"Fossies" - the Fresh Open Source Software Archive  

Source code changes of the file "fail2ban/tests/files/logs/dovecot" between
fail2ban-1.0.1.tar.gz and fail2ban-1.0.2.tar.gz

About: fail2ban scans log files and bans (via firewall rules) IP-addresses that makes too many access failures. It updates firewall rules to reject the IP address.

dovecot  (fail2ban-1.0.1):dovecot  (fail2ban-1.0.2)
skipping to change at line 116 skipping to change at line 116
# failJSON: { "time": "2005-07-26T11:11:21", "match": true , "host": "192.0.2.1" } # failJSON: { "time": "2005-07-26T11:11:21", "match": true , "host": "192.0.2.1" }
Jul 26 11:11:21 hostname dovecot: imap-login: Disconnected: Too many invalid com mands (tried to use disallowed plaintext auth): user=<test>, rip=192.0.2.1, lip= 192.168.1.1, session=<S5dIdTFCDKUWWMbU> Jul 26 11:11:21 hostname dovecot: imap-login: Disconnected: Too many invalid com mands (tried to use disallowed plaintext auth): user=<test>, rip=192.0.2.1, lip= 192.168.1.1, session=<S5dIdTFCDKUWWMbU>
# failJSON: { "time": "2005-07-26T11:12:19", "match": true , "host": "192.0.2.2" } # failJSON: { "time": "2005-07-26T11:12:19", "match": true , "host": "192.0.2.2" }
Jul 26 11:12:19 hostname dovecot: imap-login: Disconnected: Too many invalid com mands (auth failed, 1 attempts in 17 secs): user=<test>, method=PLAIN, rip=192.0 .2.2, lip=192.168.1.1, TLS, session=<g3ZKeDECFqlWWMbU> Jul 26 11:12:19 hostname dovecot: imap-login: Disconnected: Too many invalid com mands (auth failed, 1 attempts in 17 secs): user=<test>, method=PLAIN, rip=192.0 .2.2, lip=192.168.1.1, TLS, session=<g3ZKeDECFqlWWMbU>
# failJSON: { "time": "2004-08-28T06:38:51", "match": true , "host": "192.0.2.3" } # failJSON: { "time": "2004-08-28T06:38:51", "match": true , "host": "192.0.2.3" }
Aug 28 06:38:51 s166-62-100-187 dovecot: imap-login: Disconnected (auth failed, 1 attempts in 9 secs): user=<administrator@example.com>, method=PLAIN, rip=192.0 .2.3, lip=192.168.1.2, TLS: Disconnected, TLSv1.2 with cipher ECDHE-RSA-AES256-G CM-SHA384 (256/256 bits) Aug 28 06:38:51 s166-62-100-187 dovecot: imap-login: Disconnected (auth failed, 1 attempts in 9 secs): user=<administrator@example.com>, method=PLAIN, rip=192.0 .2.3, lip=192.168.1.2, TLS: Disconnected, TLSv1.2 with cipher ECDHE-RSA-AES256-G CM-SHA384 (256/256 bits)
# failJSON: { "time": "2004-08-28T06:38:52", "match": true , "host": "192.0.2.4" , "desc": "open parenthesis in optional part between Disconnected and (auth fail ed ...), gh-3210" } # failJSON: { "time": "2004-08-28T06:38:52", "match": true , "host": "192.0.2.4" , "desc": "open parenthesis in optional part between Disconnected and (auth fail ed ...), gh-3210" }
Aug 28 06:38:52 s166-62-100-187 dovecot: imap-login: Disconnected: Connection cl osed: read(size=1003) failed: Connection reset by peer (auth failed, 1 attempts in 0 secs): user=<test@example.com>, rip=192.0.2.4, lip=127.0.0.19, session=<Lsz 0Oo7WXti3b7xe> Aug 28 06:38:52 s166-62-100-187 dovecot: imap-login: Disconnected: Connection cl osed: read(size=1003) failed: Connection reset by peer (auth failed, 1 attempts in 0 secs): user=<test@example.com>, rip=192.0.2.4, lip=127.0.0.19, session=<Lsz 0Oo7WXti3b7xe>
# failJSON: { "time": "2004-08-29T01:49:33", "match": false , "desc": "avoid slo
w RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: imap-login: Disconnected: Connection closed
: read(size=1026) failed: Connection reset by peer (no auth attempts in 0 secs):
user=<>, rip=192.0.2.5, lip=127.0.0.1, TLS handshaking: read(size=1026) failed:
Connection reset by peer
# failJSON: { "time": "2004-08-29T01:49:33", "match": false , "desc": "avoid slo
w RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: imap-login: Disconnected: Connection closed
: SSL_accept() failed: error:1408F10B:SSL routines:ssl3_get_record:wrong version
