Boat Drinks  

Go Back   Boat Drinks > General > Computer and Consoles

Reply
 
Thread Tools Display Modes
Old 07-02-2007, 19:25   #1
Feek
ex SAS
 
Feek's Avatar
 
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
Angry My email system got hacked...

Came home to find 320 emails showing waiting for me from webmaster@[oneofmydomains.com]

Checked and there was someone connected to my MDaemon pumping message after message into my system spoofing the from address as the webmaster one and because that was aliased to my main address it was accepted.

I think that the only reason it happened was that although the address was aliased to my main one, I didn't have the [oneofmydomains.com] actually specified as a secondary domain within MDaemon.

I added it, removed the alias and it appears to have stopped - There are still connections trying to come in that are being refused by Tarpit so I'm hoping that once whoever was doing it realises that the hole has been patched that they'll stop.

Luckily I don't think anything got out. I'm not blacklisted anywhere which would happen fairly quickly if it had done.

Bastards
__________________
Feek is offline   Reply With Quote
Old 07-02-2007, 19:31   #2
Kell_ee001
Wants Big Meat
 
Kell_ee001's Avatar
 
Join Date: Jul 2006
Location: Newcastle
Posts: 6,478
Default

*hugs*

They suck.

Glad you fixed it though
__________________
Kell_ee001 is offline   Reply With Quote
Old 07-02-2007, 19:34   #3
Fayshun
Rocket Fuel
 
Fayshun's Avatar
 
Join Date: Jun 2006
Location: Adrift in the Orca
Posts: 6,845
Default

Quote:
Originally Posted by Le Feek View Post
Bastards
Exumptly!

Grr
__________________

We must move forward not backward, upwards not forward, and always twirling, twirling, twirling...
Fayshun is offline   Reply With Quote
Old 07-02-2007, 21:46   #4
Feek
ex SAS
 
Feek's Avatar
 
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
Default

Lots of connections from that IP are still coming in, but the tweaks I've made to MDaemon have stopped anything nasty happening. I've got fed up with all the attempts so I've firewalled that address in my router

/edit - Hmm, firewall rule isn't working
__________________

Last edited by Feek; 07-02-2007 at 21:53.
Feek is offline   Reply With Quote
Old 07-02-2007, 22:35   #5
Feek
ex SAS
 
Feek's Avatar
 
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
Default

Hmm, tweaking the config in the router wouldn't block it, which is a pain. That meant it was trying to connect and send mail and after a set number of failed attempts, MDaemon would Tarpit it and not allow connections for 20 minutes, then it'd try again.

I've now added a specific block to that IP within MDaemon and also added a DNSBL lookup to http://korea.services.net/ as it's a Korean IP that's trying to connect.

Nightmare
__________________
Feek is offline   Reply With Quote
Old 08-02-2007, 10:45   #6
Daz
The Stig
 
Daz's Avatar
 
Join Date: Jun 2006
Location: Swad!
Posts: 10,713
Default

Surely there's a problem with your firewall if you cant block it at IP level there? That's what I'd be working on.
__________________
apt-get moo
Daz is offline   Reply With Quote
Old 08-02-2007, 11:35   #7
Feek
ex SAS
 
Feek's Avatar
 
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
Default

I've never had much luck with the firewall built into the router. I'll need to have a look at the manual for it before playing again.

The self-induced hole in MDaemon has been fixed, it's just a case now of persuading them that they're not getting back in.
__________________
Feek is offline   Reply With Quote
Old 08-02-2007, 11:38   #8
Mark
Screaming Orgasm
 
Join Date: Jul 2006
Location: Newbury
Posts: 15,194
Default

I'm with Daz, but then I know how easy it is to set up an IP block on my router - done it several times now.
Mark is offline   Reply With Quote
Old 08-02-2007, 11:50   #9
Feek
ex SAS
 
Feek's Avatar
 
Join Date: Jun 2006
Location: JO01ou
Posts: 10,062
Default

What doesn't help is that they're using multiple IP ranges so if I'm not there to manually add them all it wouldn't matter anyway.

So now they're connecting, they try and fire off a mail, it gets rejected straight away because of my tweaks and because they fail the DNSBL lookup, then after 3 rejects they get tarpitted for 20 minutes and if they don't get done for that then they get done for 10 rapid connections.

(note, none have actually got as far as DNSBL or the 3 rejects, but that's the possible route through )

So nothing is getting in.
__________________
Feek is offline   Reply With Quote
Old 08-02-2007, 11:55   #10
Daz
The Stig
 
Daz's Avatar
 
Join Date: Jun 2006
Location: Swad!
Posts: 10,713
Default

Which is priority one of course Be nice to stop it all before they even get to your mail server though. Are the IP's all on the same /24 perhaps?
__________________
apt-get moo
Daz is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 06:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.