3 ms·
> RCE a few years ago If it's this one (https://nvd.nist.gov/vuln/detail/CVE-2021-32749 https://nvd.nist.gov/vuln/detail/CVE-2021-32749), I think that's kind o
by hello_computer 3y ago
> RCE a few years ago
If it's this one (https://nvd.nist.gov/vuln/detail/CVE-2021-32749 https://nvd.nist.gov/vuln/detail/CVE-2021-32749), I think that's kind of a reach--especially for the typical use case, which uses neither mail nor whois, and only adds an ephemeral block rule to the firewall.
My beef with fail2ban is that it only checks logs on a (non-configurable) 1 second interval, which allows an attacker to make several attempts (> N) from the same IP in parallel inside of that second, even when the f2b configuration is set to block at the Nth failure.