This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Email server issues
#1
Email server issues
Good afternoon all.  I have been using this control panel since Zpanel 6 early days.  I'm running Sentora on Ubuntu 14.04 server. For the second time in a month, my VPS hoster has stopped the mail service on my node because the server seems to be getting hacked and used a relay agent.  I am not the smartest person when it comes to dovecot, postfix, and Linux security, but am really trying to learn.

I have tried many things to stop this; including learning and using IPtables.  I currently only allow the following ports in OR out: 80, 143, ssh, ftp, imaps, pop3s, smtps (587) and DNS.  I also have postfix setup to where you cannot send email unless you authenticate with a valid email account that is on the server.

I am not sure what else to do. My mailqueue shows i have 2,100 pending deliveries (which i have cleared).  Earlier this month it was over 103,000. The email address they show to be sending from is a valid email account on the server but is only used for internal things. Any help would be great appreciate it.  Not sure what logs/config files you would want to see. So, if you need to see something, just let me know.

Thanks in advance!!
Reply
Thanks given by:
#2
RE: Email server issues
first thing would be to delete that email account and make another one. also change email related passwords.
@[Me.b] can help you with the rest, he is good with Sentora's email system (I used Windows so I am starting to learn my self also)
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:
#3
RE: Email server issues
1. Did you confirm it's not a hack on any website? As the sender seem a valid email here I think they have likely hacked the account that had a weak password. Could you check dovecot logs for login failure before the email spree.

2. One solution is adding fail2ban to the server and activating it to monitor dovecot & postfix logs, so IT will flag & ban brute force attacks. Take car fail2ban default settings are not good as you need to correct the log path.

M B
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#4
RE: Email server issues
Thanks for the reply! I will work on this today to hopefully get a resolution. Been working a lot so i haven't been able to respond like i wanted. I'll let you know the outcome.
Reply
Thanks given by:


Possibly Related Threads…
Thread Author Replies Views Last Post
Email has suddenly stopped coming through rsthomas 4 4 ,906 10-12-2022, 09:29 PM
Last Post: rsthomas
External mail client cannot connect to server iraqiboy90 2 6 ,321 02-28-2021, 11:34 AM
Last Post: iraqiboy90
can not send email - SMTP error on roundcube wolvepy 9 29 ,480 01-03-2020, 08:37 AM
Last Post: Telepuzik

Forum Jump:


Users browsing this thread: 1 Guest(s)