On 6/10/2010 5:31 PM, Ralf Hildebrandt wrote:
I use fail2ban which works for dovecot, postfix, ssh, telnet (non-windows), and anything that logs failed logins to a log file.I heard that there are firewalls/security appliances that supposedly can distinguish "somebody using telnet" from "a machine speaking SMTP".I must admit, it sounds feasible (timing between keystrokes etc.), but little useful. Anyway. Is there such a thing? Does anybody use such a thing?