Hi All,

I'm looking at implementing OSSEC on our pop server to stop some
recent exploits. How do you block an IP when the mail logs don't show
you the source IP.

** Alert 1242018464.1287777: -
syslog,access_control,authentication_failed,
2009 May 11 15:07:44 pop1->/var/log/maillog
Rule: 2501 (level 5) -> 'User authentication failure.'
Src IP: (none)
User: (none)
May 11 15:07:43 pop1 perdition[29955]: Auth: 216.250.166.73-
>203.10.110.88 user="thomasmoore" server="mx1.netspace.net.au"
port="110" status="failed: Re-Authentication Failure"

In this example there is no source IP. The IP I want to block is
216.250.166.73 - so can Ossec help block this IP???

Thanks.

Andy

Reply via email to