Mein System: Debian Squeeze
Ich habe von logcheck eine E-Mail bekommen, dass meine Mail Log verdächtige Einträge enthält.
Gut, habe ich nachgesehen, dachte mir aber, naja fail2ban wird schon eingegriffen haben wenn wirklich was war, aber genau das hat es nicht gemacht...
Hier mal ein Auszug aus der mail.log
Code: Alles auswählen
May 19 20:57:30 debian pop3d: LOGIN FAILED, user=ivory, ip=[::ffff:87.101.***.***]
May 19 20:57:31 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:31 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:31 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:31 debian pop3d: LOGIN FAILED, user=jack, ip=[::ffff:87.101.***.***]
May 19 20:57:35 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:35 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:36 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:36 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:37 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:37 debian pop3d: LOGIN FAILED, user=jack, ip=[::ffff:87.101.***.***]
May 19 20:57:39 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:39 debian pop3d: LOGIN FAILED, user=ivory, ip=[::ffff:87.101.***.***]
May 19 20:57:42 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:42 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:43 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:43 debian pop3d: LOGIN FAILED, user=jack, ip=[::ffff:87.101.***.***]
May 19 20:57:44 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:44 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:44 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:45 debian pop3d: LOGIN FAILED, user=ivory, ip=[::ffff:87.101.***.***]
May 19 20:57:48 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:48 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:49 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:49 debian pop3d: LOGIN FAILED, user=jack, ip=[::ffff:87.101.***.***]
May 19 20:57:50 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:50 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
May 19 20:57:50 debian pop3d: Connection, ip=[::ffff:87.101.***.***]
May 19 20:57:51 debian pop3d: LOGIN FAILED, user=ivory, ip=[::ffff:87.101.***.***]
May 19 20:57:54 debian pop3d: LOGOUT, ip=[::ffff:87.101.***.***]
May 19 20:57:54 debian pop3d: Disconnected, ip=[::ffff:87.101.***.***]
Das hätte ja eigentlich reichen sollen, das fail2ban eingreift, hat es aber nicht.
Das fail2ban.log ist leer.
Warum?
Hier mal meine jail.local
![NoPaste-Eintrag](./ext/phpbbde/pastebin/styles/debianforumde/theme/images/icon_pastebin.gif)
Es steht ja alles auf true, könnt ihr mir bitte helfen?
Denn das wird nicht das letzte mal gewesen sein.