|
From: <li...@la...> - 2016-05-11 00:13:45
|
<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><style> body { font-family: "Calibri","Slate Pro",sans-serif,"sans-serif"; color:#262626 }</style> </head> <body lang="en-US"><div><span>I'm assuming since postfix is not mentioned on the attack signature page, sshguard is only reading maillog for exim and Sendmail messages. </span></div><div><span><br></span></div><div><span>Regarding Dovecot, how do I test this feature? Do I create an incorrect email account and send messages rapidly? Also what about attacks where hackers use other protocols on the submission port such a telnet. </span></div><div><span><br></span></div><div><span>Basically I only see sshd messages in auth.log being operated on by sshguard. Eyeballing Dovecot.log, I see no hacking attempts, so the lack of messages in auth.log makes sense.</span></div><div><span><br></span></div><div></div></body></html>
|