Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-26 Thread Tim Boneko via Fail2ban-users
[higher-level config not quoted] Hello Nick! Thanks a lot! I'll have a look at the link you sent. I'll try the config the way you suggested. We rather have too many than too few mails. Bye, tim -- Hear about... the insurance salesman who says his greatest successes are

Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-25 Thread Nick Howitt via Fail2ban-users
On 25/06/2023 20:35, Tim Boneko via Fail2ban-users wrote: Am Donnerstag, dem 22.06.2023 um 16:27 +0100 schrieb Nick Howitt via Fail2ban-users: Don't allow authentication on 25! I second that. Port 25 is without encryption, so i don't offer auth there - only on 587. Apart from that, stolen pas

Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-25 Thread Tim Boneko via Fail2ban-users
Am Donnerstag, dem 22.06.2023 um 16:27 +0100 schrieb Nick Howitt via Fail2ban-users: > Don't allow authentication on 25! I second that. Port 25 is without encryption, so i don't offer auth there - only on 587. Apart from that, stolen passwords were tried for login via port 587. This is reduced qu

Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-22 Thread André Rodier via Fail2ban-users
On Thu, 2023-06-22 at 16:27 +0100, Nick Howitt via Fail2ban-users wrote: > > > On 2023-06-22 12:58, André Rodier via Fail2ban-users wrote: > > Hello, all. > > > > I just set-up a new server, running postfix, with submission(s) > > activated on standard ports (587, 465) > > > > Shortly after it

[Fail2ban-users] Postfix: running a script on authentication failure

2023-06-22 Thread André Rodier via Fail2ban-users
Hello, all. I just set-up a new server, running postfix, with submission(s) activated on standard ports (587, 465) Shortly after it has been setup, I see brute force attacks (not surprising) from a whole /24 network (more surprising). I carefully checked the logs, and see the modus operandi, w

Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-22 Thread Nick Howitt via Fail2ban-users
On 2023-06-22 12:58, André Rodier via Fail2ban-users wrote: Hello, all. I just set-up a new server, running postfix, with submission(s) activated on standard ports (587, 465) Shortly after it has been setup, I see brute force attacks (not surprising) from a whole /24 network (more surprising)

Re: [Fail2ban-users] Postfix: running a script on authentication failure

2023-06-22 Thread Gary R. Schmidt
On 22/06/2023 23:01, fail2ban-users-requ...@lists.sourceforge.net wrote: > I just set-up a new server, running postfix, with submission(s) activated on standard ports (587, 465) First of all, have you activated postscreen, and configured it to query SPAMCop &c? Postscreen is part of the pos

[Fail2ban-users] Postfix: running a script on authentication failure

2023-06-22 Thread André Rodier via Fail2ban-users
Hello, all. I just set-up a new server, running postfix, with submission(s) activated on standard ports (587, 465) Shortly after it has been setup, I see brute force attacks (not surprising) from a whole /24 network (more surprising). I carefully checked the logs, and see the modus operandi, w