<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EDV - Ende der Vernunft &#187; Fail2ban</title>
	<atom:link href="http://www.ende-der-vernunft.org/tag/fail2ban/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ende-der-vernunft.org</link>
	<description>Wir ertrinken in Information, aber hungern nach Wissen [John Naisbitt]</description>
	<lastBuildDate>Sun, 01 Jan 2012 17:51:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<image><title>EDV - Ende der Vernunft</title><url>http://www.ende-der-vernunft.org/files/joern/edv-banner.jpg</url><link>http://www.ende-der-vernunft.org</link></image>		<item>
		<title>Fail2ban and qpopper</title>
		<link>http://www.ende-der-vernunft.org/2008/03/21/fail2ban-and-qpopper/</link>
		<comments>http://www.ende-der-vernunft.org/2008/03/21/fail2ban-and-qpopper/#comments</comments>
		<pubDate>Fri, 21 Mar 2008 10:17:02 +0000</pubDate>
		<dc:creator>Joern</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Fail2ban]]></category>
		<category><![CDATA[qpopper]]></category>

		<guid isPermaLink="false">http://www.ende-der-vernunft.org/2008/03/21/fail2ban-and-qpopper/</guid>
		<description><![CDATA[Most are using fail2ban to block ssh scans, but it can do a lot more for you. Due to it&#8217;s modular nature you can scan in almost every logfile for things you don&#8217;t like and block it. If you look in /etc/fail2ban/filter.d/ you can see a lot of predefined filters for several mail or ftp [...]]]></description>
			<content:encoded><![CDATA[<p>Most are using <a href="http://fail2ban.org/">fail2ban</a> to block ssh scans, but it can do a lot more for you. Due to it&#8217;s modular nature you can scan in almost every logfile for things you don&#8217;t like and block it. </p>
<p>If you look in <em>/etc/fail2ban/filter.d/</em> you can see a lot of predefined filters for several mail or ftp servers. Mostly it tooks only one regular expression to block scans. Here for instance on qpopper pop3-servers:</p>
<p><em>/etc/fail2ban/filter.d/qpopper.conf</em></p>
<p><code># Fail2Ban configuration file<br />
[Definition]<br />
# Option:  failregex<br />
# Notes.:  regex to match the password failures messages in the logfile. The<br />
#          host must be matched by a group named "host". The tag "&lt;host&gt;" can<br />
#          be used for standard IP/hostname matching.<br />
# Values:  TEXT<br />
#<br />
failregex = \(&lt;HOST&gt;\):\ -ERR\ \[AUTH\]<br />
#<br />
# Option:  ignoreregex<br />
# Notes.:  regex to ignore. If this regex matches, the line is ignored.<br />
# Values:  TEXT<br />
#<br />
ignoreregex =<br />
</code></p>
<p><em>/etc/fail2ban/jail.conf</em></p>
<p><code>[qpopper]<br />
enabled = true<br />
port = pop3<br />
filter = qpopper<br />
logpath = /var/log/mail.log<br />
</code></p>
<p>This works for Debian Etch. For OpenSuSE look <a href="http://www.fail2ban.org/wiki/index.php/HOWTO_fail2ban_with_qpopper">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ende-der-vernunft.org/2008/03/21/fail2ban-and-qpopper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Links for 2007-06-07</title>
		<link>http://www.ende-der-vernunft.org/2007/06/07/links-for-2007-06-07/</link>
		<comments>http://www.ende-der-vernunft.org/2007/06/07/links-for-2007-06-07/#comments</comments>
		<pubDate>Thu, 07 Jun 2007 19:59:30 +0000</pubDate>
		<dc:creator>Joern</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Netz]]></category>
		<category><![CDATA[Sicherheit]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[Bandwidth]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[Congestion]]></category>
		<category><![CDATA[e10k]]></category>
		<category><![CDATA[Fail2ban]]></category>
		<category><![CDATA[Log injection]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://www.ende-der-vernunft.org/2007/06/07/links-for-2007-06-07/</guid>
		<description><![CDATA[Attacking Log analysis tools &#8211; Wie man Leute mit SSH-Bruteforce Blockern wie Fail2ban &#038; Co richtig ärgern und was man dagegen tun kann &#8211; via Nion mal eben zwei Computer transportieren&#8230; &#8211; Eine Sun e10k für Zuhause It’s Still the Latency, Stupid…pt.2 &#8211; Was man gegen Latenz-Probleme tun kann]]></description>
			<content:encoded><![CDATA[<ul>
<li><a href="http://www.ossec.net/en/attacking-loganalysis.html">Attacking Log analysis tools</a> &#8211; Wie man Leute mit SSH-Bruteforce Blockern wie <a href="http://www.fail2ban.org/">Fail2ban</a> &#038; Co richtig ärgern und was man dagegen tun kann &#8211; via <a href="http://nion.modprobe.de/blog/archives/564-DoS-for-log-analysers.html">Nion</a></li>
<li><a href="http://www.sun-powered.de/blojsom/blog/default/solaris/mal-eben-zwei-Computer-transportieren">mal eben zwei Computer transportieren&#8230;</a> &#8211; Eine <a href="http://www.e10k.net/">Sun e10k</a> für Zuhause</li>
<li><a href="http://www.edgeblog.net/2007/its-still-the-latency-stupid-pt2/">It’s Still the Latency, Stupid…pt.2</a> &#8211; Was man gegen Latenz-Probleme tun kann</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.ende-der-vernunft.org/2007/06/07/links-for-2007-06-07/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

