diff --git a/MANIFEST b/MANIFEST index 4dbbf17a..9f386450 100644 --- a/MANIFEST +++ b/MANIFEST @@ -48,6 +48,8 @@ config/filter.d/vsftpd.conf config/filter.d/apache-auth.conf config/filter.d/sshd.conf config/filter.d/couriersmtp.conf +config/filter.d/qmail.conf +config/filter.d/postfix.conf config/action.d/iptables.conf config/action.d/mail-whois.conf config/action.d/dummy.conf diff --git a/config/filter.d/couriersmtp.conf b/config/filter.d/couriersmtp.conf index 0a57373f..92d942b6 100644 --- a/config/filter.d/couriersmtp.conf +++ b/config/filter.d/couriersmtp.conf @@ -9,6 +9,6 @@ # Option: failregex # Notes.: regex to match the password failures messages in the logfile. -# Values: TEXT Default: Authentication failure|Failed password|Invalid user +# Values: TEXT Default: # failregex = error,relay=(?:::f{4,6}:)?(?P\S*),.*550 User unknown diff --git a/config/filter.d/postfix.conf b/config/filter.d/postfix.conf new file mode 100644 index 00000000..a226d28b --- /dev/null +++ b/config/filter.d/postfix.conf @@ -0,0 +1,14 @@ +# Fail2Ban configuration file +# +# Author: Cyril Jaquier +# +# $Revision: 267 $ +# + +[Definition] + +# Option: failregex +# Notes.: regex to match the password failures messages in the logfile. +# Values: TEXT Default: +# +failregex = reject: RCPT from (.*)\[(?P\S*)\]: 554 diff --git a/config/filter.d/qmail.conf b/config/filter.d/qmail.conf new file mode 100644 index 00000000..082f15cc --- /dev/null +++ b/config/filter.d/qmail.conf @@ -0,0 +1,14 @@ +# Fail2Ban configuration file +# +# Author: Cyril Jaquier +# +# $Revision: 267 $ +# + +[Definition] + +# Option: failregex +# Notes.: regex to match the password failures messages in the logfile. +# Values: TEXT Default: +# +failregex = (?:[\d,.]+[\d,.] rblsmtpd: |421 badiprbl: ip )(?P\S*) diff --git a/config/filter.d/vsftpd.conf b/config/filter.d/vsftpd.conf index f1c82be2..0c992359 100644 --- a/config/filter.d/vsftpd.conf +++ b/config/filter.d/vsftpd.conf @@ -11,4 +11,4 @@ # Notes.: regex to match the password failures messages in the logfile. # Values: TEXT Default: Authentication failure|Failed password|Invalid user # -failregex = FAIL LOGIN +failregex = vsftpd: \(pam_unix\) authentication failure; .* rhost=(?P\S*)