Re: Geofencing

2023-11-16 Thread Paul Kudla (SCOM.CA Internet Services Inc.)
thanks for the insite, being an ISP I like this kind of info even if it is off topic a bit on the dovecot mail lists, security today is up there with opertional stuff. Have A Happy Thursday !!! Thanks - Paul Kudla (Manager SCOM.CA Internet Services Inc.) Scom.ca Internet Services

Geofencing (was: Anyone Watching Actvity from this network? ...)

2023-11-16 Thread Jochen Bern
On 16.11.23 16:56, Paul Kudla wrote: the ip that triggered all this says it is allocated from NL (Neatherlands) but physicaly exists in Hawii ? As someone working for a LIR, let me clarify a couple things: IPs get assigned to organizations. The registered contacts may well be that

RE: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread J. de Meijer via dovecot
> Any traffic that is not your client's, is unwanted. I have never ever had > some scanning company called me, saying 'here you have 100 us$ because we > used your data' or 'here are some tips to configure this better'. > If someone is scanning you, it is always in their advantage not yours, no >

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Brendan Kearney
On 11/16/23 10:56 AM, Paul Kudla wrote: Ok a few things about IP blocks If they are portable they can move from country to country ?? without any real notice. the ip that triggered all this says it is allocated from NL (Neatherlands) but physicaly exists in Hawii ?

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Paul Kudla
Ok a few things about IP blocks If they are portable they can move from country to country ?? without any real notice. the ip that triggered all this says it is allocated from NL (Neatherlands) but physicaly exists in Hawii ? No list will ever be 100% acurate I did find this link that

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Richard Siddall
Brendan Kearney wrote: i have some rather old IpToCountry.csv files from a now defunct site. it mapped IP allocations to country and included the RIR, date assigned, etc.  this data is a few years old as the site was taken down and there is probably a lot of new or updated info.  a GeoDB

RE: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Marc
And what if someone is on vacation? You can also use dnsbl on your submission, that helps a lot. > > Are there publicly available lists of IP ranges by region? > > There's no reason for any IP outside of North America to be contacting > Postfix on Submission (587) or IMAP, since these are

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Brendan Kearney
On 11/16/23 9:05 AM, Nick Lockheart wrote: Are there publicly available lists of IP ranges by region? There's no reason for any IP outside of North America to be contacting Postfix on Submission (587) or IMAP, since these are employee only services. If not for mobile phones, we could really

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Nick Lockheart
Are there publicly available lists of IP ranges by region? There's no reason for any IP outside of North America to be contacting Postfix on Submission (587) or IMAP, since these are employee only services. If not for mobile phones, we could really close it off. On Thu, 2023-11-16 at 08:27

Re: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Paul Kudla
Good day to all . Just adding to the conversation with how I had to deal with this years ago. Basically hacks to any server are an issue today but it is cat & mouse trying to track all of this. That being said using the reported ip address below, I patched postfix to log the ip address

RE: Anyone Watching Actvity from this network? Attempting Dovecot Buffer Overflows?

2023-11-16 Thread Marc
Any traffic that is not your client's, is unwanted. I have never ever had some scanning company called me, saying 'here you have 100 us$ because we used your data' or 'here are some tips to configure this better'. If someone is scanning you, it is always in their advantage not yours, no santa