Size: a a a

Independent mail community

2019 August 28

F

Fljúgandi Kettlingur in Independent mail community
Evgeniy
получаю Fatal: block_alloc(134217728): Out of memory, при этом
Fatal: master: service(imap): child 27361 returned error 83 (Out of memory (service imap { vsz_limit=256 MB }

При этом vsz_limit = 1G
он один гигабайт именно на сервисе imap?
источник

F

Fljúgandi Kettlingur in Independent mail community
ну и совсем тупой вопрос, после смены 256=>1G изменения же были применены?
источник

D

Denis in Independent mail community
Evgeniy
получаю Fatal: block_alloc(134217728): Out of memory, при этом
Fatal: master: service(imap): child 27361 returned error 83 (Out of memory (service imap { vsz_limit=256 MB }

При этом vsz_limit = 1G
Патч от DoS  CVE-2019-11500 есть?
источник

F

Fljúgandi Kettlingur in Independent mail community
Nika 7+(3-1)=?
источник
2019 August 29

D

Denis in Independent mail community
источник

F

Fljúgandi Kettlingur in Independent mail community
Язабан
источник

E

Evgeniy in Independent mail community
Короче по памяти с dovecot - там в конфиге не было секции service imap.  А я добавлял в service imap-login, ну и изменял $default_vsz_limit.
А надо было короче в dovecot.conf создать секцию service imap, и там указать параметр. И все ок.
источник
2019 August 30

SG

Sergey Grigoryev (TOMCK) in Independent mail community
Sergey Grigoryev (TOMCK), [30.08.19 12:55]
Добрый день ! Ребята помогите с fail2ban. в логах ексима вылетает такое

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
2019-08-30 12:41:58.940 [14209] CRAM_MD5_AUTH authenticator failed for (hosting-by.directwebhost.org.) [45.227.253.116]:47946 I=[xxx.xxx.xxx.xxx]:25: 535 Incorrect authentication data (set_id=akadem.kniga)

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
в exim.conf есть строка

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
failregex = %(pid)s \w+ authenticator failed for (\S+ )?\[\S+\] \[<HOST>\]:25: 535 Incorrect authentication data( \(set_id=.*\)|: \d+ Time\(s\))?\s*$

Sergey Grigoryev (TOMCK), [30.08.19 12:56]
но проверяйю fail2ban-regexp не находит

Sergey Grigoryev (TOMCK), [30.08.19 12:56]
может формат не правильный?
источник

D

Denis in Independent mail community
Sergey Grigoryev (TOMCK)
Sergey Grigoryev (TOMCK), [30.08.19 12:55]
Добрый день ! Ребята помогите с fail2ban. в логах ексима вылетает такое

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
2019-08-30 12:41:58.940 [14209] CRAM_MD5_AUTH authenticator failed for (hosting-by.directwebhost.org.) [45.227.253.116]:47946 I=[xxx.xxx.xxx.xxx]:25: 535 Incorrect authentication data (set_id=akadem.kniga)

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
в exim.conf есть строка

Sergey Grigoryev (TOMCK), [30.08.19 12:55]
failregex = %(pid)s \w+ authenticator failed for (\S+ )?\[\S+\] \[<HOST>\]:25: 535 Incorrect authentication data( \(set_id=.*\)|: \d+ Time\(s\))?\s*$

Sergey Grigoryev (TOMCK), [30.08.19 12:56]
но проверяйю fail2ban-regexp не находит

Sergey Grigoryev (TOMCK), [30.08.19 12:56]
может формат не правильный?
А ты на нужный лог натравил фильтр?
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
Конечно
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
root@smtp:/etc/fail2ban/filter.d# fail2ban-regex /var/log/exim4/reject /etc/fail2ban/filter.d/exim-test.conf

Running tests
=============

Use   failregex filter file : exim-test, basedir: /etc/fail2ban
Use         log file : /var/log/exim4/reject
Use         encoding : UTF-8


Results
=======

Failregex: 0 total

Ignoreregex: 0 total

Date template hits:
|- [# of hits] date format
|  [100] Year(?P<_sep>[-/.])Month(?P=_sep)Day 24hour:Minute:Second(?:,Microseconds)?
`-

Lines: 100 lines, 0 ignored, 0 matched, 100 missed
[processed in 0.01 sec]

Missed line(s): too many to print.  Use --print-all-missed to print all 100 lines
источник

D

Denis in Independent mail community
fail2ban-client проверял состояние?
источник

D

Denis in Independent mail community
Sergey Grigoryev (TOMCK)
root@smtp:/etc/fail2ban/filter.d# fail2ban-regex /var/log/exim4/reject /etc/fail2ban/filter.d/exim-test.conf

Running tests
=============

Use   failregex filter file : exim-test, basedir: /etc/fail2ban
Use         log file : /var/log/exim4/reject
Use         encoding : UTF-8


Results
=======

Failregex: 0 total

Ignoreregex: 0 total

Date template hits:
|- [# of hits] date format
|  [100] Year(?P<_sep>[-/.])Month(?P=_sep)Day 24hour:Minute:Second(?:,Microseconds)?
`-

Lines: 100 lines, 0 ignored, 0 matched, 100 missed
[processed in 0.01 sec]

Missed line(s): too many to print.  Use --print-all-missed to print all 100 lines
где mainlog
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
А зчем maillog
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
[exim]
enabled = true
filter = exim
port = smtp,ssmtp
action = iptables-allports[name=exim, protocol=tcp]
logpath = /var/log/exim4/rejectlog
maxretry = 2
bantime = 77200
findtime = 7200
источник

D

Denis in Independent mail community
фильтр по матчу скипнут. или неверный regexp, возможно другой формат выводит.
источник

D

Denis in Independent mail community
filter = exim так у тебя exim-test
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
да я скопировал
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
и на нем проверяю
источник

SG

Sergey Grigoryev (TOMCK) in Independent mail community
в тесте одна строчка
источник