Guillermo Villanueva 7.Jun.12 04:01 PM a Web browser Domino Server7.0.2All Platforms
Hello, I am getting SMTP attacks in my Linux 7.0.2 Server.
In the log I have the following message repeated thousands of times:
31/05/2012 07:44:56 AM SMTP Server [12807:00016--1584358480] Authentication failed for user user
31/05/2012 07:44:57 AM SMTP Server [12807:00013--1328714832] Authentication failed for user users
31/05/2012 07:44:57 AM SMTP Server [12807:00016--1584358480] Authentication failed for user user
31/05/2012 07:44:59 AM SMTP Server [12807:00013--1328714832] Authentication failed for user users
31/05/2012 07:44:59 AM SMTP Server [12807:00016--1584358480] Authentication failed for user user
31/05/2012 07:45:00 AM SMTP Server [12807:00013--1328714832] Authentication failed for user users
31/05/2012 07:45:00 AM SMTP Server [12807:00016--1584358480] Authentication failed for user user
31/05/2012 07:45:01 AM SMTP Server [12807:00013--1328714832] Authentication failed for user users
31/05/2012 07:45:02 AM SMTP Server [12807:00016--1584358480] Authentication failed for user user
The problem: I can't see the IP, so I can't block it by firewall.
Is there any way to know the IP of the attacker?
Is there any way to block attempts from the same domino?
Something similar happens to me on a Win 6.5.1 server but in this case the attack is POP3
And the messages are as follows:
03/06/2012 09:45:36 p.m. POP3 Server: Authentication failure for craig, connecting host 63.143.42.68: Password not found in the Name and Address Book entry or password did not verify
03/06/2012 09:45:36 p.m. POP3 Server: Authentication failure for claudia, connecting host 63.143.42.68: Password not found in the Name and Address Book entry or password did not verify
03/06/2012 09:45:36 p.m. POP3 Server: Authentication failure for gerald, connecting host 63.143.42.68: Password not found in the Name and Address Book entry or password did not verify
03/06/2012 09:45:36 p.m. POP3 Server: Authentication failure for greg, connecting host 63.143.42.68: Password not found in the Name and Address Book entry or password did not verify
Here I can see the IP address.
Is there any way to block attempts from the same domiPOPno?
I must to use an external firewall to block?