Hi All, I'm looking at implementing OSSEC on our pop server to stop some recent exploits. How do you block an IP when the mail logs don't show you the source IP.
** Alert 1242018464.1287777: - syslog,access_control,authentication_failed, 2009 May 11 15:07:44 pop1->/var/log/maillog Rule: 2501 (level 5) -> 'User authentication failure.' Src IP: (none) User: (none) May 11 15:07:43 pop1 perdition[29955]: Auth: 216.250.166.73- >203.10.110.88 user="thomasmoore" server="mx1.netspace.net.au" port="110" status="failed: Re-Authentication Failure" In this example there is no source IP. The IP I want to block is 216.250.166.73 - so can Ossec help block this IP??? Thanks. Andy
