AnsweredHot!SMTP.Brute.Force IPS - not working?

Author
RasmusM
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/08/31 04:45:42
  • Status: offline
2019/06/21 04:02:23 (permalink)
0

SMTP.Brute.Force IPS - not working?

Dear forum,
 
I have a FortiGate 300E and a Fortimail 200E, love them both very much - great products!
 
However I have an IPS Sensor issue regarding the signature "SMTP.Login.Brute.Force".
 
On the FortiGate we have the IPv4 policy that controls smtp traffic to our spamfilter:
Source: ALL
Destination: SMTP VIP (External IP: X.X.X.X to Mapped IP 10.100.10.9, External Port 25 to Map port 25).
Service: SMTP, SMTPS
Action: Accept
Security Profiles: IPS (with IPS Signature SMTP.Login.Brute.Force, Quarantine 15 Minutes).
 
On the FortiMail I see around 6000-7000 SMTP Auth Failed attempts every day, some are legit email addresses, but most are random names, which probably is someone trying to brute force login.
 
Why does the IPS Sensor not stop this?
 
I have tried custom signatures I found on these forums and put those into the IPS Sensor, with no luck :
 
F-SBID( --attack_id 6228; --name POP3.Brute.Force; --protocol tcp; --service POP3; --flow from_server,reversed; --pattern " -ERR [AUTH] Password supplied" ; --rate 10,180; --track src_ip; )
F-SBID( --attack_id 2712; --name " SMTP.Brute.Force" ; --pattern " AUTH LOGIN" ; --service SMTP; --no_case; --context header; --rate 10,180; --track src_ip;)
F-SBID( --attack_id 7393;  --revision 1; --name \"SMTP_AUTH_FAILURE01\"; --service SMTP; --protocol tcp; --tcp_flags PA; --pattern \"535 Authentication failed. Restarting authentication process\"; --flow from_server,reversed; --track dst_ip; --rate 10,120; )
 
Please help! Any input is much appreciated. Thank you.
 
 
 
 
#1
hubertzw
Gold Member
  • Total Posts : 192
  • Scores: 5
  • Reward points: 0
  • Joined: 2018/04/16 13:29:04
  • Status: offline
Re: SMTP.Brute.Force IPS - not working? 2019/06/21 10:28:03 (permalink) ☼ Best Answerby RasmusM 2019/06/24 00:18:00
#2
RasmusM
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/08/31 04:45:42
  • Status: offline
Re: SMTP.Brute.Force IPS - not working? 2019/06/24 00:19:13 (permalink)
0
Dear Hubertz
 
I tried with the IPS signatures, it did not work - still getting 5000+ attempts daily. Unsure on how to setup the DoS sensor with SMTP traffic?? Is that possible?
 
Is it possible to change the rate so it to blocks/quarantines faster?
post edited by RasmusM - 2019/06/24 00:22:40
#3
Markus
Gold Member
  • Total Posts : 183
  • Scores: 18
  • Reward points: 0
  • Joined: 2015/03/19 07:30:23
  • Location: Switzerland
  • Status: offline
Re: SMTP.Brute.Force IPS - not working? 2019/06/24 04:06:01 (permalink)
0
Hello Rasmus

I'm not using Fortimail, but it's similar, just another pattern. This is my working IDP SMTP Brute Force Signature.
F-SBID( --attack_id 2712; --name " SMTP.Brute.Force" ; --pattern "Authentication unsuccessful" ; --service SMTP; --flow from_server,reversed; --no_case; --context header; --rate 2,60; --track src_ip;)
 
Why do you have two SMTP Signatures? Is this especially because you have Fortimail?

Good luck
post edited by Markus - 2019/06/24 04:10:20
#4
RasmusM
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/08/31 04:45:42
  • Status: offline
Re: SMTP.Brute.Force IPS - not working? 2019/06/24 04:35:57 (permalink)
0
mgrosni
Hello Rasmus

I'm not using Fortimail, but it's similar, just another pattern. This is my working IDP SMTP Brute Force Signature.
F-SBID( --attack_id 2712; --name " SMTP.Brute.Force" ; --pattern "Authentication unsuccessful" ; --service SMTP; --flow from_server,reversed; --no_case; --context header; --rate 2,60; --track src_ip;)
 
Why do you have two SMTP Signatures? Is this especially because you have Fortimail?

Good luck




Thank you, I will try this and see how it works.
 
I used one SMTP signature each try, those I wrote was active one at a time to test if they worked, which they did not.
#5
mattnotley2004
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/02/20 20:40:46
  • Status: offline
Re: SMTP.Brute.Force IPS - not working? 2019/08/11 23:01:38 (permalink)
0
Hi Rasmus

We are having the same issue. Have tried all the various custom IPS signatures listed on these forums, etc, with no luck. Our FortiMail returns the pattern "535 5.7.0 authentication failed" when testing through Telnet, but even with this in the FortiGate IPS signature - nothing goes into quarantine.

Did you manage to get this working?


Cheers,
Matt.
#6
Jump to:
© 2019 APG vNext Commercial Version 5.5