Bonjour,
Je remarque des attaques postfix dans les logs qui perturbent les services WEB d’un serveur Debian 9 et ne sont pas bannies par fail2ban:
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:64676 to [ip.du.serv.eur]:25
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.05 from [77.247.110.113]:64676: EHLO ylmf-pc\r\n
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: DISCONNECT [77.247.110.113]:64676
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:59444 to [ip.du.serv.eur]:25
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.05 from [77.247.110.113]:59444: EHLO ylmf-pc\r\n
Feb 27 00:00:04 ks307144 postfix/postscreen[26029]: DISCONNECT [77.247.110.113]:59444
Feb 27 00:00:04 ks307144 systemd[1]: man-db.service: Succeeded.
Feb 27 00:00:04 ks307144 systemd[1]: Started Daily man-db regeneration.
Feb 27 00:00:06 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:61228 to [ip.du.serv.eur]:25
Feb 27 00:00:06 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.05 from
...
Feb 27 07:37:05 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:52036 to [ip.du.serv.eur]:25
Feb 27 07:37:05 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.04 from [77.247.110.113]:52036: EHLO ylmf-pc\r\n
Feb 27 07:37:05 ks307144 postfix/postscreen[26029]: DISCONNECT [77.247.110.113]:52036
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:55323 to [ip.du.serv.eur]:25
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.05 from [77.247.110.113]:55323: EHLO ylmf-pc\r\n
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: DISCONNECT [77.247.110.113]:55323
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:56835 to [ip.du.serv.eur]:25
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: PREGREET 14 after 0.05 from [77.247.110.113]:56835: EHLO ylmf-pc\r\n
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: DISCONNECT [77.247.110.113]:56835
Feb 27 07:37:06 ks307144 postfix/postscreen[26029]: CONNECT from [77.247.110.113]:54462 to [ip.du.serv.eur]:25
Mais cette IP qui se connecte/déconnecte pendant 7 heures sans réussir à envoyer aucun message ne semble pas bannie par fail2ban à 9h52 malgré 2 jails postfix:
$ sudo fail2ban-client status
Status
|- Number of jail: 16
`- Jail list: apache-badbots, apache-botsearch, apache-fakegooglebot, apache-nohome, apache-noscript, apache-overflows, dovecot, dovecot-pop3imap, joomla-login-errors, mysqld-auth, pam-generic, postfix, postfix-sasl, pureftpd, recidive, sshd
Quelqu’un sait-il s’il y a une jail fail2ban qui bannirait ce type d’attaque ?