[fail2ban] Jail greift nicht !



Dennisda

Registered User
Moin,

seit gestern werde ich über sasl von den Francen etwas genervt *g*

Also folgendes in der auth.log:

Mar 2 12:27:15 puppa saslauthd[1088]: pam_mysql - SELECT returned no result.
Mar 2 12:27:15 puppa saslauthd[1088]: DEBUG: auth_pam: pam_authenticate failed: User not known to the underlying authentication module
Mar 2 12:27:15 puppa saslauthd[1088]: do_auth : auth failure: [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
[/QUOTE]

mail.warn:

[QUOTE]Mar 2 12:23:00 puppa postfix/smtpd[15354]: warning: xxxcnn3348.hospedagemdesites.ws[187.45.213.53]: SASL LOGIN authentication failed: authentication failure
Mar 2 12:23:35 puppa last message repeated 12 times
Mar 2 12:24:16 puppa last message repeated 7 times
Mar 2 12:24:21 puppa postfix/smtpd[14608]: warning: xxxcnn3348.hospedagemdesites.ws[187.45.213.53]: SASL LOGIN authentication failed: authentication failure
Mar 2 12:24:55 puppa last message repeated 12 times[/QUOTE]

Sodele hier die jail:

[QUOTE][sasl-iptables]

enabled = true
filter = sasl
backend = polling
maxentry = 5
logpath = /var/log/auth.log
action = iptables[name=sasl, port=smtp, protocol=tcp]
sendmail-whois-lines[name=sasl, [email protected], sender=fail2ban@DEINE-DOMAIN, logpath=%(logpath)s]
[/QUOTE]

und dann mal hier der Filter:

[QUOTE]# Fail2Ban configuration file
#
# Author: Yaroslav Halchenko
#
# $Revision: 510 $
#

[Definition]

# Option: failregex
# Notes.: regex to match the password failures messages in the logfile. The
# host must be matched by a group named "host". The tag "<HOST>" can
# be used for standard IP/hostname matching and is only an alias for
# (?:::f{4,6}:)?(?P<host>\S+)
# Values: TEXT
#
failregex = : warning: [-._\w]+\[<HOST>\]: SASL (?:LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed$

# Option: ignoreregex
# Notes.: regex to ignore. If this regex matches, the line is ignored.
# Values: TEXT
#
ignoreregex =
[/QUOTE]

Egal welche Konfiguration ich bei den jails verwende, er blockt diese Angriffe einfach nicht. Mag sein das ich doof oder Blind bin aber wo soll den der Hund begraben sein ?
 
Huschi das weiß ich :-)

nur ob da mail.* oder gottweißwas.* steht, er tuts einfach nicht -.-

Werde es aber nebenbei weiter machen und tüffteln
 
Schön das Du es weißt.
Ich kann aber nur damit arbeiten, was Du uns zum lesen gibst. :cool:

huschi.
 
Hi,

schon mal in der /etc/fail2ban/fail2ban.conf das Debug-Level auf 4 erhöht und geprüft, ob dort evtl. Fehler ausgegeben werden?

Ich habe bei mir folgenden Eintrag in der /etc/fail2ban/filter.d/sasl.conf
Code:
warning: .*\[<HOST>\]: SASL LOGIN authentication failed: authentication failure
und in der jail.conf natürlich auf die mail.log.

Ein restart von Fail2ban wurde ebenfalls durchgeführt?

Mfg Martin
 
schon mal in der /etc/fail2ban/fail2ban.conf das Debug-Level auf 4 erhöht und geprüft, ob dort evtl. Fehler ausgegeben werden?

Keine Error*s oder Warn Meldungen.

Ich habe bei mir folgenden Eintrag in der /etc/fail2ban/filter.d/sasl.conf

Jip Danke habe es mal übernommen ! Muss aber nu auf einen Angriff warten !
und neu starten, tue ich nach jeder Änderung und da gibt es auch keine ungewöhnliche Meldungen.
 
Back
Top