Follow up on postfix-sasl and apache-noscript watch items

Both were left as "revisit if it escalates" notes from earlier audits.
Checked live logs on alpha via SSH (port 10022): postfix-sasl remains
scattered low-volume noise, not a coordinated low-and-slow campaign like
the dovecot spray; the original three /24s behind the apache-noscript
distributed scan are no longer active, current activity is normal
per-IP jail behavior. No fixes needed for either; also reconfirmed the
dyndns per-user auth binding gap is still present and unfixed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-26 09:31:10 +02:00
co-authored by Claude Sonnet 5
parent a715c217d2
commit b926af5fca
2 changed files with 13 additions and 0 deletions
+6
View File
@@ -282,6 +282,12 @@ Audited 2026-07-20 — which public hostnames require credentials:
design — it needs subnet-level (CIDR) banning instead, which risks
blocking legitimate traffic sharing that block (e.g. carrier NAT). Left
as routine scan noise for now; revisit if it escalates.
**Follow-up 2026-07-26**: rechecked — the original three `/24`s are gone
from current logs entirely (that specific campaign appears to have moved
on). `apache-noscript` shows normal jail activity (42 total bans, 3
currently banned) from ordinary repeat-offender IPs already caught by
per-IP thresholds, not a new distributed single-shot pattern. No
escalation; still fine to leave as-is.
- **No real nameserver redundancy**: 2026-07-19, `ns1.jayfield.org` and
`ns2.jayfield.org` were registered as this domain's NS records at the