Index: [Article Count Order] [Thread]

Date:  Wed, 18 Apr 2007 12:40:04 -0400
From:  "Paul Aviles" <paul.aviles (at mark) nickelnetworks.com>
Subject:  [coba-e:09613] Back by popular demand -  Dovecot/POP3 Flood
To:  <coba-e (at mark) bluequartz.org>
Message-Id:  <200704181640.l3IGe6Rc004080 (at mark) srv1.nickelnetworks.com>
In-Reply-To:  <200704162216.l3GMGjF3030754 (at mark) srv1.nickelnetworks.com>
X-Mail-Count: 09613

By popular demand the issue is back...... 

Apr 18 08:45:07 srv1 dovecot: pop3-login: Aborted login: rip=127.0.0.1,
lip=127.0.0.1, secured
Apr 18 08:45:13 srv1 dovecot: pop3-login: Aborted login: user=<test>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:13 srv1 dovecot: pop3-login: Aborted login: user=<sales>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:13 srv1 dovecot: pop3-login: Aborted login: user=<root>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:15 srv1 dovecot: pop3-login: Aborted login: user=<contact>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:17 srv1 dovecot: pop3-login: Aborted login: user=<account>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:17 srv1 dovecot: pop3-login: Aborted login: user=<root>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:17 srv1 dovecot: pop3-login: Aborted login: user=<test>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:17 srv1 dovecot: pop3-login: Aborted login: user=<sales>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:17 srv1 dovecot: pop3-login: Aborted login: user=<support>,
method=PLAIN, rip=81.18.67.70, lip=10.5.36.4
Apr 18 08:45:19 srv1 dovecot: pop3-login: Aborted login:
user=<administrator>, method=PLAIN, rip=81.18.67.70, lip=

After a few bunch more of this the server stopped responding.


-----Original Message-----
From: Brian N. Smith [mailto:brian (at mark) nuonce.net]
Sent: Monday, April 16, 2007 6:05 PM
To: coba-e (at mark) bluequartz.org
Subject: [coba-e:09588] Re: Dovecot/POP3 Flood

> After, we only did the changes to dovecot.conf and with 100 
> consecutive connections per sec we did not exhibit the same issue.

Are you saying that the configuration that I had recommended seams to have
cleared up the dovecot-auth bug/issue?

-Brian