youds
Verified User
Hi
I hope you are all well.
I have had fail2ban installed for some time and am getting messages saying failed login attempts in the thousands, now i know that is not possible with fail2ban working correctly. Before fail2ban ran from fail ban command, but when it changed to fail2ban-server and fail2ban-client problems started happening and I think I've been exposed ever since.
Here are the output of some logs:
/var/log/messages
And besides that the configuration is the same as other systems. I'm running CentOS release 6.7 (Final).
Any help would be appreciated; have I missed some article on how to integrate fail2ban with DirectAdmin these days?
Seems stupid it doesn't work out of the box...
Thanks in advance
I hope you are all well.
I have had fail2ban installed for some time and am getting messages saying failed login attempts in the thousands, now i know that is not possible with fail2ban working correctly. Before fail2ban ran from fail ban command, but when it changed to fail2ban-server and fail2ban-client problems started happening and I think I've been exposed ever since.
Here are the output of some logs:
/var/log/messages
Code:
Jun 11 17:00:11 europa freshclam[1094]: Received signal: wake up
Jun 11 17:00:11 europa freshclam[1094]: ClamAV update process started at Sat Jun 11 17:00:11 2016
Jun 11 17:00:11 europa freshclam[1094]: Your ClamAV installation is OUTDATED!
Jun 11 17:00:11 europa freshclam[1094]: Local version: 0.99 Recommended version: 0.99.2
Jun 11 17:00:11 europa freshclam[1094]: DON'T PANIC! Read http://www.clamav.net/support/faq
Jun 11 17:00:11 europa freshclam[1094]: main.cvd is up to date (version: 57, sigs: 4218790, f-level: 60, builder: amishhammer)
Jun 11 17:00:11 europa freshclam[1094]: daily.cld is up to date (version: 21712, sigs: 264117, f-level: 63, builder: neo)
Jun 11 17:00:11 europa freshclam[1094]: bytecode.cld is up to date (version: 278, sigs: 50, f-level: 63, builder: neo)
Jun 11 17:00:11 europa freshclam[1094]: --------------------------------------
Jun 11 17:02:07 europa named[1652]: error (network unreachable) resolving 'ns.isc.afilias-nst.info/A/IN': 2a01:8840:9::1#53
Jun 11 17:02:07 europa named[1652]: error (network unreachable) resolving 'ns.isc.afilias-nst.info/AAAA/IN': 2a01:8840:9::1#53
Jun 11 17:02:07 europa named[1652]: error (network unreachable) resolving 'ns.isc.afilias-nst.info/A/IN': 2a01:8840:8::1#53
Jun 11 17:02:07 europa named[1652]: error (network unreachable) resolving 'ns.isc.afilias-nst.info/AAAA/IN': 2a01:8840:8::1#53
Jun 11 17:02:07 europa named[1652]: error (network unreachable) resolving 'dlv.isc.org/DNSKEY/IN': 2001:500:71::29#53
Jun 11 17:02:08 europa named[1652]: error (network unreachable) resolving 'ns1.isc.ultradns.net/A/IN': 2610:a1:1015::e8#53
Jun 11 17:02:08 europa named[1652]: error (network unreachable) resolving 'ns1.isc.ultradns.net/AAAA/IN': 2610:a1:1015::e8#53
Jun 11 17:02:08 europa named[1652]: error (network unreachable) resolving 'pdns196.ultradns.info/A/IN': 2001:500:1a::1#53
Jun 11 17:02:08 europa named[1652]: error (network unreachable) resolving 'pdns196.ultradns.info/AAAA/IN': 2001:500:1a::1#53
Jun 11 17:02:08 europa named[1652]: error (network unreachable) resolving 'pdns196.ultradns.info/AAAA/IN': 2610:a1:1016::e8#53
Jun 11 17:48:12 europa named[1652]: client 113.17.184.25#20000: query (cache) '3895082674.www.baidu.com/A/IN' denied
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './DNSKEY/IN': 2001:500:2f::f#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving 'dlv.isc.org/DNSKEY/IN': 2001:500:71::30#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './NS/IN': 2001:500:2f::f#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './DNSKEY/IN': 2001:7fd::1#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './NS/IN': 2001:7fd::1#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './DNSKEY/IN': 2001:500:2d::d#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './NS/IN': 2001:500:2d::d#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './DNSKEY/IN': 2001:dc3::35#53
