pop3-login login failures not blocked after Dovecot upgrade
Posted: 22 Feb 2012, 18:08
LFD doesn't seem to recognise pop3-login failures after upgrading to Dovecot 2.1.0
We are running Direct Admin current with Dovecot 2.1.0
/var/log# csf --version
csf: v5.46 (DirectAdmin)
These are the log entries that don't work now
Server1
Feb 22 11:21:39 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<root>, method=PLAIN, rip=211.142.85.44, lip=192.194.199.1
Feb 22 11:21:47 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<root>, method=PLAIN, rip=211.142.85.44, lip=192.194.199.1
Feb 22 11:21:47 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<backuppc>, method=PLAIN, rip=211.142.85.44, lip=lip=192.194.199.1
Server2
Feb 21 19:42:38 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violet>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:38 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violet>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<viola>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
I reverted back to Dovecot 2.0.18
These log entries are picked up by LFD
Server1
Feb 22 12:58:40 bob1 dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test1>, method=PLAIN, rip=192.168.1.101, lip=192.194.199.1
Server2
Feb 22 12:52:57 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test>, method=PLAIN, rip=192.168.1.101, lip=192.192.192.192
This may not be a CSF a bug but more of a regex matching issue
Any response appreciated.
WBA
We are running Direct Admin current with Dovecot 2.1.0
/var/log# csf --version
csf: v5.46 (DirectAdmin)
These are the log entries that don't work now
Server1
Feb 22 11:21:39 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<root>, method=PLAIN, rip=211.142.85.44, lip=192.194.199.1
Feb 22 11:21:47 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<root>, method=PLAIN, rip=211.142.85.44, lip=192.194.199.1
Feb 22 11:21:47 bob1 dovecot: pop3-login: Disconnected: Inactivity (auth failed, 1 attempts): user=<backuppc>, method=PLAIN, rip=211.142.85.44, lip=lip=192.194.199.1
Server2
Feb 21 19:42:38 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violet>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:38 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violet>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<vinnie>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<viola>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
Feb 21 19:42:39 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 10 secs): user=<violeta>, method=PLAIN, rip=117.21.127.39, lip=192.192.192.192
I reverted back to Dovecot 2.0.18
These log entries are picked up by LFD
Server1
Feb 22 12:58:40 bob1 dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test1>, method=PLAIN, rip=192.168.1.101, lip=192.194.199.1
Server2
Feb 22 12:52:57 bob2 dovecot: pop3-login: Disconnected (auth failed, 1 attempts): user=<test>, method=PLAIN, rip=192.168.1.101, lip=192.192.192.192
This may not be a CSF a bug but more of a regex matching issue
Any response appreciated.
WBA