Displaying 20 results from an estimated 1100 matches similar to: "Disconnecting unauthenticated IMAP entities faster?"
2018 May 18
0
Disconnecting unauthenticated IMAP entities faster?
> On 18 May 2018, at 20.19, David Hubbard <dhubbard at dino.hostasaurus.com> wrote:
>
> Hello, given the 2015 revision date, I was curious if anyone can confirm https://wiki2.dovecot.org/Timeouts is still accurate where the 'before login' IMAP timeout remains hard coded?
>
> We're having an issue where blocks of IP's from China and similar locations are
2019 Mar 06
2
how to enable PowerDNS/Weakforced with Fedora and sendmail
We have dovecot-1:2.3.3-1.fc29.x86_64 running on Fedora 29. I'd like to
test wforce, from https://github.com/PowerDNS/weakforced.
I see instructions at the Authentication policy support page,
https://wiki2.dovecot.org/Authentication/Policy
I see the Required Minimum Configuration:
auth_policy_server_url = http://example.com:4001/
auth_policy_hash_nonce = localized_random_string
But when I
2017 Dec 19
3
detect suspicious logins
does anyone know of a linux module (maybe similar to fail2ban) that
could be installed which would monitor email logs (sign ins) and alert
the user to any suspicious activity on their account? i suspect it
would need to log geo location, device type and ip address to a
database. it seems like a module like this would be very useful and
should exist already? thanks in advance
2019 Apr 12
2
Mail account brute force / harassment
On 11/04/2019 14:33, Anton Dollmaier via dovecot wrote:
>> Which is why a dnsbl for dovecot is a good idea. I do not believe the
>> agents behind these login attempts are only targeting me, hence the
>> addresses should be shared via a dnsbl.
>
> Probably there's an existing solution for both problems (subsequent
> attempts and dnsbl):
>
>>
2019 Apr 11
1
Mail account brute force / harassment
> Am 11.04.2019 um 12:43 schrieb Marc Roos via dovecot <dovecot at dovecot.org>:
>
> Please do not assume anything other than what is written, it is a
> hypothetical situation
>
>
> A. With the fail2ban solution
> - you 'solve' that the current ip is not able to access you
> - it will continue bothering other servers and admins
> - you get the
2018 May 21
2
Dovecot blacklist?
Just wondering if there is an easy way to have dovecot do a blacklist
lookup as a negative authentication so that if the IP is on a blacklist
then authentification fails even if they get the password right.
If this works I have a blacklist everyone can use.
2019 Apr 11
5
Mail account brute force / harassment
On Thu, 11 Apr 2019 at 13:24, Marc Roos via dovecot <dovecot at dovecot.org>
wrote:
>
>
> Say for instance you have some one trying to constantly access an
> account
>
>
> Has any of you made something creative like this:
>
> * configure that account to allow to login with any password
> * link that account to something like /dev/zero that generates infinite
2016 Jun 27
2
Suggestion: Split login_trusted_networks
Hi,
For the upcoming 2.3 development, I'd like to re-suggest this:
It seems the use of login_trusted_networks is overloaded.
Example:
* It's used for indicating which hosts you trust to provide XCLIENT
remote IP's. (like a proxy)
* It's used for indicating from which hosts you trust logins enough to
disable auth penalty. (like in a webmail)
Often these two uses cases have a
2017 Jun 30
2
Auth Policy Server
I've made a preliminary auth policy server in Perl - and it sort of
works (mostly) - but I've got some questions on "proper" implementation.
It appears the communication is HTTP based - is the intent to talk to a
"proper" webserver, or is a simple dedicated daemon appropriate (which
is what I made)?
Should connections be maintained, or terminated after each
2020 Apr 22
1
Recommendations on intrusion prevention/detection?
