The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Fail2ban Questions

Discussion in 'Security' started by bltst2, Feb 20, 2014.

  1. bltst2

    bltst2 Member

    Joined:
    Jun 10, 2008
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    1
    I don't mean to hijack this thread, but has anyone used Fail2Ban to reactivate ban IPs that are doing this type of brute force attempts?

    I've setup what I think is a good REGEX

    failregex = \[<HOST>\] .*(?:rejected by local_scan|Unrouteable address)
    login authenticator failed for .* \[<HOST>\]: 535 Incorrect authentication data \(set_id=.*\)\s*$

    logpath = /var/log/exim_rejectlog
    /var/log/exim_mainlog


    But, it's not working...Any thoughts? Anyone every use Fail2Ban to ban these type of attempts?
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,482
    Likes Received:
    203
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Post moved to it's own thread.
     
  3. vanessa

    vanessa Well-Known Member
    PartnerNOC

    Joined:
    Sep 26, 2006
    Messages:
    817
    Likes Received:
    22
    Trophy Points:
    18
    Location:
    Virginia Beach, VA
    cPanel Access Level:
    DataCenter Provider
    I've had clients use it and it seems to do the job
     
Loading...

Share This Page