[plug] Recent increase in SSL probes

Alexander alex at spottedmouse.com
Tue Dec 16 06:24:41 UTC 2014


My guess would be due to the recent problems with SSLv3 and TLS 1.0 that
there are lots of servers out there which haven't been upgraded to TLS 1.2.

I can highly recommend have a look at ssllabs.com and testing your
server. Unfortunately they don't scan anything other than https.

https://www.ssllabs.com/ssltest/analyze.html?d=plug.org.au&latest

Once scanned you can correct the settings and and then apply similar
configuration changes to your imap service.

On 16/12/14 11:07, Brad Campbell wrote:
> G'day all,
>
> In the last couple of days we've seen an exponential increase in
> probes on ssh and new hits on imap. Notable because we've never seen
> the hits on the imap server before :
>
> dovecot: imap-login: Disconnected (no auth attempts in 0 secs):
> user=<>, rip=99.56.220.255, lip=192.168.2.1, TLS handshaking:
> SSL_accept() failed: error:140760FC:SSL
> routines:SSL23_GET_CLIENT_HELLO:unknown protocol,
> session=<K/n1XR0KQwBjONz/>
>
> Anyone else know what is going on ?
>
> _______________________________________________
> PLUG discussion list: plug at plug.org.au
> http://lists.plug.org.au/mailman/listinfo/plug
> Committee e-mail: committee at plug.org.au
> PLUG Membership: http://www.plug.org.au/membership



More information about the plug mailing list