unihostbrasil
Verified User
wait wait, it will log user IP even if brute force attacks come from 127.0.0.1, 127.0.0.1 is localhost, so this looks like attack from server it self, from some website or user account, how it will log user ip when user is server, thats why brute force attacks are from 127.0.0.1 ip. or im missing something here or dont understand ?
If the attack comes from RoundCube, the Dovecot log registers your local IP (127.0.0.1) because it's an local script. RoundCube is trying to connect into your Dovecot, not the attacker. Since the version 0.5 RoundCube also log the user IP so you can identify it. You must check the RoundCube log (if the attack comes from it) instead of Dovecot log.