Re: under another kind of attack

2017-07-25 Thread Michael Starks
On 2017-07-25 09:37, Olaf Hopp wrote: But the rate at which they are knocking is very very low. So fail2ban will never catch them. For example one IP: Jul 25 14:03:17 irams1 dovecot: auth-worker(2212): pam(eurodisc,101.231.247.210,): unknown user Jul 25 15:16:36 irams1 dovecot:

Re: Catch-all with LMTP and Postfix

2016-08-22 Thread Michael Starks
On 08/22/2016 02:00 PM, Aki Tuomi wrote: Seems you accidentically replied to me only. Yup, whoops. Postfix uses the filename you provide as name for the db file, so running it against symlinks does follow the symlink, but it uses the symlink name as what it uses to create the .db file. You

Catch-all with LMTP and Postfix

2016-08-21 Thread Michael Starks
Hidy-ho, I'm having a difficult time getting catch-all working when using Dovecot LMTP. I would like *@example.com (everything) to go to virt...@example.com, where virtual is a valid virtual user. It seems that things are getting as far as LMTP, but then the mail gets bounced. To wit: Aug

[Dovecot] Dovecot Support Added to OSSEC

2009-07-02 Thread Michael Starks
I have added (beta) Dovecot support for the OSSEC HIDs. It will detect certain attacks and error conditions, and optionally block the attacker (similar to fail2ban). Rather than re-hash the details here, I refer you to the OSSEC mailing list for details on how to install. I would appreciate any