Jun 11 18:02:08 europa named[1652]: error (network unreachable) resolving './NS/IN': 2001:dc3::35#53
Jun 11 18:19:46 europa fail2ban.server[8643]: INFO Stopping all jails
Jun 11 18:19:46 europa fail2ban.action[8643]: ERROR iptables -D INPUT -p tcp -m multiport --dports pop3,pop3s,imap,imaps -j f2b-dovecot-pop3imap#012iptables -F f2b-dovecot-pop3imap#012iptables -X f2b-dovecot-pop3imap -- stdout: ''
Jun 11 18:19:46 europa fail2ban.action[8643]: ERROR iptables -D INPUT -p tcp -m multiport --dports pop3,pop3s,imap,imaps -j f2b-dovecot-pop3imap#012iptables -F f2b-dovecot-pop3imap#012iptables -X f2b-dovecot-pop3imap -- stderr: "iptables v1.4.7: Couldn't load target `f2b-dovecot-pop3imap':/lib64/xtables/libipt_f2b-dovecot-pop3imap.so: cannot open shared object file: No such file or directory\n\nTry `iptables -h' or 'iptables --help' for more information.\niptables: No chain/target/match by that name.\niptables: No chain/target/match by that name.\n"
Jun 11 18:19:46 europa fail2ban.action[8643]: ERROR iptables -D INPUT -p tcp -m multiport --dports pop3,pop3s,imap,imaps -j f2b-dovecot-pop3imap#012iptables -F f2b-dovecot-pop3imap#012iptables -X f2b-dovecot-pop3imap -- returned 1
Jun 11 18:19:46 europa fail2ban.actions[8643]: ERROR Failed to stop jail 'dovecot-pop3imap' action 'iptables-multiport': Error stopping action
Jun 11 18:19:46 europa fail2ban.jail[8643]: INFO Jail 'dovecot-pop3imap' stopped
Jun 11 18:19:46 europa fail2ban.server[8643]: INFO Exiting Fail2ban
Jun 11 18:19:47 europa fail2ban.server[430]: INFO Changed logging target to SYSLOG (/dev/log) for Fail2ban v0.9.3
Jun 11 18:19:47 europa fail2ban.database[430]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
Jun 11 18:19:47 europa fail2ban.jail[430]: INFO Creating new jail 'dovecot-pop3imap'
Jun 11 18:19:47 europa fail2ban.jail[430]: INFO Jail 'dovecot-pop3imap' uses pyinotify
Jun 11 18:19:47 europa fail2ban.filter[430]: INFO Set jail log file encoding to UTF-8
Jun 11 18:19:47 europa fail2ban.jail[430]: INFO Initiated 'pyinotify' backend
Jun 11 18:19:47 europa fail2ban.filter[430]: INFO Added logfile = /var/log/maillog
Jun 11 18:19:47 europa fail2ban.filter[430]: INFO Set maxRetry = 20
Jun 11 18:19:47 europa fail2ban.filter[430]: INFO Set jail log file encoding to UTF-8
Jun 11 18:19:47 europa fail2ban.actions[430]: INFO Set banTime = 1200
Jun 11 18:19:47 europa fail2ban.filter[430]: INFO Set findtime = 1200
Jun 11 18:19:47 europa fail2ban.jail[430]: INFO Jail 'dovecot-pop3imap' started
Jun 11 18:44:56 europa fail2ban.server[430]: INFO Stopping all jails
Jun 11 18:44:57 europa fail2ban.jail[430]: INFO Jail 'dovecot-pop3imap' stopped
Jun 11 18:44:57 europa fail2ban.server[430]: INFO Exiting Fail2ban
Jun 11 18:44:57 europa fail2ban.server[603]: INFO Changed logging target to SYSLOG (/dev/log) for Fail2ban v0.9.3
Jun 11 18:44:57 europa fail2ban.database[603]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
Jun 11 18:44:57 europa fail2ban.jail[603]: INFO Creating new jail 'dovecot-pop3imap'
Jun 11 18:44:57 europa fail2ban.jail[603]: INFO Jail 'dovecot-pop3imap' uses pyinotify
Jun 11 18:44:57 europa fail2ban.filter[603]: INFO Set jail log file encoding to UTF-8
Jun 11 18:44:57 europa fail2ban.jail[603]: INFO Initiated 'pyinotify' backend
Jun 11 18:44:57 europa fail2ban.filter[603]: INFO Added logfile = /var/log/maillog
Jun 11 18:44:57 europa fail2ban.filter[603]: INFO Set maxRetry = 20
Jun 11 18:44:57 europa fail2ban.filter[603]: INFO Set jail log file encoding to UTF-8
Jun 11 18:44:57 europa fail2ban.actions[603]: INFO Set banTime = 1200
Jun 11 18:44:57 europa fail2ban.filter[603]: INFO Set findtime = 1200
Jun 11 18:44:57 europa fail2ban.jail[603]: INFO Jail 'dovecot-pop3imap' started
And besides that the configuration is the same as other systems. I'm running CentOS release 6.7 (Final).
Any help would be appreciated; have I missed some article on how to integrate fail2ban with DirectAdmin these days?
Seems stupid it doesn't work out of the box...
Thanks in advance