Skip to content

PMG Harden

killmasta93 edited this page May 30, 2022 · 3 revisions

Hardening PMG

Install the packages

apt-get install gcc pyzor make unzip

cd /tmp

wget http://www.dcc-servers.net/dcc/source/dcc.tar.Z


tar xzvf dcc.tar.Z

then run this one by one

cd dcc-*
./configure
make
make install

then create the service

nano /lib/systemd/system/dcc.service

[Unit]
Description=DCC (Distributed Checksum Clearinghouses) interface daemon
After=remote-fs.target systemd-journald-dev-log.socket

[Service]
Type=forking
PermissionsStartOnly=true
RuntimeDirectory=dcc
ExecStart=/var/dcc/libexec/dccifd
User=root
Group=root
Nice=1

#DCC writes pid file with "-" at the beginning which confuses systemd
#PIDFile=/run/dcc/dccifd.pid

[Install]
WantedBy=multi-user.target

then start the service

systemctl enable dcc

systemctl start dcc

Then were going to install geolocation and re2c

apt-get install re2c

cd /etc/cron.hourly && wget sa.schaal-it.net/sa-update && chown root.root sa-update && chmod 755 sa-update

nano /etc/cron.hourly/sa-update

then inside delete everything and add this

#!/bin/sh

# schaal @it
#
# Simple script to update SpamAssassin

SYSLOG_TAG=sa-update

compile=0

logger -d -t $SYSLOG_TAG "Start SA-Update"

sa-update --nogpg
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi


sa-update --nogpg --channel updates.spamassassin.org
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi

sa-update --nogpg --channel sa.zmi.at
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi

sa-update --nogpg --channel sa.schaal-it.net
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi

sa-update --nogpg --channel spamassassin.heinlein-support.de
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi

if [ $compile -eq 1 ]; then
    logger -d -t $SYSLOG_TAG "SA-Update found"
    sa-compile --quiet 2>/dev/null
    systemctl restart pmg-smtp-filter
else
    logger -d -t $SYSLOG_TAG "No SA-Update found"
fi


GEOIP

then were going to install geoip download the zip file attached

 gunzip GeoIP.dat.gz 
  mkdir /usr/share/GeoIP
  mv GeoIP.dat /usr/share/GeoIP/

then copy the template

cp /var/lib/pmg/templates/init.pre.in /etc/pmg/templates/

then edit the file and inside at this at the bottom

nano /etc/pmg/templates/init.pre.in

loadplugin Mail::SpamAssassin::Plugin::Pyzor
use_pyzor 1

loadplugin Mail::SpamAssassin::Plugin::DCC
dcc_path /usr/local/bin/dccproc
dcc_home /var/dcc
dcc_dccifd_path /var/dcc/dccifd
dcc_body_max 999999
dcc_fuz1_max 999999
dcc_fuz2_max 999999
use_dcc 1
dcc_timeout 10

loadplugin Mail::SpamAssassin::Plugin::RelayCountry

then edit the spamassin customconf

ifplugin Mail::SpamAssassin::Plugin::RelayCountry
add_header all Relay-Country _RELAYCOUNTRY_
header RELAYCOUNTRY_BAD X-Relay-Countries =~ /(CN|RU|UA|RO|VN)/
describe RELAYCOUNTRY_BAD Relayed through spammy country at some point
score RELAYCOUNTRY_BAD 2.0
header RELAYCOUNTRY_GOOD X-Relay-Countries =~ /^(CO|AT|CH)/
describe RELAYCOUNTRY_GOOD First untrusted GW is CO, AT or CH
score RELAYCOUNTRY_GOOD -0.5
endif # Mail::SpamAssassin::Plugin::RelayCountry

header RCVD_IN_BRBL eval:check_rbl('brbl-lastexternal', 'b.barracudacentral.org.', '127.0.0.2')
describe RCVD_IN_BRBL Received via a relay in Barracuda RBL
tflags RCVD_IN_BRBL net
score RCVD_IN_BRBL 1.4

header RCVD_IN_NIX_SPAM eval:check_rbl('nix-spam-lastexternal', 'ix.dnsbl.manitu.net.')
describe RCVD_IN_NIX_SPAM Listed in NiX Spam DNSBL (heise.de)
tflags RCVD_IN_NIX_SPAM net
score RCVD_IN_NIX_SPAM 1.4

header RCVD_IN_WPBL eval:check_rbl('wpbl-lastexternal', 'db.wpbl.info.', '127.0.0.2')
describe RCVD_IN_WPBL Listed in WPBL
tflags RCVD_IN_WPBL net
score RCVD_IN_WPBL 1.4

then after that run this

pmgconfig sync --restart 1

then this

spamassassin -D --lint

then this

echo "test" | spamassassin -D pyzor 2>&1 | less

you will get a long list of spamassassin just hit enter and quit it

then this

systemctl restart pmg-smtp-filter

and reboot and EMAIL YOURSELF BEFORE you proceed

next add the following inside the main

nano /etc/pmg/templates/main.cf.in

underneath of this line [%- IF pmg.mail.verifyreceivers %] reject_unverified_recipient[% END %] add this

