Commit Graph

3158 Commits (af088eefcef8ba70713a15ec9fc75c2637634f92)

Author SHA1 Message Date
Daniel Black 2bcc6c66b1 TST: remove python 2.5 from TravisCI 2013-11-29 21:54:36 +11:00
Daniel Black b9b2ddf996 BF: smtps not IANA standard. Closes #447 2013-11-29 21:47:53 +11:00
Daniel Black cade746307 BF: jail name mysqld-syslog-iptables too long. removed -iptables. Thanks Stefan (#447) 2013-11-29 21:45:11 +11:00
Daniel Black 9e53892708 BF: did remove instead of move 2013-11-29 19:26:24 +11:00
Daniel Black af4feb0c92 Actions to have f2b- as prefix instead of fail2ban- as per #462 2013-11-29 19:08:38 +11:00
Daniel Black b157be22d2 TST: pids don't match test case for sshd filter 2013-11-29 16:02:28 +11:00
Daniel Black fb666b69ff BF: firewall-cmd-direct-new was too long. Thanks Joel. 2013-11-28 23:35:05 +11:00
Daniel Black 99838440c8 DOC: document rational behind 20 character jail name limit 2013-11-28 23:18:34 +11:00
Daniel Black 227f27ce6b ENH: added multiline filter for sshd filter 2013-11-25 14:55:41 +11:00
Daniel Black f80fa7d7a0 Merge pull request #456 from grooverdan/apffix
BF: add init section with name for action.d/apf. Closes #398
2013-11-24 13:48:46 -08:00
Daniel Black 13223c33f5 MRG: recidive-protocol-all 2013-11-25 08:22:09 +11:00
Daniel Black dc154c792e BF: add init section with name for action.d/apf. Closes #398 2013-11-25 08:08:20 +11:00
Daniel Black 093aee9676 TST: no python-2.5 any more - https://github.com/travis-ci/travis-ci/issues/1668 2013-11-25 07:54:49 +11:00
Yaroslav Halchenko 085ebbe1de Changelog entries for the last changes 2013-11-24 11:55:58 -05:00
Yaroslav Halchenko a26d4f42b7 ENH: added optional [PID] matching in recidive.conf 2013-11-24 10:21:02 -05:00
Yaroslav Halchenko a6f085786c ENH: reintroducing levelnameinto syslog msgs, time stamp and indentation in non-syslog msgs
any indentation from syslog msgs wsa removed -- no need
2013-11-24 10:19:50 -05:00
Yaroslav Halchenko 09e8c9be28 Merge pull request #454 from grooverdan/kernel-timestamp
BF: kernel messages can have space. Thanks ag4ve(shawn). Closes #448
2013-11-24 07:02:03 -08:00
Daniel Black a989787e0d DOC: more distro bug tracker urls 2013-11-24 18:43:23 +11:00
Daniel Black 9a82bc3c61 BF: kernel messages can have space. Thanks ag4ve(shawn). Closes #448 2013-11-24 18:21:02 +11:00
Daniel Black 98eacdf333 MRG/BF: merge from master. Fix bugs in iso8601 2013-11-24 16:36:06 +11:00
Daniel Black f2c529ca7b ENH: move signal.signal(signal.SIGHUP, signal.SIG_IGN) before fork in server. closes #446 2013-11-23 11:33:41 +11:00
Yaroslav Halchenko d34d8db3d2 BF/ENH: include [PID] into logging msgs, remove indentation from syslog messages
Otherwise leads to incorrect parsing of the log messages by syslog(-ng). See
http://bugs.debian.org/730202

