Richard G
Verified User
If found several 127.0.0.1 stuff, but not this one.
Lately if regularly get these messages:
Brute-Force Attack detected in service log from IP(s) 127.0.0.1
So I'm going to look in the brute force monitor and it says this:
There are a couple of domain names there. Not may however.
I have even seen this from suspended domains.
Somewhere I read maybe somebody is bruteforcing webmail, but there is nothing showing up in the apache logs. Or at least I don't see anything which resembles this in the access or error log.
Lately if regularly get these messages:
Brute-Force Attack detected in service log from IP(s) 127.0.0.1
So I'm going to look in the brute force monitor and it says this:
dovecot1 Feb 16 16:28:39 server dovecot: imap-login: Aborted login (auth failed, 1 attempts): user=<[email protected]>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, secured
There are a couple of domain names there. Not may however.
I have even seen this from suspended domains.
Somewhere I read maybe somebody is bruteforcing webmail, but there is nothing showing up in the apache logs. Or at least I don't see anything which resembles this in the access or error log.