Re: Attack on the James Server

Günter Paul <[email protected]>
Newsgroups gmane.comp.jakarta.james.user
Message-ID <[email protected]>
Hi Benoit,

Yes, I am glad to write a small documentation. But I need a few days for this.

I currently solved it by writing my own appender for log4j2. This makes the evaluation easier for me, since I can do without complicated regex expressions. But this does not work for other loggers.

The best way I think would be if James could handle this internally. Until then, fail2ban is a good alternative.

Best wishes

Günter

> Benoit TELLIER <[email protected]> hat am 15.06.2023 05:06 CEST geschrieben:
> 
>  
> Hello Paul,
> 
> Fail2ban set up with Apache James seems rather generic, and might be 
> worth sharing through either a blog post of through a dedicated 
> documentation page.
> 
> Do you think you would be able to share your experience with others?
> 
> I would be happy to add a blog post entry on James website for this, if 
> relevant.
> 
> Regards,
> 
> Benoit
> 
> On 15/06/2023 00:13, Günter Paul wrote:
> > Hi,
> >
> > at the end I'm using fail2ban. Thanks a lot for information.
> >
> > I see log4j2 works too with the parameters, so I found a solution for me.
> >
> > Best wishes
> >
> > Günter
> >
> >> Günter Paul <[email protected]> hat am 08.06.2023 22:23 CEST geschrieben:
> >>
> >>   
> >> Hi,
> >>
> >> Thanks, logback sounds good. I'm using the spring-version. I will try to change, hope it' possible without problems.
> >>
> >> Günter
> >>
> >>
> >> Am 8. Juni 2023 18:21:55 MESZ schrieb David Matthews <[email protected]>:
> >>>> To chip-in. It should be possible to configure logback to: output only log entries for failing
> >>>> connections (e.g. for org.apache.james.protocols.smtp.core.esmtp.AuthCmdHandler.doAuthTest) and with
> >>>> simplified entry (e.g. only the error message) that should make writing regexp simpler.
> >>>>
> >>> yes, that would help
> >>>
> >>> With my exim4 setup, fail2ban is only looking at the rejectlog. You can't just ban everything though as you'd lock yourself out next time you fat fingered the password.
> >>>
> >>> --
> >>> David Matthews
> >>> [email protected]
> >>>
> >>>
> >>> ---------------------------------------------------------------------
> >>> To unsubscribe, e-mail: [email protected]
> >>> For additional commands, e-mail: [email protected]
> >>>
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> >
> >
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.