I also removed %(levelname)-6s from syslog messages completely since they are
passed to the syslog and it is up to the configuration/admin to decide include
levels into the messages or not (I have checked that at least debug level indeed
goes to /var/log/debug)
2013-11-22 15:57:03 -05:00
Daniel Black 28d8aec511 DOC: Arch Linux link 2013-11-21 07:05:21 +11:00
Daniel Black 24c143b411 Merge pull request #445 from grooverdan/suhosin
TST: more test cases for suhosin
2013-11-19 15:23:59 -08:00
Daniel Black 015b403df0 TST: more test cases for suhosin 2013-11-20 10:01:06 +11:00
Yaroslav Halchenko 629e9ae445 Merge pull request #443 from grooverdan/apache-authfix
BF: apache filters using error log weren't matched when referer existed ...
2013-11-18 15:53:39 -08:00
Daniel Black 284f811c91 BF: apache filters using error log weren't matched when referer existed in HTTP header 2013-11-19 10:27:55 +11:00
Yaroslav Halchenko 491165c929 Merge pull request #438 from grooverdan/solid-pop3d
ENH: filter for Solid-pop3d
2013-11-17 17:34:46 -08:00
Daniel Black 1ea68b2d0c DOC: filter.d/solid-pop3d - document lack of PAM support. Thanks to Jacques for the log messages 2013-11-18 09:44:26 +11:00
Yaroslav Halchenko d583637c50 changeset_ac061155f093464fb6cd2329d3d513b15c68e256.diff absorbed upstream 2013-11-17 17:32:25 -05:00
Yaroslav Halchenko 30fe2ce7ba changelog entry for previous cherry picked patch 2013-11-17 17:29:56 -05:00
Yaroslav Halchenko 0c24daeb10 added patch changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff to "cherry-pick" d4f6ca4f85 (ENH: adding custom date format for proftpd when logging in its own log file (default on Debian) -- includes milliseconds) 2013-11-17 17:27:50 -05:00
Daniel Black 0eea0a35db ENH: filter.d/solid-pop3d - added log messages and regexes 2013-11-18 08:58:23 +11:00
Daniel Black 8aa20a7b0e ENH: credits for #440 recidive jail protocol=all 2013-11-18 07:59:56 +11:00
Daniel Black dab2ddb9da ENH: recidive jail to block all protocols. Closes #440 2013-11-18 07:57:16 +11:00
Daniel Black 2c63b1fe93 Merge pull request #439 from yarikoptic/bf/proftpd-millisec
ENH: proftpd in Debian (now or forever) has ",milliseconds" in its date format
2013-11-17 12:44:44 -08:00
Daniel Black b3b9ea4559 ENH: jail for solid-pop3d 2013-11-18 07:42:45 +11:00
Yaroslav Halchenko 19a472928d More of changelog entries to close bugs addressed in this release 2013-11-16 22:58:15 -05:00
Yaroslav Halchenko 4dba65f685 debian/NEWS - information for change of default iptables action to REJECT now (Closes: #711463) 2013-11-16 22:30:31 -05:00
Yaroslav Halchenko 82174ea4c4 Changelog for preceding proftpd date format change 2013-11-16 22:18:51 -05:00
Yaroslav Halchenko d4f6ca4f85 ENH: adding custom date format for proftpd when logging in its own log file (default on Debian) -- includes milliseconds
Should resolve Debian #648276
2013-11-16 22:15:58 -05:00
Yaroslav Halchenko 2d068572bc debian/jail.conf - dropbear jail: use dropbear filter (instead of ssh) and monitor auth.log instead of non-existing /var/log/dropbear (Closes: #620760) 2013-11-16 21:35:04 -05:00
Yaroslav Halchenko 7d8dc0f322 fresh changelog 2013-11-16 21:30:15 -05:00
Yaroslav Halchenko b2f5a79eeb Merge tag '0.8.11' into debian
* tag '0.8.11':
  DOC: finalise 0.8.11 release
  BF/ENH: DoS resistant roundcube-auth with test cases and more variation in IMAP error given
  BF: exim filter to be DoS resistant
  ENH: DoS resistant dropbear filter
  BF/ENH: asterisk connection ID is a hex not decimal number. Add "Rejecting unknown SIP connection from <HOST>" regex thanks to Jonathan Lanning
  ENH: apache-2.4 message IDs for filter apache-noscript
  TST: change source URL
  ENH: apache-overflow filter to have HTTP-2.4 message IDs and test samples
  ENH: apache-overflows - more detail on "request failed: URI too long (longer than %d)" with test case
  TST: end of json in sshd sample log
  TST: fix space in sshd sample log
  TST: test case that shows injection
  DOC: more on filter regexes - DEVELOP
  DOC: filter regex debugging
  BF: anchor introduced nginx-http-auth at the end
2013-11-16 21:19:48 -05:00
Daniel Black 88eff70774 ENH: filter.d/solid-pop3d added 2013-11-16 09:43:15 +11:00
Daniel Black ed212fcdcc DOC: new ChangeLog header 2013-11-16 09:40:05 +11:00
Daniel Black 84f915c1f7 fix nginx-http-auth lof file location and MANIFEST 2013-11-13 09:57:13 +11:00
Daniel Black a7604c899f DOC: list Wiki pages to update after a release 2013-11-13 09:43:36 +11:00
Daniel Black 1ac7b53cad MRG: merge from master 2013-11-13 09:16:45 +11:00
Daniel Black 752ea054db DOC: post release version change 2013-11-13 09:01:52 +11:00