On 2/4/2012 11:47 AM, Pete wrote:
Hello,Can someone confirm that the log excerpt below is most likely a bot of some kind attempting to authenticate to my Postfix server please ?
That looks like a brute force attempt, or at least a bot looking for weak passwords. I see the same things in my logs, too.
The only thing I have found is ConfigServer firewall: http://configserver.com/cp/csf.htmlIt is a dynamic firewall containing a "login failure daemon" that monitors for failed logins on various services, and blocks offending IP's based on your defined thresholds.
I hope that this helps! - Nick Bright
smime.p7s
Description: S/MIME Cryptographic Signature