07-02-2007, 19:25 | #1 |
ex SAS
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
|
My email system got hacked...
Came home to find 320 emails showing waiting for me from webmaster@[oneofmydomains.com]
Checked and there was someone connected to my MDaemon pumping message after message into my system spoofing the from address as the webmaster one and because that was aliased to my main address it was accepted. I think that the only reason it happened was that although the address was aliased to my main one, I didn't have the [oneofmydomains.com] actually specified as a secondary domain within MDaemon. I added it, removed the alias and it appears to have stopped - There are still connections trying to come in that are being refused by Tarpit so I'm hoping that once whoever was doing it realises that the hole has been patched that they'll stop. Luckily I don't think anything got out. I'm not blacklisted anywhere which would happen fairly quickly if it had done. Bastards
__________________
|
07-02-2007, 19:31 | #2 |
Wants Big Meat
Join Date: Jul 2006
Location: Newcastle
Posts: 6,478
|
*hugs*
They suck. Glad you fixed it though
__________________
|
07-02-2007, 19:34 | #3 |
Rocket Fuel
Join Date: Jun 2006
Location: Adrift in the Orca
Posts: 6,845
|
__________________
We must move forward not backward, upwards not forward, and always twirling, twirling, twirling... |
07-02-2007, 21:46 | #4 |
ex SAS
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
|
Lots of connections from that IP are still coming in, but the tweaks I've made to MDaemon have stopped anything nasty happening. I've got fed up with all the attempts so I've firewalled that address in my router
/edit - Hmm, firewall rule isn't working
__________________
Last edited by Feek; 07-02-2007 at 21:53. |
07-02-2007, 22:35 | #5 |
ex SAS
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
|
Hmm, tweaking the config in the router wouldn't block it, which is a pain. That meant it was trying to connect and send mail and after a set number of failed attempts, MDaemon would Tarpit it and not allow connections for 20 minutes, then it'd try again.
I've now added a specific block to that IP within MDaemon and also added a DNSBL lookup to http://korea.services.net/ as it's a Korean IP that's trying to connect. Nightmare
__________________
|
08-02-2007, 10:45 | #6 |
The Stig
Join Date: Jun 2006
Location: Swad!
Posts: 10,713
|
Surely there's a problem with your firewall if you cant block it at IP level there? That's what I'd be working on.
__________________
apt-get moo |
08-02-2007, 11:35 | #7 |
ex SAS
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
|
I've never had much luck with the firewall built into the router. I'll need to have a look at the manual for it before playing again.
The self-induced hole in MDaemon has been fixed, it's just a case now of persuading them that they're not getting back in.
__________________
|
08-02-2007, 11:38 | #8 |
Screaming Orgasm
Join Date: Jul 2006
Location: Newbury
Posts: 15,194
|
I'm with Daz, but then I know how easy it is to set up an IP block on my router - done it several times now.
|
08-02-2007, 11:50 | #9 |
ex SAS
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
|
What doesn't help is that they're using multiple IP ranges so if I'm not there to manually add them all it wouldn't matter anyway.
So now they're connecting, they try and fire off a mail, it gets rejected straight away because of my tweaks and because they fail the DNSBL lookup, then after 3 rejects they get tarpitted for 20 minutes and if they don't get done for that then they get done for 10 rapid connections. (note, none have actually got as far as DNSBL or the 3 rejects, but that's the possible route through ) So nothing is getting in.
__________________
|
08-02-2007, 11:55 | #10 |
The Stig
Join Date: Jun 2006
Location: Swad!
Posts: 10,713
|
Which is priority one of course Be nice to stop it all before they even get to your mail server though. Are the IP's all on the same /24 perhaps?
__________________
apt-get moo |