-
Notifications
You must be signed in to change notification settings - Fork 0
PMG Harden
Install the packages
apt-get install gcc pyzor make unzip
cd /tmp
wget http://www.dcc-servers.net/dcc/source/dcc.tar.Z
tar xzvf dcc.tar.Z
then run this one by one
cd dcc-*
./configure
make
make install
then create the service
nano /lib/systemd/system/dcc.service
[Unit]
Description=DCC (Distributed Checksum Clearinghouses) interface daemon
After=remote-fs.target systemd-journald-dev-log.socket
[Service]
Type=forking
PermissionsStartOnly=true
RuntimeDirectory=dcc
ExecStart=/var/dcc/libexec/dccifd
User=root
Group=root
Nice=1
#DCC writes pid file with "-" at the beginning which confuses systemd
#PIDFile=/run/dcc/dccifd.pid
[Install]
WantedBy=multi-user.target
then start the service
systemctl enable dcc
systemctl start dcc
Then were going to install geolocation and re2c
apt-get install re2c
cd /etc/cron.hourly && wget sa.schaal-it.net/sa-update && chown root.root sa-update && chmod 755 sa-update
nano /etc/cron.hourly/sa-update
then inside delete everything and add this
#!/bin/sh
# schaal @it
#
# Simple script to update SpamAssassin
SYSLOG_TAG=sa-update
compile=0
logger -d -t $SYSLOG_TAG "Start SA-Update"
sa-update --nogpg
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi
sa-update --nogpg --channel updates.spamassassin.org
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi
sa-update --nogpg --channel sa.zmi.at
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi
sa-update --nogpg --channel sa.schaal-it.net
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi
sa-update --nogpg --channel spamassassin.heinlein-support.de
retval="$?"
if [ $retval -eq 0 ]; then compile=1; fi
if [ $compile -eq 1 ]; then
logger -d -t $SYSLOG_TAG "SA-Update found"
sa-compile --quiet 2>/dev/null
systemctl restart pmg-smtp-filter
else
logger -d -t $SYSLOG_TAG "No SA-Update found"
fi
then were going to install geoip download the zip file attached
gunzip GeoIP.dat.gz
mkdir /usr/share/GeoIP
mv GeoIP.dat /usr/share/GeoIP/
then copy the template
cp /var/lib/pmg/templates/init.pre.in /etc/pmg/templates/
then edit the file and inside at this at the bottom
nano /etc/pmg/templates/init.pre.in
loadplugin Mail::SpamAssassin::Plugin::Pyzor
use_pyzor 1
loadplugin Mail::SpamAssassin::Plugin::DCC
dcc_path /usr/local/bin/dccproc
dcc_home /var/dcc
dcc_dccifd_path /var/dcc/dccifd
dcc_body_max 999999
dcc_fuz1_max 999999
dcc_fuz2_max 999999
use_dcc 1
dcc_timeout 10
loadplugin Mail::SpamAssassin::Plugin::RelayCountry
then edit the spamassin customconf
ifplugin Mail::SpamAssassin::Plugin::RelayCountry
add_header all Relay-Country _RELAYCOUNTRY_
header RELAYCOUNTRY_BAD X-Relay-Countries =~ /(CN|RU|UA|RO|VN)/
describe RELAYCOUNTRY_BAD Relayed through spammy country at some point
score RELAYCOUNTRY_BAD 2.0
header RELAYCOUNTRY_GOOD X-Relay-Countries =~ /^(CO|AT|CH)/
describe RELAYCOUNTRY_GOOD First untrusted GW is CO, AT or CH
score RELAYCOUNTRY_GOOD -0.5
endif # Mail::SpamAssassin::Plugin::RelayCountry
header RCVD_IN_BRBL eval:check_rbl('brbl-lastexternal', 'b.barracudacentral.org.', '127.0.0.2')
describe RCVD_IN_BRBL Received via a relay in Barracuda RBL
tflags RCVD_IN_BRBL net
score RCVD_IN_BRBL 1.4
header RCVD_IN_NIX_SPAM eval:check_rbl('nix-spam-lastexternal', 'ix.dnsbl.manitu.net.')