smtpd_data_restrictions = reject_unauth_pipelining

then underneath this line

smtpd_tls_received_header = yes
[% END %]
[% END %]

add this

header_checks = regexp:/etc/postfix/header_checks

then create the file for the header checks

nano /etc/postfix/header_checks

/^From:/ INFO
/^To:/ INFO
/^Subject:/ INFO

ClamAV unofficial

Next were going to install the unofficial ClamAV run each command per line

cd /tmp
wget https://github.com/extremeshok/clamav-unofficial-sigs/archive/master.zip
unzip master.zip
cp clamav-unofficial-sigs-master/clamav-unofficial-sigs.sh /usr/local/sbin/
chmod 755 /usr/local/sbin/clamav-unofficial-sigs.sh
mkdir /etc/clamav-unofficial-sigs
cp -r clamav-unofficial-sigs-master/config/* /etc/clamav-unofficial-sigs/
mkdir /var/log/clamav-unofficial-sigs
cd /etc/clamav-unofficial-sigs
cat /etc/*release*
cd /etc/clamav-unofficial-sigs/os
cp os.debian.conf /etc/clamav-unofficial-sigs/
cd /etc/clamav-unofficial-sigs/
mv os.debian.conf os.conf

Then nano the user conf add the receipt number to do so wait till you get an email malware patrol then go to free

then inside of the of cd /etc/clamav-unofficial-sigs

edit nano user.conf

uncomment these lines and add your receipt number

malwarepatrol_receipt_code="YOUR-RECEIPT-NUMBER"
malwarepatrol_product_code="8"
malwarepatrol_list="clamav_basic" # clamav_basic or clamav_ext
malwarepatrol_free="yes"

then run these commands per line

/usr/local/sbin/clamav-unofficial-sigs.sh --install-cron
/usr/local/sbin/clamav-unofficial-sigs.sh --install-logrotate
/usr/local/sbin/clamav-unofficial-sigs.sh --install-man
/usr/local/sbin/clamav-unofficial-sigs.sh

After it install run this

cp /tmp/clamav-unofficial-sigs-master/systemd/* /etc/systemd/
clamscan --debug 2>&1 /dev/null | grep "loaded"

EBL list

Next were going to add email blocklist of EBL

nano /etc/mail/spamassassin/v342.pre

and uncomment

loadplugin Mail::SpamAssassin::Plugin::HashBL

then edit this file

nano /etc/mail/spamassassin/custom.cf

and add this at the bottom of that file

ifplugin Mail::SpamAssassin::Plugin::HashBL
header HASHBL_EMAIL eval:check_hashbl_emails('ebl.msbl.org')
describe HASHBL_EMAIL Message contains email address found on EBL
score HASHBL_EMAIL 1.0
endif

and then reboot

after that were going to disable VRFY

nano /etc/pmg/templates/main.cf.in

inside add this

disable_vrfy_command = yes

Fail2ban

Next is Fail2ban install guide

apt-get install fail2ban
cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

then create rule

nano /etc/fail2ban/filter.d/postfix-auth.conf

and add this

# Fail2ban postfix-auth filter
[INCLUDES]
before = common.conf

[Definition]
_daemon = postfix/smtpd
failregex = ^%(__prefix_line)slost connection after .*\[<HOST>\]$
ignoreregex =

then edit this file

nano /etc/fail2ban/jail.local

inside the file at the bottom part

[postfix-auth]
enabled  = true
port     = smtp,ssmtp,28,27
filter   = postfix-auth
action   = iptables[name=SMTP-auth, port=smtp, protocol=tcp]
logpath  = /var/log/mail.info
maxretry = 2
bantime = 36000
findtime = 300

then were going to add another filter

cd /etc/fail2ban/filter.d/

wget https://raw.githubusercontent.com/iredmail/iRedMail/master/samples/fail2ban/filter.d/postfix-pregreet.iredmail.conf

then edit the jail config

nano /etc/fail2ban/jail.local

at the bottom add this

[postfix-pregreet-iredmail]
enabled     = true
filter      = postfix-pregreet.iredmail
logpath     = /var/log/syslog
maxretry    = 1
action      = iptables-multiport[name=postfix, port="25", protocol=tcp]

then we add another part to fail2ban config

nano /etc/fail2ban/filter.d/postfix-hangup.conf

inside add this

[Definition]

failregex = postscreen\[\d+\]: HANGUP .* from \[<HOST>\]:\d+

ignoreregex =

then edit the jail config

nano /etc/fail2ban/jail.local

and add this at the bottom

[postfix-hangup]
enabled = true
port = smtp
filter = postfix-hangup
action = iptables[name=postfix-hangup, port=smtp, protocol=tcp]
logpath = /var/log/mail.log
bantime = 172800
findtime = 86400
maxretry = 2

restart fail2ban

Clone this wiki locally