Hacker News new | ask | show | jobs
by loeg 1729 days ago
You know, or just don’t use fail2ban: https://research.securitum.com/fail2ban-remote-code-executio... . It’s adding extra attack surface for a cosmetic benefit.
1 comments

Good catch, thanks!

Remedy: Don't let fail2ban send mail, or at least remove the whois part.