Sendmail + fail2ban = OK !
[root@fedora8 log]# cat secure* | grep "Invalid"
May 15 08:17:52 fedora8 sshd[5365]: Invalid user ftpuser from 200.2.252.18
May 15 08:17:57 fedora8 sshd[5370]: Invalid user user from 200.2.252.18
May 15 08:17:59 fedora8 sshd[5372]: Invalid user mailer from 200.2.252.18
[root@fedora8 log]#
je reçois bien un mail de confirmation :
Sujet: [Fail2Ban] SSH: banned 200.2.252.18
Date: Thu, 15 May 2008 08:18:01 +0200
Hi,
The IP 200.2.252.18 has just been banned by Fail2Ban after
5 attempts against SSH.
Here are more information about 200.2.252.18:
[Requête en cours whois.lacnic.net]
[whois.lacnic.net]
% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries
% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2008-05-15 03:19:55 (BRT -03:00)
% Too many clients. Please, try again later.
% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.
Regards,
Fail2Ban
j'avais laissé le port 25 ouvert ! grosse boulette ! corrigée ! :-)
Un Linux, c'est bien ...........plein de Linux, c'est mieux !
Debian lenny // Fedora 2.6.24.5-85.fc8 // Gentoo 2.6.24-gentoo-r7 // Mandriva 2007.1 Spring