Re: Attack on the James Server
David Matthews <[email protected]>
| Newsgroups | gmane.comp.jakarta.james.user |
|---|---|
| Message-ID | <[email protected]> |
>To chip-in. It should be possible to configure logback to: output only log entries for failing >connections (e.g. for org.apache.james.protocols.smtp.core.esmtp.AuthCmdHandler.doAuthTest) and with >simplified entry (e.g. only the error message) that should make writing regexp simpler. > yes, that would help With my exim4 setup, fail2ban is only looking at the rejectlog. You can't just ban everything though as you'd lock yourself out next time you fat fingered the password. -- David Matthews [email protected]