• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Block SMTP - SpamBot

Scheduled Pinned Locked Moved Firewalling
6 Posts 5 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    prae1809
    last edited by Apr 9, 2014, 6:11 PM

    One of my clients has been listed on Spamhouse

    This IP is infected (or NATting for a computer that is infected) with the cutwail spambot. In other words, it's participating in a botnet.

    I've passed through all computers (15) and can't find who's spamming through port 25. (I used netstat).

    I decided to create a firewall rule and see the logs to see the faulting machine.

    I don't see any traffic going on port 25 in the logs. I suspect my rules to be wrong. Each 4 hours the error is refreshed on http://cbl.abuseat.org/ meaning that I'm still infected.

    It was last detected at 2014-04-09 16:00 GMT (+/- 30 minutes), approximately 1 hours, 30 minutes ago.

    Here's my config :
    http://i.imgur.com/NSHP97b.jpg

    Any help would be appreciated. Thanks,

    Ben

    1 Reply Last reply Reply Quote 0
    • P
      phil.davis
      last edited by Apr 9, 2014, 6:15 PM

      Rules are processed from the top down, first match applies. So the default allow LAN to any rule is letting everything through. Move that rule to the end, so that your special rules for port 25 have effect first.

      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

      1 Reply Last reply Reply Quote 0
      • P
        prae1809
        last edited by Apr 9, 2014, 6:53 PM

        Resolved ! I can see who's my spammer ! ;D

        Thanks for you quick reply.

        1 Reply Last reply Reply Quote 0
        • Q
          quyda
          last edited by Apr 23, 2014, 4:37 PM

          HI I'm wondering if you found your spammer.
          We have the same problem, our hosting provider keeps blocking us (from sending incorrect credential more than 15 times/30min)
          And I cant find who's sending.
          Would be interested in your finding.

          Cheers
          Q

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by Apr 23, 2014, 7:18 PM

            I had the same worries. In our network the clients (software developers) all have local admin permissions so they may install anything they want.

            To prevent spam I had added the rule on LAN interface seen in attachment and had made good experiences with it.
            This blocks any SMTP connections from LAN except that from our internal mail server and to any host except an permitted external SMTP server.

            Put such rule on the top of LAN net rule set and enable logging. So you will get the IPs of clients who sent mails to forbidden hosts.

            SMTP_Block_Rule.png
            SMTP_Block_Rule.png_thumb

            1 Reply Last reply Reply Quote 0
            • B
              BBcan177 Moderator
              last edited by Apr 23, 2014, 9:55 PM

              The best option is to have a dedicated WAN IP for the mail server.

              Next best option is to create the Rules to block smtp and smtps outbound from any other IPs except for the mail server.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received