Roundcube Community Forum

Release Support => Pending Issues => Topic started by: jeffshead on May 11, 2011, 01:19:14 AM

Title: [0.5.2] hmail_autoban plugin help
Post by: jeffshead on May 11, 2011, 01:19:14 AM
I don't understand why 127.0.0.1 is the address that always gets added to the autoban list regardless of the user's public IP address.

This means that if a bot or a malicious user tries to access a legitimate user's account, it will also ban the real account owner if he/she tries to login.

I thought only the public IP address of the user (failed attempts) would be banned but it's always 127.0.0.1 which blocks anyone from accessing the account.

Is there a way to just block the failed attempt user's IP address or an octet range?

What am I not understanding?

To me, it does not make sense to block account access from all IP addresses.
Title: [0.5.2] hmail_autoban plugin help
Post by: rosali on May 11, 2011, 02:55:37 AM
Read that and configure hMailserver IP ranges accordingly:

Auto-ban (http://www.hmailserver.com/documentation/latest/?page=reference_autoban)

hMailserver can't not know the IP address of the user connecting to the webmail,
because there is no direct connection.

The IP for connections from Webmail to hMailserver is always the Server IP.

EDIT: You may want to give 'crawler' and 'dnsbl' plugins in addition to hmail_autoban a shot.
Title: [0.5.2] hmail_autoban plugin help
Post by: jeffshead on May 12, 2011, 03:01:05 AM
OK. Now it makes sense. Thanks:)
Title: good
Post by: eveninggowns on May 12, 2011, 11:10:14 PM
Get ideas and information on various styles and fashions of
Evening Dresses (http://www.vicyc.com/evening-dresses-c-91.html)
Formal Dresses[/url (http://www.vicyc.com/evening-dresses-c-91.html)