Koozali.org: home of the SME Server

Obsolete Releases => SME 9.x Contribs => Topic started by: SchulzStefan on November 12, 2017, 04:29:50 PM

Title: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: SchulzStefan on November 12, 2017, 04:29:50 PM
The IP 212.83.168.232 attempts a lot times against Qpsmtpd.

https://www.talosintelligence.com/reputation_center/lookup?search=212.83.168.232 (https://www.talosintelligence.com/reputation_center/lookup?search=212.83.168.232)

brings up:

Hostname   front.koozali.org

What does this mean?

regards,
stefan
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: Daniel B. on November 12, 2017, 05:27:10 PM
This is the main IP address of Koozali's infra, including the one emails of our mailing lists are sent from. When you say "attempts" I guess you mean this server tries to deliver emails to you, which is probably legitimate. Please send any further info to security@contribs.org and we'll investigate if necessary
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: Daniel B. on November 12, 2017, 06:48:52 PM
Please send me directly some logs of those SMTP transactions (from your qpsmtpd logs)
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: SchulzStefan on November 13, 2017, 09:54:54 AM
This might have been the reason:

#config show qpsmtpd BadCountries
qpsmtpd=service
    BadCountries=snip - FR - snip

I deleted FR from my list and will report back, if this helped.

regards,
stefan
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: Daniel B. on November 13, 2017, 09:57:07 AM
This certainly can be a reason ;-)
Koozali infra is hosted in France indeed
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: SchulzStefan on November 14, 2017, 02:13:59 PM
It was the reason.

regards,
stefan
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: CharlieBrady on November 21, 2017, 07:36:19 PM
#config show qpsmtpd BadCountries
qpsmtpd=service
    BadCountries=snip - FR - snip

NATO allies, are they not?
Title: Re: Fail2Ban against Qpsmtpd IP 212.83.168.232
Post by: SchulzStefan on November 21, 2017, 09:07:45 PM
NATO allies, are they not?

They are, of course. My bad. I should trust any French IP. J'aime beaucoup nos amis francaise. And it's not only because of the Bordeaux-Wine and the delicious food... This is going to be OT now...

regards,
stefan