Re: OpenSMTPd Denial-of-Service with table-mysql (using default configuration)

2024-05-13 Thread Omar Polo
On 2024/05/13 09:38:40 +0200, Philipp wrote: > Hi > > Sorry, this mail was overseen. Yeah, sorry. > [2022-08-30 13:23] "Tobias Fiebig" > > I just started to see some DoS issue on my OpenSMTPd with table-mysql as > > the backend. Specifically, my server ran into the user lookup process > > ea

Re: OpenSMTPd Denial-of-Service with table-mysql (using default configuration)

2024-05-13 Thread Philipp
Hi Sorry, this mail was overseen. [2022-08-30 13:23] "Tobias Fiebig" > I just started to see some DoS issue on my OpenSMTPd with table-mysql as the > backend. Specifically, my server ran into the user lookup process eating a > full core and torturing the mysql > server after some funny brute-f

OpenSMTPd Denial-of-Service with table-mysql (using default configuration)

2022-08-30 Thread Tobias Fiebig
Heho, I just started to see some DoS issue on my OpenSMTPd with table-mysql as the backend. Specifically, my server ran into the user lookup process eating a full core and torturing the mysql server after some funny brute-force attempts came in. (writeup with graphs here: https://doing-stupid-t

Re: denial of service?

2016-05-10 Thread Edgar Pettijohn
Sent from my iPhone > On May 10, 2016, at 11:10 AM, Gilles Chehade wrote: > >> On Tue, May 10, 2016 at 10:56:10AM -0500, Edgar Pettijohn wrote: >> >> >>> On 05/10/16 10:29, Gilles Chehade wrote: On Tue, May 10, 2016 at 10:11:48AM -0500, Edgar Pettijohn wrote: Sharing with the list

Re: Fwd: Re: denial of service?

2016-05-10 Thread Gilles Chehade
On Tue, May 10, 2016 at 10:56:10AM -0500, Edgar Pettijohn wrote: > > > On 05/10/16 10:29, Gilles Chehade wrote: > >On Tue, May 10, 2016 at 10:11:48AM -0500, Edgar Pettijohn wrote: > >>Sharing with the list at Gilles request. > >> > >>To me it seems like at some point the daemon was treating my ou

Re: Fwd: Re: denial of service?

2016-05-10 Thread Edgar Pettijohn
On 05/10/16 10:29, Gilles Chehade wrote: On Tue, May 10, 2016 at 10:11:48AM -0500, Edgar Pettijohn wrote: Sharing with the list at Gilles request. To me it seems like at some point the daemon was treating my outgoing mail as incoming mail and refusing it because they weren't legal recipients.

Re: Fwd: Re: denial of service?

2016-05-10 Thread Gilles Chehade
On Tue, May 10, 2016 at 10:11:48AM -0500, Edgar Pettijohn wrote: > Sharing with the list at Gilles request. > > To me it seems like at some point the daemon was treating my outgoing mail > as incoming mail and refusing it because they weren't legal recipients. > > Enjoy, > Actually I'm unsure I

Re: denial of service?

2016-05-09 Thread Gilles Chehade
On Tue, May 10, 2016 at 12:52:54AM +0200, Gilles Chehade wrote: > Doubtful that it is related. > 3000 connections is less than 1 / sec during a single hour. > You should share your system, OpenSMTPD version, config and logs > so we help you understand what was the real issue. > 3k connections fr

Re: denial of service?

2016-05-09 Thread Gilles Chehade
Doubtful that it is related. 3000 connections is less than 1 / sec during a single hour. You should share your system, OpenSMTPD version, config and logs so we help you understand what was the real issue. 3k connections from a host, even flooding you, is not going to prevent your mails from reach

denial of service?

2016-05-09 Thread Edgar Pettijohn
I found I was unable to send outgoing messages earlier. Looking through the logs I had over 3000 connections from 112.236.76.92 in less than 24 hours. I blocked them with pf and now I can send outgoing again. Just thought I'd share for those interested in this sort of thing. Thanks, Edgar