Web Hosting Talk







View Full Version : dictionary attacks and rate limiting


tonj
09-22-2010, 03:53 PM
cobalt raq server running centos 4.8
sendmail-8.13.1-3.3.el4

I'm concerned about the numerous dictionary attacks I see in my daily server.mail.log My server hasn't been compromised but I hoped...
1) there might be a way to configure the server so that if a mail-sending ip failed twice in a row it would be automatically blacklisted or blocked in some way. Can this be done?
2) I'd like to limit the number of outbound emails that can be sent per unit time. Is there a way to do this?

gnetwerker
02-26-2011, 11:15 PM
You'll want to look into "Fail2Ban". It can be put on your system with a minimum amount of work, though it does need some skill.

c0op3r
02-27-2011, 04:03 PM
You'll want to look into "Fail2Ban". It can be put on your system with a minimum amount of work, though it does need some skill.

gnetwerker

I just wanted to leave a note that I am very glad to see someone with good Cobalt/Linux knowledge back in this forum, I truly believe that there is a small group of people out there who get Cobalt RaQ units that will need help in setting these machines up. (I was [and to a point still am one of these]).

I know that there are plenty of them in service as Web Servers all over the world, but they have become cheap enough that the common hobbyist can get a nice unit off eBay (or maybe de-commissioned from their work) that I think having an active and knowledgeable place for them to ask questions and share information is important.

I personally have only had mine for a couple months now, and have found a few people that are knowledgeable about them (yourself included in this group), but no ACTIVE place to exchange information. I hope that this can be the re-state of this forum as other search and find it, and notice that it is not DEAD and there are new post.

Again thanx so much and hope to see you here often.

________________
c0op3r - c0op3r.com