Any chance you have a version for Courier? Seems that adds content before the ylmc section that's throwing it off. I'd changed your version to match the line, but can't seem to get the reverse IP bit ( host81-149-19-219.in-addr.btopenworld.com ) to be caught.Sergio wrote:I had a direct rule just for YLMF-PC attacks and I have just added to the REGEX sticky, please check it at:
http://forum.configserver.com/viewtopic.php?f=6&t=7517&start=10#p22150
[edit]
Just an FYI, it's not always present. About half the time it exists, the rest it goes directly to the ylmf portion after "for".
Sample hit:
Code: Select all
2014-09-23 17:31:00 courier_login authenticator failed for host81-149-19-219.in-addr.btopenworld.com (ylmf-pc) [81.149.19.219]:61469: 535 Incorrect authentication data (set_id=jim)