<!doctype html>
<html>
<head>
<meta charset="UTF-8">
</head>
<body>
<div>
<br>
</div>
<blockquote type="cite">
<div>
On 22/04/2020 19:56 Benny Pedersen <
<a href="mailto:me@junc.eu">me@junc.eu</a>> wrote:
</div>
<div>
<br>
2019 Apr 11
5
Mail account brute force / harassment
On 11/04/2019 11:43, Marc Roos via dovecot wrote:
> A. With the fail2ban solution
> - you 'solve' that the current ip is not able to access you
It is only a solution if there are subsequent attempts from the same
address. I currently have several thousand addresses blocked due to
dovecot login failures. My firewall is set to log these so I can see
that few repeat, those
2017 Oct 20
2
Post-login scripting
No, it's entirely my own.
If all you want to do is write client IP addresses to a database then your script will probably fit in 20 lines of code or so.
On 10/20/2017 05:04 PM, j.emerlik wrote:
> Which one policy server are you using ?
> Someone from that list : http://www.postfix.org/addon.html
>
> 2017-10-20 16:53 GMT+02:00 Gedalya <gedalya at gedalya.net>:
>
>>
2017 Oct 16
2
Filtering by country
Is it possible to filter out logins by country (I would like to limit dovecot instance users to log in only from specific countries)???
Anvar?Kuchkartaev?
anvar at anvartay.com?
2018 May 21
1
Dovecot blacklist?
Or you can implement a policy server yourself. :)The protocol is not complicated, json over http. See?https://wiki.dovecot.org/Auth/Policy
---Aki TuomiDovecot oy
-------- Original message --------From: Aki Tuomi <aki.tuomi at dovecot.fi> Date: 21/05/2018 19:13 (GMT+02:00) To: Marc Perkel <marc at perkel.com>, dovecot at dovecot.org Subject: Re: Dovecot blacklist?
2016 Aug 05
3
Dovecot password policy
> On August 5, 2016 at 6:47 PM "Michael A. Peters" <mpeters at domblogger.net> wrote:
>
>
> On 08/05/2016 08:41 AM, Robert Blayzor wrote:
> > Is there a way to configure Dovecot to perhaps filter/enforce which passwords are accepted before authenticating?
> >
> > Ie: Reject immediately (without a database lookup) if password is not X characters in
2017 Jun 30
1
Auth Policy Server
On 6/30/2017 12:05 PM, Aki Tuomi wrote:
>> On June 30, 2017 at 9:49 PM Daniel Miller <dmiller at amfes.com> wrote:
>>
>>
>> I've made a preliminary auth policy server in Perl - and it sort of
>> works (mostly) - but I've got some questions on "proper" implementation.
>>
>>
> Hi!
>
> First of all, which version are you
2017 Jul 20
3
under some kind of attack
Hi all,
If I may, one more question on this subject:
I would like to create a fail2ban filer, that scans for these lines:
> Jul 20 11:10:09 auth: Info: ldap(user1,60.166.35.162,<cDFXHbxUQgA8piOi>): invalid credentials (given password: password)
> Jul 20 11:10:19 auth: Info: ldap(user2,61.53.66.4,<V+nyHbxU+wA9NUIE>): invalid credentials (given password: password)
(as you can
2017 Oct 21
2
Post-login scripting
Aha. Looks pretty cool, and it's really nice that it supports HTTP.
On the other hand if I'm rate limiting the number of messages sent = number of times a client said RCPT TO, I guess it still has to be a postfix policy server?
Anyway, thanks for pointing this out, I'm sure I'll use it :-)
On 10/21/2017 02:16 PM, Aki Tuomi wrote:
> Dovecot auth supports auth_policy_server
2017 Jun 12
1
Log authentication attempts
I need to save that to database because I have more then one mail server
and them must share each other failed login attempts information.
I'll try check how Dovecot Authentication Policy works.
--JAcek
2017-06-12 16:50 GMT+02:00 Leonardo Rodrigues <leolistas at solutti.com.br>:
> Em 12/06/17 09:39, j.emerlik escreveu:
>
>> Failed login attempts information may be useful
2015 Feb 17
0
Controlling inactivity timeout for IMAP
Andr? Peters writes:
> > I have a problem with a user who uses a wireless carrier that keeps
> > changing his IP as he travels throughout the city. From the perspective
> > of our dovecot IMAP server, the user keeps logging in from another IP,
> > and after a short while, hits up against the mail_max_userip_connections
> > limit. It takes 30 minutes before those