3 ms·
> At least one RCE, admittedly with a non-default fail2ban config and a somewhat unlikely attack chain: you had to manipulate answers from a whois server. Sur
by rigid 3y ago
> At least one RCE, admittedly with a non-default fail2ban config and a somewhat unlikely attack chain:
you had to manipulate answers from a whois server.
Sure, it increases attack surface (like any additional piece of code) but argueing to better let an IP hammer your mailserver with infinite stuffed credentials just to avoid possible bugs, is questionable at least.
fail2ban's CVE track record is quite good in comparision, if you take that as metric. It might be even more secure than using multiple different rate-limiting implementations that were written in C.
- marcus0x62 3y agoYes, as I said, the attack chain was unlikely to be used it practice.