To avoid bad things(TM) caused by a cracked e-mail account on our postfix mailserver, I used the script Check Auth Log to detect abnormal high numbers of logins or logins from many different IP addresses within a certain time onto a certain account. Then the script will lock out the account. This, together with per-session limits within postfix configuration (smtpd_client_message_rate_limit, smtpd_client_recipient_rate_limit), should help to avoid or at least mitigate the damage caused by cracked accounts, i.e. SMTP server being blacklisted.
	
	 add comment 
 (  1146 views )
  |  permalink
  |  related link
  |
 add comment 
 (  1146 views )
  |  permalink
  |  related link
  |  



 ( 3 / 1638 )
 ( 3 / 1638 )
 Links
 Links