• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

IMAP connection internally? Hacked?

mparadis

Regular Pleskian
Mar 9 09:00:25 psa imapd: IMAP connect from @ [::ffff:127.0.0.1]INFO: LOGIN, user=safeg@xxxxx.net, ip=[::ffff:127.0.0.1], protocol=IMAP
Mar 9 09:00:25 psa imapd: 1331305225.438406 DISCONNECTED, user=safeg@xxxxx.net, ip=[::ffff:127.0.0.1], headers=0, body=42357, rcvd=343, sent=46960, maildir=/var/qmail/mailnames/xxxxx.net/safeg/Maildir

I was watching someone doing a dictionary attack until they hit on an email and got in. Moments later, I saw that different servers on my network seemed to be being poked for email services, sending, etc.

I changed the password on the hacked account, made sure the user got cut off, then let him back in. Sure enough, he lost access to the account but... then I noticed something strange which is the above.

When I first noticed the attack, it was coming from an external public IP. When they got into the above account, a while later, I noticed something trying to connect to the same account but from 127.0.0.1.

What gives??? Did the spammer somehow install something on my system from his hacked POP account? Sounds unlikely but why are the connections coming from the local machine now?
 
Last edited:
Back
Top