i just love

Forum for things that doesn't really have anything to do with hMailServer. Such as php.ini, beer, etc etc.
Post Reply
User avatar
johang
Senior user
Senior user
Posts: 286
Joined: 2008-09-01 09:20

i just love

Post by johang » 2020-08-03 08:55

love.jpg
sometimes i just love seing mailfunctioning scripting in work ..

( yes yes Palinka I KNOW i should do firewall ban.. i am just low maintainance lazy .. )
___________________________________________________________end of the line
spam filter appliance gateway: www.mailcleaner.org

User avatar
jimimaseye
Moderator
Moderator
Posts: 8674
Joined: 2011-09-08 17:48

Re: i just love

Post by jimimaseye » 2020-08-03 09:16

There is a post on the forum somewhere of a screenshot where i received 3.5 thousand autobans overnight. It looked scary until you realise that it's just hmailserver doing its job very well.

Why do you say it a malfunctioning script? Do you mean one of your scripts?

[Entered by mobile. Excuse my spelling.]
5.7 on test.
SpamassassinForWindows 3.4.0 spamd service
AV: Clamwin + Clamd service + sanesecurity defs : https://www.hmailserver.com/forum/viewtopic.php?f=21&t=26829

User avatar
johang
Senior user
Senior user
Posts: 286
Joined: 2008-09-01 09:20

Re: i just love

Post by johang » 2020-08-03 11:10

jimimaseye wrote:
2020-08-03 09:16
There is a post on the forum somewhere of a screenshot where i received 3.5 thousand autobans overnight. It looked scary until you realise that it's just hmailserver doing its job very well.

Why do you say it a malfunctioning script? Do you mean one of your scripts?

[Entered by mobile. Excuse my spelling.]
my reason to call it malfunction is that they actually try to authenticate with "number"name@domain.xx , so their script passes (for example) number 400 in their spam address list as included in emailadddress .. hilarious ..

for instance me actually having "371.spikesley@mydomain.com" as user are almost less then 0% propability in my case :D :D :D and they ask me with and without attached domainname from different IPaddresses ... ( if they wanted just to check for open relay, they could have stopped after 1 try, but these guys try to authenticate from multiple locations with same "username" )
___________________________________________________________end of the line
spam filter appliance gateway: www.mailcleaner.org

palinka
Senior user
Senior user
Posts: 1998
Joined: 2017-09-12 17:57

Re: i just love

Post by palinka » 2020-08-04 14:22

johang wrote:
2020-08-03 08:55
( yes yes Palinka I KNOW i should do firewall ban.. i am just low maintainance lazy .. )
Yeah, baby!!!

Just a dictionary attack. These bot nets are massive. So big they can have individual IPs hit you once and never return. 60% of my firewall bans never return for a second attack.

They're in the long game. Once they verify a user, they'll start attacking based on passwords. The whole thing is brute force that might take years but they'll keep trying no matter how futile it appears.

It hardly costs them anything.

Post Reply