[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: masking out invalid root logins with logcheck?



martin f krafft wrote:
I don't really care being informed that my servers are being
brute-forced, which is what fail2ban takes care of anyway...
Unfortunately Fail2Ban doesn't block the attackers on this attack, as the Log line doesn't contain the IP of the attacker (the IP is only listed if the login doesn't exist). However, having the attempted attack listed in LogCheck mails doesn't block it...I also ask is there any use however in having it listed?

Ceers
	Stefano Salvi



Reply to: