晋太元中,武陵人捕鱼为业。缘溪行,忘路之远近。忽逢桃花林,夹岸数百步,中无杂树,芳草鲜美,落英缤纷。渔人甚异之,复前行,欲穷其林。 林尽水源,便得一山,山有小口,仿佛若有光。便舍船,从口入。初极狭,才通人。复行数十步,豁然开朗。土地平旷,屋舍俨然,有良田、美池、桑竹之属。阡陌交通,鸡犬相闻。其中往来种作,男女衣着,悉如外人。黄发垂髫,并怡然自乐。 见渔人,乃大惊,问所从来。具答之。便要还家,设酒杀鸡作食。村中闻有此人,咸来问讯。自云先世避秦时乱,率妻子邑人来此绝境,不复出焉,遂与外人间隔。问今是何世,乃不知有汉,无论魏晋。此人一一为具言所闻,皆叹惋。余人各复延至其家,皆出酒食。停数日,辞去。此中人语云:“不足为外人道也。”(间隔 一作:隔绝) 既出,得其船,便扶向路,处处志之。及郡下,诣太守,说如此。太守即遣人随其往,寻向所志,遂迷,不复得路。 南阳刘子骥,高尚士也,闻之,欣然规往。未果,寻病终。后遂无问津者。
| DIR:/proc/thread-self/root/proc/thread-self/root/opt/cpguard/cpglfd/configs/jails.available/ |
| Current File : //proc/thread-self/root/proc/thread-self/root/opt/cpguard/cpglfd/configs/jails.available/exim.yaml |
jails:
- name: "exim-attacks"
enabled: true
log_paths:
- "/var/log/exim_mainlog" # Common on cPanel / CentOS
- "/var/log/exim/mainlog" # Common on generic Linux
- "/var/log/exim/main.log" # Common on generic Linux
rules:
# 1. SASL / AUTH Failures (Brute Force)
# Matches: "535 Incorrect authentication data"
# Covers standard login attempts and Dovecot-linked failures
- regexp: "authenticator failed for .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]: 535 Incorrect authentication data"
# 2. Relay Denied (Spam Attempts)
# Matches: External IPs trying to send mail through your server without auth
- regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\] .* rejected RCPT <.*>: Relay not permitted"
# 3. Dictionary Attacks (Unknown Users)
# Matches: Spammers guessing email addresses (e.g., admin@, info@)
# Note: Higher retry limit (5) to avoid banning legit servers for a simple typo.
- regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\] .* rejected RCPT <.*>: (Unknown user|Unrouteable address)"
max_retries: 15
# 4. Synchronization Errors (DoS / Botnets)
# Matches: Bots that don't wait for the server greeting (Protocol Violation)
- regexp: "SMTP protocol violation: synchronization error .* H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]"
# 5. RBL/Blacklist Blocks (Optional)
# Matches: IPs that are already on a spam blacklist (e.g., Spamhaus)
- regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]: .* rejected after DATA: .* listed in"
# 6. Matches: sender verify fail (when the sender's domain or email is invalid)
- regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* sender verify fail for"
max_retries: 5 # Recommended: Set >1 as DNS glitches can sometimes cause false positives
# 7. Matches:
# 1. "Unrouteable address" (User doesn't exist or domain creates a loop)
# 2. "all relevant MX records point to non-existent hosts" (Bad MX)
- regexp: "H=.* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* (Unrouteable address|all relevant MX records point to non-existent hosts)"
# 8. Matches: SMTP connection from (host) [IP] closed by DROP in ACL
- regexp: "SMTP connection from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\].* closed by DROP in ACL"
max_retries: 15
# 9. Too many errors (Garbage Commands)
# "SMTP call from... dropped: too many syntax or protocol errors"
# Matches clients that send junk commands or nonsensical data.
- regexp: "SMTP call from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\](?::\\d+)? dropped: too many (?:(?:nonmail|unrecognized) commands|syntax or protocol errors)"
max_retries: 20
# 10. Protocol Errors (Command not advertised)
# "SMTP protocol error... command used when not advertised"
# Matches bots trying to AUTH when not allowed, or PIPELINING when not supported.
- regexp: "SMTP protocol error in \".*\" .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\](?::\\d+)? [A-Z]+ (?:command used when not advertised|authentication mechanism not supported)"
max_retries: 15
# 11. Empty Connections (Socket Wasting)
# "no MAIL in SMTP connection from"
# Matches bots that connect, wait, and disconnect without sending anything.
- regexp: "no MAIL in SMTP connection from .* \\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]"
# Global Defaults for Exim
max_retries: 10
find_time: "1m"
ban_time: "1h"
actions:
- name: "cpgblock-exim"
ban_command: '/usr/bin/cpgcli ip --temp-block {{.IP}} --reason "Blocked by {{.JailName}} due to more than {{.MaxRetry}} abusive access within {{.FindTime}} seconds" --extra " LogFile: {{.LogPath}} | Reason: {{.LogLine}}"'
unban_command: "/usr/bin/cpgcli ip --temp-block {{.IP}} --remove"
|