Bonjour dans mes log j’ai :
Jun 24 14:48:21 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<1@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:23 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<disk@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:25 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<carmen@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:27 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<radio@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:29 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<ftp@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:31 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<web@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:33 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<testmail@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:35 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:37 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<root@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:39 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<info@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:41 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<www@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:43 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<2@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:45 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<sales@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:47 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<recruit@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:49 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<alias@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:51 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<office@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Jun 24 14:48:53 mx dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<music@ovh.net>, method=PLAIN, rip=209.177.94.11, lip=[MonIP]
Comme ça pour des milliers de lignes …
J’ai fail2ban d’installer, mais ça ne suffit pas …
L’IP 209.177.94.11 renvoie sur un serveur Apache … ça sent le zombi !
Je pense qu’avec IPTABLE je peux bannir cette IP, mais quand pensez-vous ?