[Mailman-Users] Logging failed Admin logins [SEC=UNCLASSIFIED]

Mark Sapiro mark at msapiro.net
Mon May 21 23:09:55 CEST 2012


Dale, Mark wrote:
>
>I've had a look through the Mailman log files and can't see that Mailman writes anywhere for failed login attempts (to the Admin page).


Correct.


>It seems that the best that can be done at the moment is to guess it from the POST entries in the Apache logs.
>
>Even there,  a failed login just reloads the page and  generates an Apache '200' (Okay) entry for the request.


Since Mailman 2.1.14, a login failure generates a 401. This should be
enough for a fail2ban regexp to identify these failures.

-- 
Mark Sapiro <mark at msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan



More information about the Mailman-Users mailing list