rbest
New Member
Hallo, wollte mal einen Rat von Fachleuten. Und zwar ging kürzlich mein Server in die Knie und ich habe die Logs nach Auffälligkeiten durchsucht. In maillog habe ich seitenweise Einträge mit immer derselben IP [172.82.179.71] gefunden.
Kann mir jemand sagen, was da genau stattgefunden hat und ob ich was ich dagegen tun kann. Ich danke im Voraus.
Auszug aus dem Anfang und Ende von maillog:
Kann mir jemand sagen, was da genau stattgefunden hat und ob ich was ich dagegen tun kann. Ich danke im Voraus.
Auszug aus dem Anfang und Ende von maillog:
Code:
Jan 26 00:17:27 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:28 h2660562 plesk_saslauthd[24040]: listen=6, status=5, dbpath='/plesk/passwd.db', keypath='/plesk/passwd_db_key', chroot=1, unprivileged=1
Jan 26 00:17:28 h2660562 plesk_saslauthd[24040]: privileges set to (108:114) (effective 108:114)
Jan 26 00:17:28 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=5)
Jan 26 00:17:28 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:28 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:28 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:28 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:29 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=5)
Jan 26 00:17:29 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:29 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:29 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:29 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:30 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=5)
Jan 26 00:17:30 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:30 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:30 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:30 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:31 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=8)
Jan 26 00:17:31 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:31 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:31 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:31 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:32 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=8)
Jan 26 00:17:32 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:32 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:32 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:32 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:33 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=8)
Jan 26 00:17:33 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:33 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:33 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:33 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:34 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=8)
Jan 26 00:17:34 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:34 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:34 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:34 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:35 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=6)
Jan 26 00:17:35 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:35 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:35 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:35 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
Jan 26 00:17:36 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=6)
Jan 26 00:17:36 h2660562 postfix/smtpd[24023]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 00:17:36 h2660562 postfix/smtpd[24023]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 00:17:36 h2660562 postfix/smtpd[24023]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 00:17:36 h2660562 postfix/smtpd[24023]: connect from unknown[172.82.179.71]
so geht das weiter bis hier:
Jan 26 01:06:28 h2660562 postfix/smtpd[24848]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:28 h2660562 postfix/smtpd[24848]: connect from unknown[172.82.179.71]
Jan 26 01:06:28 h2660562 postfix/smtpd[24858]: warning: hostname systemip7.example.com does not resolve to address 91.200.12.153: Name or service not known
Jan 26 01:06:28 h2660562 postfix/smtpd[24858]: connect from unknown[91.200.12.153]
Jan 26 01:06:28 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'clifton' (password len=9)
Jan 26 01:06:28 h2660562 postfix/smtpd[24858]: warning: unknown[91.200.12.153]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:28 h2660562 postfix/smtpd[24858]: lost connection after AUTH from unknown[91.200.12.153]
Jan 26 01:06:28 h2660562 postfix/smtpd[24858]: disconnect from unknown[91.200.12.153] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:28 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=7)
Jan 26 01:06:28 h2660562 postfix/smtpd[24848]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:29 h2660562 postfix/smtpd[24848]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 01:06:29 h2660562 postfix/smtpd[24848]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:29 h2660562 postfix/smtpd[24858]: connect from unknown[172.82.179.71]
Jan 26 01:06:29 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=7)
Jan 26 01:06:29 h2660562 postfix/smtpd[24858]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:30 h2660562 postfix/smtpd[24858]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 01:06:30 h2660562 postfix/smtpd[24858]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:30 h2660562 postfix/smtpd[24848]: connect from unknown[172.82.179.71]
Jan 26 01:06:30 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=6)
Jan 26 01:06:30 h2660562 postfix/smtpd[24848]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:31 h2660562 postfix/smtpd[24848]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 01:06:31 h2660562 postfix/smtpd[24848]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:31 h2660562 postfix/smtpd[24858]: connect from unknown[172.82.179.71]
Jan 26 01:06:32 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=7)
Jan 26 01:06:32 h2660562 postfix/smtpd[24858]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:32 h2660562 postfix/smtpd[24858]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 01:06:32 h2660562 postfix/smtpd[24858]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:32 h2660562 postfix/smtpd[24848]: connect from unknown[172.82.179.71]
Jan 26 01:06:33 h2660562 plesk_saslauthd[24040]: failed mail authenticatication attempt for user 'info@rbest.de' (password len=7)
Jan 26 01:06:33 h2660562 postfix/smtpd[24848]: warning: unknown[172.82.179.71]: SASL LOGIN authentication failed: authentication failure
Jan 26 01:06:33 h2660562 postfix/smtpd[24848]: lost connection after AUTH from unknown[172.82.179.71]
Jan 26 01:06:33 h2660562 postfix/smtpd[24848]: disconnect from unknown[172.82.179.71] ehlo=1 auth=0/1 commands=1/2
Jan 26 01:06:48 h2660562 postfix/smtpd[24858]: warning: hostname walkerj235.com does not resolve to address 91.200.12.13