diff --git a/ChangeLog b/ChangeLog index 0d088e0b..ebd511c0 100644 --- a/ChangeLog +++ b/ChangeLog @@ -64,6 +64,8 @@ ver. 0.8.11 (2013/XX/XXX) - loves-unittests Steven Hiscocks * filter.d/dovecot - Addition of session, time values and possible blank user + Zurd and Daniel Black + * filter/named-refused - added refused on zone transfer ver. 0.8.10 (2013/06/12) - wanna-be-secure ----------- diff --git a/THANKS b/THANKS index ac9eee30..f333c833 100644 --- a/THANKS +++ b/THANKS @@ -57,3 +57,4 @@ Yaroslav Halchenko ykimon Yehuda Katz zugeschmiert +Zurd diff --git a/config/filter.d/named-refused.conf b/config/filter.d/named-refused.conf index 1cdc626e..e30afee7 100644 --- a/config/filter.d/named-refused.conf +++ b/config/filter.d/named-refused.conf @@ -26,6 +26,7 @@ __line_prefix=(?:\s\S+ %(__daemon_combs_re)s\s+)? # Values: TEXT # failregex = %(__line_prefix)sclient #\S+: (view (internal|external): )?query(?: \(cache\))? '.*' denied\s*$ + %(__line_prefix)sclient #\S+: zone transfer '\S+/AXFR/\w+' denied\s*$ # Option: ignoreregex # Notes.: regex to ignore. If this regex matches, the line is ignored. diff --git a/testcases/files/logs/named-refused b/testcases/files/logs/named-refused index 6f6092e2..04b0e34f 100644 --- a/testcases/files/logs/named-refused +++ b/testcases/files/logs/named-refused @@ -10,3 +10,8 @@ Jul 24 14:20:25 raid5 named[3935]: client 148.160.29.6#33081: query (cache) 'shi Jul 24 14:23:36 raid5 named[3935]: client 148.160.29.6#33081: query (cache) 'mietberatung.de/NS/IN' denied # failJSON: { "time": "2005-07-24T14:23:36", "match": true , "host": "62.109.4.89" } Jul 24 14:23:36 raid5 named[3935]: client 62.109.4.89#9334: view external: query (cache) './NS/IN' denied +# failJSON: { "time": "2013-08-11T03:36:11", "match": true , "host": "1.2.3.4" } +11-Aug-2013 03:36:11.372 error: client 1.2.3.4#52115: zone transfer 'domain.com/AXFR/IN' denied +# failJSON: { "time": "2004-08-17T08:20:22", "match": true , "host": "223.252.23.219" } +Aug 17 08:20:22 catinthehat named[2954]: client 223.252.23.219#56275: zone transfer 'openquery.eu/AXFR/IN' denied +