Wpis z mikrobloga

Wiecie może jak powstrzymać ten atak przez fail2ban?

postfix/smtpd[28660]: warning: unknown[xxx.xxx.xxx.xxx]: SASL Login authentication failed: UGFzc3dvcmQ6

Mój config:
[pureftpd]
enabled = true
port = ftp
filter = pureftpd
logpath = /var/log/syslog
bantime = -1
maxretry = 2

[pure-ftpd]
enabled = true
port = ftp,ftp-data,ftps,ftps-data
filter = pure-ftpd
logpath = /var/log/syslog
bantime = -1
maxretry = 2

[postfix-sasl]
enabled = true
port = smtp,ssmtp,imap2,imap3,imaps
filter = postfix-sasl
logpath = /var/log/mail.log
bantime = -1
maxretry = 1

[ssh]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
bantime = -1
maxretry = 2

[postfix]
enabled = true
port = smtp,ssmtp
filter = postfix
logpath = /var/log/mail.log
bantime = -1
maxretry = 1

[dovecot-pop3imap]
enabled = true
filter = dovecot-pop3imap
action = iptables-multiport[name=dovecot-pop3imap, port="pop3,imap", protocol=tcp]
logpath = /var/log/mail.log
bantime = -1
maxretry = 1

#linux #fail2ban #flood #ssh #ban #debian
  • 4