Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to find spambot? Got network abuse report from my ISP

    Scheduled Pinned Locked Moved General pfSense Questions
    85 Posts 10 Posters 11.2k Views 9 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan
      last edited by

      I guess you can remove (or disable or make it log only) this LAN firewall rule that blocks mail server ports.
      Scarp that ASUS board - or make that IPMI brain-dead.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • M Offline
        MrGlasspoole
        last edited by

        @Gertjan as i wrote: that jumper did deactivate IPMI.

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          I would also consider reinstalling pfSense to be sure. Anyone with access to the BMC would have had full access to the system including console access. They could have installed anything really.

          It would be interesting to know what they did there have the controller send email. I suspect they were just relaying it somehow. It was probably entirely automated based on knowing there are a lot of misconfigured BMC devices connected directly to WAN like that. As such I doubt any real person connected to do anything specific but....

          Steve

          1 Reply Last reply Reply Quote 0
          • M Offline
            MrGlasspoole
            last edited by MrGlasspoole

            Yes i guess there are bots scanning for that IPMI thing.

            But i can use my backup (settings) if i make a fresh pfSense install?

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Yes, you should be able to. I would read through it though. Better to be sure.

              Steve

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.