lonerunner
Verified User
- Joined
- Nov 16, 2010
- Messages
- 56
I have alot of Brute force attack reports on my message system. Lately, in last 3-4 weeks i have lot more Brute force attacks and many of them are comming from google ip's
Currently i have over 700 messages about brute force attacks from last 4 days. When i take a look over 500 of them are from google IP's 209.85..... when i trace ip's all they come from various google mail servers.
These are just messages about attacks when i open message every of them have reported from 500 to 900 attacks.
Example
When i look in detailed brute force attack i see attacks are failed login attempts through pop3
I don't get any complains about spaming others and as i can see my server is not sending mass mails and spam.
How much these attacks are dangerous and how to get rid of these attacks. should i block whole range of ip's or do some more security checks or what ?
Currently i have over 700 messages about brute force attacks from last 4 days. When i take a look over 500 of them are from google IP's 209.85..... when i trace ip's all they come from various google mail servers.
These are just messages about attacks when i open message every of them have reported from 500 to 900 attacks.
Example
IP 209.85.215.12 has 782 failed login attempts: dovecot1=782
When i look in detailed brute force attack i see attacks are failed login attempts through pop3
hosting dovecot[5451]: pop3-login: Disconnected (auth failed, 1 attempts): user=<tbn>, method=PLAIN, rip=209.85.215.13
I don't get any complains about spaming others and as i can see my server is not sending mass mails and spam.
How much these attacks are dangerous and how to get rid of these attacks. should i block whole range of ip's or do some more security checks or what ?