
31st July 2009, 17:32
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 17
Thanks: 1
Thanked 5 Times in 4 Posts
|
|
SquirrelMail/imap/pop3 fail2ban IP address
I'm running ISPConfig3 on Centos 5.3 as per the installation instructions at this site. When configuring fail2ban for trapping SquirrelMail failed logins, I notice the following in /var/log/maillog:
Jul 31 15:23:55 server_name imapd: LOGIN FAILED, user=45354, ip=[::ffff:127.0.0.1]
Jul 31 15:24:04 server_name imapd: LOGIN FAILED, user=34566, ip=[::ffff:127.0.0.1]
Jul 31 15:24:14 server_name imapd: LOGIN FAILED, user=56757, ip=[::ffff:127.0.0.1]
Jul 31 15:24:26 server_name imapd: LOGIN FAILED, user=4566, ip=[::ffff:127.0.0.1]
Each failed login generates an entry but with IP address 127.0.0.1 (localhost) and hence fail2ban cannot really action the iptables ban because there's no public IP address in the maillog file.
Does anyone have any ideas how a real IP address might be captured to enable fail2ban to do it's stuff? fail2ban works well on the system for ssh and ftp but they use a different logfile.
|

1st August 2009, 10:26
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,591 Times in 2,443 Posts
|
|
Quote:
Originally Posted by gscott187
Jul 31 15:23:55 server_name imapd: LOGIN FAILED, user=45354, ip=[::ffff:127.0.0.1]
Jul 31 15:24:04 server_name imapd: LOGIN FAILED, user=34566, ip=[::ffff:127.0.0.1]
Jul 31 15:24:14 server_name imapd: LOGIN FAILED, user=56757, ip=[::ffff:127.0.0.1]
Jul 31 15:24:26 server_name imapd: LOGIN FAILED, user=4566, ip=[::ffff:127.0.0.1]
|
This is ISPConfig's monitoring module, trying to find out if imapd is still running. Nothing to worry about.
|

2nd August 2009, 21:00
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 17
Thanks: 1
Thanked 5 Times in 4 Posts
|
|
Quote:
Originally Posted by falko
This is ISPConfig's monitoring module, trying to find out if imapd is still running. Nothing to worry about. 
|
Thanks for your reply.
I can confirm that imapd is still running. What I really wanted was to be able to ban (using fail2ban) repeated unsuccessful login attempts through SquirrelMail's Web interface. To be able to do this would involve knowing the real IP address. However, /var/log/maillog only contains IP address 127.0.0.1.
|

3rd August 2009, 09:51
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,591 Times in 2,443 Posts
|
|
Quote:
Originally Posted by gscott187
However, /var/log/maillog only contains IP address 127.0.0.1.
|
Yes, because ISPConfig connects from localhost (127.0.0.1).
|

3rd August 2009, 15:16
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 17
Thanks: 1
Thanked 5 Times in 4 Posts
|
|
fail2ban and SquirrelMail step by step instructions
I've now sucessfully set-up fail2ban with SquirrelMail for ISPConfig3 on CentOS v5.3 using the Squirrel Logger plugin to limit the number of login attempts. If there's any interest in how to do this, I'll write it up and post it. Whilst the process is covered in a few Web places, there are some steps that could cause frustration
Let me know if there's any interest?
|
|
The Following User Says Thank You to gscott187 For This Useful Post:
|
falko (4th August 2009)
|

4th August 2009, 13:31
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,591 Times in 2,443 Posts
|
|
A tutorial would be great!
|

5th August 2009, 14:39
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 17
Thanks: 1
Thanked 5 Times in 4 Posts
|
|
SqurrelMail/fail2ban
Quote:
Originally Posted by falko
A tutorial would be great! 
|
There should be a tutorial in your email inbox awaiting your consideration.
|
|
The Following User Says Thank You to gscott187 For This Useful Post:
|
falko (6th August 2009)
|

14th August 2009, 01:49
|
|
Senior Member
|
|
Join Date: Jul 2009
Posts: 120
Thanks: 5
Thanked 1 Time in 1 Post
|
|
Quote:
Originally Posted by gscott187
I've now sucessfully set-up fail2ban with SquirrelMail for ISPConfig3 on CentOS v5.3 using the Squirrel Logger plugin to limit the number of login attempts. If there's any interest in how to do this, I'll write it up and post it. Whilst the process is covered in a few Web places, there are some steps that could cause frustration
Let me know if there's any interest?
|
I am interested in your how-to on fail2ban and centos. Thanks
|

14th August 2009, 10:51
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 17
Thanks: 1
Thanked 5 Times in 4 Posts
|
|
Location of SquirrelMail/Fail2ban tutorial
Here's the location of the published SquirrelMail/Fail2ban tutorial:
http://www.howtoforge.com/configurin....3-ispconfig-3
|
|
The Following User Says Thank You to gscott187 For This Useful Post:
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 08:07.
|
Recent comments
1 day 7 hours ago
1 day 10 hours ago
1 day 12 hours ago
1 day 13 hours ago
1 day 15 hours ago
1 day 16 hours ago
1 day 17 hours ago
2 days 9 hours ago
2 days 10 hours ago
2 days 14 hours ago