number (no auth attempts in 0 secs): user=<>, rip=192.0.2.5, lip=127.0.0.1, TLS
handshaking: SSL_accept() failed: error:1408F10B:SSL routines:ssl3_get_record:w
rong version number
# failJSON: { "time": "2004-08-29T01:49:33", "match": false , "desc": "avoid slo
w RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: managesieve-login: Disconnected: Too many i
nvalid commands. (no auth attempts in 0 secs): user=<>, rip=192.0.2.5, lip=127.0
.0.1
# failJSON: { "time": "2004-08-29T01:49:33", "match": false , "desc": "avoid slo
w RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: managesieve-login: Disconnected: Connection
closed: read(size=1007) failed: Connection reset by peer (no auth attempts in 1
secs): user=<>, rip=192.0.2.5, lip=127.0.0.1
# failJSON: { "time": "2004-08-29T01:49:33", "match": false , "desc": "avoid slo
w RE, gh-3370" }
Aug 29 01:49:33 server dovecot[472]: imap-login: Disconnected: Connection closed
: SSL_accept() failed: error:14209102:SSL routines:tls_early_post_process_client
_hello:unsupported protocol (no auth attempts in 0 secs): user=<>, rip=192.0.2.5
, lip=127.0.0.1, TLS handshaking: SSL_accept() failed: error:14209102:SSL routin
es:tls_early_post_process_client_hello:unsupported protocol
# failJSON: { "time": "2004-08-29T03:17:18", "match": true , "host": "192.0.2.13 3" } # failJSON: { "time": "2004-08-29T03:17:18", "match": true , "host": "192.0.2.13 3" }
Aug 29 03:17:18 server dovecot: submission-login: Client has quit the connection (auth failed, 1 attempts in 2 secs): user=<user1>, method=LOGIN, rip=192.0.2.13 3, lip=0.0.0.0 Aug 29 03:17:18 server dovecot: submission-login: Client has quit the connection (auth failed, 1 attempts in 2 secs): user=<user1>, method=LOGIN, rip=192.0.2.13 3, lip=0.0.0.0
# failJSON: { "time": "2004-08-29T03:53:52", "match": true , "host": "192.0.2.16 9" } # failJSON: { "time": "2004-08-29T03:53:52", "match": true , "host": "192.0.2.16 9" }
Aug 29 03:53:52 server dovecot: submission-login: Remote closed connection (auth failed, 1 attempts in 2 secs): user=<user4>, method=PLAIN, rip=192.0.2.169, lip =0.0.0.0 Aug 29 03:53:52 server dovecot: submission-login: Remote closed connection (auth failed, 1 attempts in 2 secs): user=<user4>, method=PLAIN, rip=192.0.2.169, lip =0.0.0.0
# failJSON: { "time": "2004-08-29T15:33:53", "match": true , "host": "192.0.2.10 0" } # failJSON: { "time": "2004-08-29T15:33:53", "match": true , "host": "192.0.2.10 0" }
Aug 29 15:33:53 server dovecot: managesieve-login: Disconnected: Too many invali d commands. (auth failed, 1 attempts in 2 secs): user=<myself>, method=PLAIN, ri p=192.0.2.100, lip=0.0.0.0, TLS, TLSv1.3 with cipher TLS_CHACHA20_POLY1305_SHA25 6 (256/256 bits) Aug 29 15:33:53 server dovecot: managesieve-login: Disconnected: Too many invali d commands. (auth failed, 1 attempts in 2 secs): user=<myself>, method=PLAIN, ri p=192.0.2.100, lip=0.0.0.0, TLS, TLSv1.3 with cipher TLS_CHACHA20_POLY1305_SHA25 6 (256/256 bits)
# --------------------------------------- # ---------------------------------------
# Test-cases of aggressive mode: # Test-cases of aggressive mode:
# --------------------------------------- # ---------------------------------------
# filterOptions: [{"mode": "aggressive"}] # filterOptions: [{"mode": "aggressive"}]
# failJSON: { "time": "2004-08-29T01:49:33", "match": true , "host": "192.0.2.5"
, "desc": "matches in aggressive mode, avoid slow RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: imap-login: Disconnected: Connection closed
: read(size=1026) failed: Connection reset by peer (no auth attempts in 0 secs):
user=<>, rip=192.0.2.5, lip=127.0.0.1, TLS handshaking: read(size=1026) failed:
Connection reset by peer
