On 2/4/2012 11:47 AM, Pete wrote:
Hello,

Can someone confirm that the log excerpt below is most likely a bot of
some kind attempting to authenticate to my Postfix server please ?


That looks like a brute force attempt, or at least a bot looking for weak passwords. I see the same things in my logs, too.

The only thing I have found is ConfigServer firewall:

http://configserver.com/cp/csf.html

It is a dynamic firewall containing a "login failure daemon" that monitors for failed logins on various services, and blocks offending IP's based on your defined thresholds.

I hope that this helps!

 - Nick Bright

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to