Hello, I'm using Debian Bullseye (11) and sshguard debian package (2.4.2-1). I was wondering if you could create sshguard triggers for the following messages in the qmail-smtp log file: Reject::TLS::required Reject::AUTH::cram-md5

Also in the file: /var/log/mail.log the following messages which are entries from IMAP: vchkpw-smtps: password fail

  Kevin Zheng

    Sure. Do you have samples of the attack signature? Keep in mind that the log needs to include the attacker’s IP; otherwise, SSHGuard doesn’t know what to block.