# failJSON: { "time": "2004-08-29T01:49:33", "match": true , "host": "192.0.2.5"
, "desc": "matches in aggressive mode, avoid slow RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: imap-login: Disconnected: Connection closed
: SSL_accept() failed: error:1408F10B:SSL routines:ssl3_get_record:wrong version
number (no auth attempts in 0 secs): user=<>, rip=192.0.2.5, lip=127.0.0.1, TLS
handshaking: SSL_accept() failed: error:1408F10B:SSL routines:ssl3_get_record:w
rong version number
# failJSON: { "time": "2004-08-29T01:49:33", "match": true , "host": "192.0.2.5"
, "desc": "matches in aggressive mode, avoid slow RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: managesieve-login: Disconnected: Too many i
nvalid commands. (no auth attempts in 0 secs): user=<>, rip=192.0.2.5, lip=127.0
.0.1
# failJSON: { "time": "2004-08-29T01:49:33", "match": true , "host": "192.0.2.5"
, "desc": "matches in aggressive mode, avoid slow RE, gh-3370" }
Aug 29 01:49:33 server dovecot[459]: managesieve-login: Disconnected: Connection
closed: read(size=1007) failed: Connection reset by peer (no auth attempts in 1
secs): user=<>, rip=192.0.2.5, lip=127.0.0.1
# failJSON: { "time": "2004-08-29T01:49:33", "match": true , "host": "192.0.2.5"
, "desc": "matches in aggressive mode, avoid slow RE, gh-3370" }
Aug 29 01:49:33 server dovecot[472]: imap-login: Disconnected: Connection closed
: SSL_accept() failed: error:14209102:SSL routines:tls_early_post_process_client
_hello:unsupported protocol (no auth attempts in 0 secs): user=<>, rip=192.0.2.5
, lip=127.0.0.1, TLS handshaking: SSL_accept() failed: error:14209102:SSL routin
es:tls_early_post_process_client_hello:unsupported protocol
# failJSON: { "time": "2004-08-29T16:06:58", "match": true , "host": "192.0.2.5" } # failJSON: { "time": "2004-08-29T16:06:58", "match": true , "host": "192.0.2.5" }
Aug 29 16:06:58 s166-62-100-187 dovecot: imap-login: Disconnected (disconnected before auth was ready, waited 0 secs): user=<>, rip=192.0.2.5, lip=192.168.1.2, TLS handshaking: SSL_accept() syscall failed: Connection reset by peer Aug 29 16:06:58 s166-62-100-187 dovecot: imap-login: Disconnected (disconnected before auth was ready, waited 0 secs): user=<>, rip=192.0.2.5, lip=192.168.1.2, TLS handshaking: SSL_accept() syscall failed: Connection reset by peer
# failJSON: { "time": "2004-08-31T16:15:10", "match": true , "host": "192.0.2.6" } # failJSON: { "time": "2004-08-31T16:15:10", "match": true , "host": "192.0.2.6" }
Aug 31 16:15:10 s166-62-100-187 dovecot: imap-login: Disconnected (client didn't finish SASL auth, waited 2 secs): user=<>, method=PLAIN, rip=192.0.2.6, lip=192 .168.1.2, TLS: SSL_read() syscall failed: Connection reset by peer, TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits) Aug 31 16:15:10 s166-62-100-187 dovecot: imap-login: Disconnected (client didn't finish SASL auth, waited 2 secs): user=<>, method=PLAIN, rip=192.0.2.6, lip=192 .168.1.2, TLS: SSL_read() syscall failed: Connection reset by peer, TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)
# failJSON: { "time": "2004-08-31T16:21:53", "match": true , "host": "192.0.2.7" } # failJSON: { "time": "2004-08-31T16:21:53", "match": true , "host": "192.0.2.7" }
Aug 31 16:21:53 s166-62-100-187 dovecot: imap-login: Disconnected (no auth attem pts in 4 secs): user=<>, rip=192.0.2.7, lip=192.168.1.2, TLS handshaking: SSL_ac cept() syscall failed: Connection reset by peer Aug 31 16:21:53 s166-62-100-187 dovecot: imap-login: Disconnected (no auth attem pts in 4 secs): user=<>, rip=192.0.2.7, lip=192.168.1.2, TLS handshaking: SSL_ac cept() syscall failed: Connection reset by peer
 End of changes. 2 change blocks. 
0 lines changed or deleted 62 lines changed or added

Home  |  About  |  Features  |  All  |  Newest  |  Dox  |  Diffs  |  RSS Feeds  |  Screenshots  |  Comments  |  Imprint  |  Privacy  |  HTTP(S)