Your IP : 10.1.73.149


Current Path : /opt/cpguard/cpglfd/configs/jails.available/
Upload File :
Current File : //opt/cpguard/cpglfd/configs/jails.available/exim.yaml

jails:  
  - name: "exim-attacks"
    enabled: true
    log_paths:
      - "/var/log/exim_mainlog"   # Common on cPanel / CentOS
      - "/var/log/exim/mainlog"   # Common on generic Linux
      - "/var/log/exim/main.log"  # Common on generic Linux

    rules:
      # 1. SASL / AUTH Failures (Brute Force)
      # Matches: "535 Incorrect authentication data"
      # Covers standard login attempts and Dovecot-linked failures
      - regexp: "authenticator failed for .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]: 535 Incorrect authentication data"

      # 2. Relay Denied (Spam Attempts)
      # Matches: External IPs trying to send mail through your server without auth
      - regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\] .* rejected RCPT <.*>: Relay not permitted"

      # 3. Dictionary Attacks (Unknown Users)
      # Matches: Spammers guessing email addresses (e.g., admin@, info@)
      # Note: Higher retry limit (5) to avoid banning legit servers for a simple typo.
      - regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\] .* rejected RCPT <.*>: (Unknown user|Unrouteable address)"
        max_retries: 15

      # 4. Synchronization Errors (DoS / Botnets)
      # Matches: Bots that don't wait for the server greeting (Protocol Violation)
      - regexp: "SMTP protocol violation: synchronization error .* H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]"

      # 5. RBL/Blacklist Blocks (Optional)
      # Matches: IPs that are already on a spam blacklist (e.g., Spamhaus)
      - regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]: .* rejected after DATA: .* listed in"

      # 6. Matches: sender verify fail (when the sender's domain or email is invalid)
      - regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* sender verify fail for"
        max_retries: 5  # Recommended: Set >1 as DNS glitches can sometimes cause false positives
      # 7. Matches:
      # 1. "Unrouteable address" (User doesn't exist or domain creates a loop)
      # 2. "all relevant MX records point to non-existent hosts" (Bad MX)
      - regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* (Unrouteable address|all relevant MX records point to non-existent hosts)"

      # 8. Matches: SMTP connection from (host) [IP] closed by DROP in ACL
      - regexp: "SMTP connection from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* closed by DROP in ACL"
        max_retries: 15

      # 9. Too many errors (Garbage Commands)
      #  "SMTP call from... dropped: too many syntax or protocol errors"
      # Matches clients that send junk commands or nonsensical data.
      - regexp: "SMTP call from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\](?::\\d+)? dropped: too many (?:(?:nonmail|unrecognized) commands|syntax or protocol errors)"
        max_retries: 20

      # 10. Protocol Errors (Command not advertised)
      #  "SMTP protocol error... command used when not advertised"
      # Matches bots trying to AUTH when not allowed, or PIPELINING when not supported.
      - regexp: "SMTP protocol error in \".*\" .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\](?::\\d+)? [A-Z]+ (?:command used when not advertised|authentication mechanism not supported)"
        max_retries: 15

      # 11. Empty Connections (Socket Wasting)
      #  "no MAIL in SMTP connection from"
      # Matches bots that connect, wait, and disconnect without sending anything.
      - regexp: "no MAIL in SMTP connection from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]"

    # Global Defaults for Exim
    max_retries: 10
    find_time: "1m"
    ban_time: "1h"

    actions:
      - name: "cpgblock-exim"
        ban_command: '/usr/bin/cpgcli ip --temp-block {{.IP}} --reason "Blocked by {{.JailName}} due to more than {{.MaxRetry}} abusive access within {{.FindTime}} seconds" --extra " LogFile: {{.LogPath}} | Reason: {{.LogLine}}"'
        unban_command: "/usr/bin/cpgcli ip --temp-block {{.IP}} --remove"