Fail2ban dovecot: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
(Die Seite wurde neu angelegt: „=Hydra installieren= *apt install hydra =brute Force auf den Rechner= *hydra -S -v -l xinux -P bad-passwords -s 993 -f 10.88.201.21 imap =sshd in fail2ban akti…“)
 
Zeile 10: Zeile 10:
 
*fail2ban-client status dovecot
 
*fail2ban-client status dovecot
 
<pre>
 
<pre>
Status for the jail: sshd
+
Status for the jail: dovecot
 
|- Filter
 
|- Filter
|  |- Currently failed: 1
+
|  |- Currently failed: 0
|  |- Total failed: 14
+
|  |- Total failed: 45
|  `- File list: /var/log/auth.log
+
|  `- File list: /var/log/mail.log
 
`- Actions
 
`- Actions
   |- Currently banned: 1
+
   |- Currently banned: 0
 
   |- Total banned: 1
 
   |- Total banned: 1
   `- Banned IP list: 172.31.31.1
+
   `- Banned IP list:
 
</pre>
 
</pre>
 +
 
=Alles unbannen=  
 
=Alles unbannen=  
 
*fail2ban-client  unban --all
 
*fail2ban-client  unban --all

Version vom 13. Dezember 2022, 16:14 Uhr

Hydra installieren

  • apt install hydra

brute Force auf den Rechner

  • hydra -S -v -l xinux -P bad-passwords -s 993 -f 10.88.201.21 imap

sshd in fail2ban aktivieren

  • sed -ie "/^\[dovecot\]/aenabled = true" jail.local

fail2ban neustarten

  • systemctl restart fail2ban

Status checken

  • fail2ban-client status dovecot
Status for the jail: dovecot
|- Filter
|  |- Currently failed:	0
|  |- Total failed:	45
|  `- File list:	/var/log/mail.log
`- Actions
   |- Currently banned:	0
   |- Total banned:	1
   `- Banned IP list:

Alles unbannen

  • fail2ban-client unban --all