describe RCVD_IN_NIX_SPAM Listed in NiX Spam DNSBL (heise.de)
tflags RCVD_IN_NIX_SPAM net
score RCVD_IN_NIX_SPAM 1.4
header RCVD_IN_WPBL eval:check_rbl('wpbl-lastexternal', 'db.wpbl.info.', '127.0.0.2')
describe RCVD_IN_WPBL Listed in WPBL
tflags RCVD_IN_WPBL net
score RCVD_IN_WPBL 1.4
then after that run this
pmgconfig sync --restart 1
then this
spamassassin -D --lint
then this
echo "test" | spamassassin -D pyzor 2>&1 | less
you will get a long list of spamassassin just hit enter and quit it
then this
systemctl restart pmg-smtp-filter
and reboot and EMAIL YOURSELF BEFORE you proceed
next add the following inside the main
nano /etc/pmg/templates/main.cf.in
underneath of this line [%- IF pmg.mail.verifyreceivers %] reject_unverified_recipient[% END %]
add this
smtpd_data_restrictions = reject_unauth_pipelining
then underneath this line
smtpd_tls_received_header = yes
[% END %]
[% END %]
add this
header_checks = regexp:/etc/postfix/header_checks
then create the file for the header checks
nano /etc/postfix/header_checks
/^From:/ INFO
/^To:/ INFO
/^Subject:/ INFO
Next were going to install the unofficial ClamAV run each command per line
cd /tmp
wget https://github.com/extremeshok/clamav-unofficial-sigs/archive/master.zip
unzip master.zip
cp clamav-unofficial-sigs-master/clamav-unofficial-sigs.sh /usr/local/sbin/
chmod 755 /usr/local/sbin/clamav-unofficial-sigs.sh
mkdir /etc/clamav-unofficial-sigs
cp -r clamav-unofficial-sigs-master/config/* /etc/clamav-unofficial-sigs/
mkdir /var/log/clamav-unofficial-sigs
cd /etc/clamav-unofficial-sigs
cat /etc/*release*
cd /etc/clamav-unofficial-sigs/os
cp os.debian.conf /etc/clamav-unofficial-sigs/
cd /etc/clamav-unofficial-sigs/
mv os.debian.conf os.conf
Then nano the user conf add the receipt number to do so wait till you get an email malware patrol then go to free
then inside of the of cd /etc/clamav-unofficial-sigs
edit nano user.conf
uncomment these lines and add your receipt number
malwarepatrol_receipt_code="YOUR-RECEIPT-NUMBER"
malwarepatrol_product_code="8"
malwarepatrol_list="clamav_basic" # clamav_basic or clamav_ext
malwarepatrol_free="yes"
then run these commands per line
/usr/local/sbin/clamav-unofficial-sigs.sh --install-cron
/usr/local/sbin/clamav-unofficial-sigs.sh --install-logrotate
/usr/local/sbin/clamav-unofficial-sigs.sh --install-man
/usr/local/sbin/clamav-unofficial-sigs.sh
After it install run this
cp /tmp/clamav-unofficial-sigs-master/systemd/* /etc/systemd/
clamscan --debug 2>&1 /dev/null | grep "loaded"
Next were going to add email blocklist of EBL
nano /etc/mail/spamassassin/v342.pre
and uncomment
loadplugin Mail::SpamAssassin::Plugin::HashBL
then edit this file
nano /etc/mail/spamassassin/custom.cf
and add this at the bottom of that file
ifplugin Mail::SpamAssassin::Plugin::HashBL
header HASHBL_EMAIL eval:check_hashbl_emails('ebl.msbl.org')
describe HASHBL_EMAIL Message contains email address found on EBL
score HASHBL_EMAIL 1.0
endif
and then reboot
after that were going to disable VRFY
nano /etc/pmg/templates/main.cf.in
inside add this
disable_vrfy_command = yes
Next is Fail2ban install guide
apt-get install fail2ban
cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
then create rule
nano /etc/fail2ban/filter.d/postfix-auth.conf
and add this
# Fail2ban postfix-auth filter
[INCLUDES]
before = common.conf
[Definition]
_daemon = postfix/smtpd
failregex = ^%(__prefix_line)slost connection after .*\[<HOST>\]$
ignoreregex =
then edit this file
nano /etc/fail2ban/jail.local
inside the file at the bottom part
[postfix-auth]
enabled = true
port = smtp,ssmtp,28,27
filter = postfix-auth
action = iptables[name=SMTP-auth, port=smtp, protocol=tcp]
logpath = /var/log/mail.info
maxretry = 2
bantime = 36000
findtime = 300
then were going to add another filter
cd /etc/fail2ban/filter.d/
wget https://raw.githubusercontent.com/iredmail/iRedMail/master/samples/fail2ban/filter.d/postfix-pregreet.iredmail.conf
then edit the jail config
nano /etc/fail2ban/jail.local
at the bottom add this
[postfix-pregreet-iredmail]
enabled = true
filter = postfix-pregreet.iredmail
logpath = /var/log/syslog
maxretry = 1
action = iptables-multiport[name=postfix, port="25", protocol=tcp]
then we add another part to fail2ban config
nano /etc/fail2ban/filter.d/postfix-hangup.conf
inside add this
[Definition]
failregex = postscreen\[\d+\]: HANGUP .* from \[<HOST>\]:\d+
ignoreregex =
then edit the jail config
nano /etc/fail2ban/jail.local
and add this at the bottom
[postfix-hangup]
enabled = true
port = smtp
filter = postfix-hangup
action = iptables[name=postfix-hangup, port=smtp, protocol=tcp]
logpath = /var/log/mail.log
bantime = 172800
findtime = 86400
maxretry = 2
restart fail2ban