Hi

has someone a script which can filter out dictionary attacks
from /var/log/maillog and notify about the source-IPs?

i know about fail2ban and so on, but i would like to have
a mail with the IP address for two reasons and avoid fail2ban
at all because it does not match in the way we maintain firewalls

* add the IP to a distributed "iptables-block.sh" and distribute
  it to any server with a comment and timestamp
* write a abuse-mail to the ISP

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to