfix log)
Info: pam(s...@robert-chalmers.uk,45.125.65.52): unknown user (given password: 
sale01)        (dovecot log)

and I’m wondering if there is someway - other than what I have - of blocking 
them, or automatically adding their IP to a <badhosts> list that I have for 
pfctl.

This is a bit more of the Postfix log.

Jul 06 06:45:59 www postfix/smtpd[3643]: > unknown[45.125.65.52]: 334 
VXNlcm5hbWU6
Jul 06 06:45:59 www postfix/smtpd[3643]: < unknown[45.125.65.52]: c3RvcmU=
Jul 06 06:45:59 www postfix/smtpd[3643]: xsasl_dovecot_handle_reply: auth 
reply: CONT?1?UGFzc3dvcmQ6
Jul 06 06:45:59 www postfix/smtpd[3643]: > unknown[45.125.65.52]: 334 
UGFzc3dvcmQ6
Jul 06 06:45:59 www postfix/smtpd[3643]: < unknown[45.125.65.52]: c3RvcmUhQCM=
Jul 06 06:46:03 www postfix/smtpd[3643]: xsasl_dovecot_handle_reply: auth 
reply: FAIL?1?user=store
Jul 06 06:46:03 www postfix/smtpd[3643]: warning: unknown[45.125.65.52]: SASL 
LOGIN authentication failed: UGFzc3dvcmQ6
Jul 06 06:46:03 www postfix/smtpd[3643]: > unknown[45.125.65.52]: 535 5.7.8 
Error: authentication failed: UGFzc3dvcmQ6
Jul 06 06:46:03 www postfix/smtpd[3643]: watchdog_pat: 0x7ff1b472fdc0
Jul 06 06:46:03 www postfix/smtpd[3643]: < unknown[45.125.65.52]: QUIT
Jul 06 06:46:05 www postfix/smtpd[3643]: > unknown[45.125.65.52]: 221 2.0.0 Bye
Jul 06 06:46:05 www postfix/smtpd[3643]: match_hostname: 
smtpd_client_event_limit_exceptions: unknown ~? 151.225.136.134
Jul 06 06:46:05 www postfix/smtpd[3643]: match_hostaddr: 
smtpd_client_event_limit_exceptions: 45.125.65.52 ~? 151.225.136.134
Jul 06 06:46:05 www postfix/smtpd[3643]: match_hostname: 
smtpd_client_event_limit_exceptions: unknown ~? 94.1.23.155
Jul 06 06:46:05 www postfix/smtpd[3643]: match_hostaddr: 
smtpd_client_event_limit_exceptions: 45.125.65.52 ~? 94.1.23.155

thanks
robert

Reply via email to