ChrisMonder
Basic Pleskian
Hello,
I'm getting a lot of SMTP AUTH intents, I have installed CSF, Juggernauth security plug and well all the intents become banned, but the "hacker" is trying every minute using a lot of different IP's
I know, it's quite common, but I want to block them, I have a very good RBL, I have checked a lot of times, and most all the IP's the "hacker" uses are listed, so I want to do this:
1.- Any connection to SMTP AUTH is first checked vs RBL, if the IP is listed, then DROP and/or BLOCK.
2.- If the IP is not listed then the user can try to use SMTP AUTH
I understand what this could carry some false/positives, I don't care, I really have checked a lot of times/days the RBL vs our real users IP's and they are not listed, vs the "bad" ones, yes, mostly are listed in that RBL.
Thanks in advance
I'm getting a lot of SMTP AUTH intents, I have installed CSF, Juggernauth security plug and well all the intents become banned, but the "hacker" is trying every minute using a lot of different IP's
I know, it's quite common, but I want to block them, I have a very good RBL, I have checked a lot of times, and most all the IP's the "hacker" uses are listed, so I want to do this:
1.- Any connection to SMTP AUTH is first checked vs RBL, if the IP is listed, then DROP and/or BLOCK.
2.- If the IP is not listed then the user can try to use SMTP AUTH
I understand what this could carry some false/positives, I don't care, I really have checked a lot of times/days the RBL vs our real users IP's and they are not listed, vs the "bad" ones, yes, mostly are listed in that RBL.
Thanks in advance