Re: [Dovecot] Auto-blocking faulty login attempts

2013-09-01 Thread Patrick Ben Koetter
* Jos Chrispijn dove...@webrz.net: Dear group, How can I block login attempts to dovecot after trying 5 times in error? If you can read German take a look at this: http://sys4.de/de/blog/2012/12/28/botnets-mit-rsyslog-und-iptables-recent-modul-abwehren/ p@rick -- [*] sys4 AG

Re: [Dovecot] Auto-blocking faulty login attempts

2013-09-01 Thread Adrian Minta
On 08/31/13 23:13, Jos Chrispijn wrote: Dear group, How can I block login attempts to dovecot after trying 5 times in error? You need to use fail2ban: http://wiki2.dovecot.org/HowTo/Fail2Ban -- Best regards, Adrian Minta

Re: [Dovecot] Logging passwords on auth failure/dealing with botnets

2013-09-01 Thread Charles Marcus
On 2013-08-30 7:55 PM, Joseph Tam jtam.h...@gmail.com wrote: Michael Smith writes: We're already running fail2ban, but it doesn't seem that effective against botnets, when they only do one attempt per IP. Yeah, distributed BFDs are tough to block unless you can characterize the clients well.

Re: [Dovecot] Logging passwords on auth failure/dealing with botnets

2013-09-01 Thread LuKreme
On 01 Sep 2013, at 09:00 , Charles Marcus cmar...@media-brokers.com wrote: On 2013-08-30 7:55 PM, Joseph Tam jtam.h...@gmail.com wrote: Michael Smith writes: We're already running fail2ban, but it doesn't seem that effective against botnets, when they only do one attempt per IP. Yeah,

Re: [Dovecot] Logging passwords on auth failure/dealing with botnets

2013-09-01 Thread Noel
On 9/1/2013 10:00 AM, Charles Marcus wrote: On 2013-08-30 7:55 PM, Joseph Tam jtam.h...@gmail.com wrote: Michael Smith writes: We're already running fail2ban, but it doesn't seem that effective against botnets, when they only do one attempt per IP. Yeah, distributed BFDs are tough to block

Re: [Dovecot] Getting back into Dovecot 2.2.5

2013-09-01 Thread Andreas Kasenides
On 31-08-2013 13:07, Kai Hendry wrote: However I found /usr/share/doc/dovecot/example-config/conf.d/ a little scary, since I like to have my configs as minimalistic as possible, e.g. I suggest you forget all the options and concentrate on the ones you intend to use. Dovecot has defaults

Re: [Dovecot] Getting back into Dovecot 2.2.5

2013-09-01 Thread Kai Hendry
On Mon, Sep 02, 2013 at 02:37:04AM +0300, Andreas Kasenides wrote: mail_location=maildir:/var/spool/mail/%u first and see how it works before moving the INBOX separately from other boxes That won't work: imap(hendry): Error: stat(/var/spool/mail/hendry/tmp) failed: Not a directory