Sergey G. Brester
7544e969d5
new test messages for exim (gh-3497)
2 years ago
Sergey G. Brester
2b98f461bb
Merge pull request #2860 from a16bitsysop/mikrotik
...
Add action for mikrotik routerOS
2 years ago
Sergey G. Brester
e73748c442
Merge branch 'master' into mikrotik
2 years ago
Sergey G. Brester
27294c4b9e
fail2banregextestcase: compatibility fix for testWrongRE
2 years ago
sebres
56485c8548
filtertestcase.py: byte related copy of lines in tests (locale independent); closes gh-2936
2 years ago
Sergey G. Brester
a9b30eb86e
Merge pull request #2226 from mbologna/nginx-forbidden
...
Feat: ban nginx forbidden accesses
2 years ago
Sergey G. Brester
9cbf59c827
anchored datepattern and added journalmatch (if monitoring systemd journal)
2 years ago
Sergey G. Brester
212a4c236a
update changeLog, nginx-forbidden, gh-2226
2 years ago
Sergey G. Brester
2c0360d178
Merge branch 'master' into nginx-forbidden
2 years ago
sebres
d1d1730de0
Merge fix #3479 :
...
action.d/cloudflare-token.conf: url-encode args by unban
closes 'gh-3479'
2 years ago
Sergey G. Brester
3d4bed50c2
changelog entry (gh-3479)
2 years ago
Sergey G. Brester
c7f8b75e7e
action.d/cloudflare-token.conf: fixes #3479 , url-encode args by unban
2 years ago
Duncan Bellamy
7dc32971f8
changed missed names
2 years ago
Duncan Bellamy
9b1417a169
apply suggestions
2 years ago
Duncan Bellamy
b892133d51
move new comment in changelog
2 years ago
Sergey G. Brester
d46ec3a555
add jail boundary to flush command for more precise targeting of jail (if some name may be equal to prefix of other name)
2 years ago
Duncan Bellamy
5781675a7d
change startcomment and comment so correct rules are flushed
2 years ago
Duncan Bellamy
ac2076ef4f
change unban back to find comment so correct entry always deleted
2 years ago
Duncan Bellamy
0e3e9b1d7f
Add flushaction
...
Change unban to find by ip address not comment
2 years ago
Duncan Bellamy
9997807fb3
Add action for mikrotik routerOS
2 years ago
Vít Kabele
a2c77429b9
New filter: routeros-auth.conf ( Closes #3469 )
...
Add filter to detect failed login attempts in the log produced by
MikroTik RouterOS.
- Add the filter to jail.conf
- Add testcase for the filter
Signed-off-by: Vít Kabele <vit@kabele.me>
2 years ago
Sergey G. Brester
234660e94d
CI-workflow: remove 3.5 (seems to have a bug in GHA now)
2 years ago
Sergey G. Brester
17f060526e
readme: amend
2 years ago
Sergey G. Brester
92fae68071
readme: update version
2 years ago
Sergey G. Brester
06e3dea062
Merge pull request #3460 from Trotyl84/patch-1
...
.gitignore: ignore `.venv/`
2 years ago
Łukasz Turon
5dcbc0dd55
Update .gitignore
...
Please add this entry for virtual python interpreter. This directory name is needed in the PyCharm environment.
2 years ago
sebres
f93a538693
gh-3447: fix careless mistake arisen in b12a3acb06
by attempt to implement new reload capacity (rewritten latter): causing error "'noduplicates' is not defined" by double jail configuration
2 years ago
sebres
a3a3fffa54
Merge branch 'fix-gh-3438':
...
* circumvent SEGFAULT in a python's socket module by getaddrinfo with disabled IPv6 (gh-3438)
* improve auto-detection of IPv6 support (`allowipv6 = auto` by default)
* improve `ignoreself` by considering all local addresses from network interfaces additionally to IPs from hostnames (gh-3132)
2 years ago
sebres
ed135b6a93
changelog entries (gh-3438, gh-3132)
2 years ago
sebres
582436aadf
don't add subnets to local addresses of `ignoreself` from network interfaces, use only IPs instead (subnets may be too heavy and not wanted, todo: make it configurable later)
2 years ago
sebres
cb8674e68a
amend with few improvements, IPv6IsAllowed prefers IPs from network interfaces (if available for platform) and uses DNS (socket.getaddrinfo) as a fallback only
2 years ago
sebres
09c23fd5b8
try to obtain local addresses from network interfaces before DNS to IP lookup (closes gh-3132);
...
DNSUtils.getSelfIP returns IPAddrSet now (because own IPs may be the subnets now, so the check `ignoreself` must check whether any of subnets contains the IP)
2 years ago
sebres
d8a9812adc
improve auto detection of IPv6 - try to check sysctl net.ipv6.conf.all.disable_ipv6 (prefer value read from `/proc/sys/net/ipv6/conf/all/disable_ipv6`)
2 years ago
sebres
58834b6734
better auto-detection for IPv6 support (`allowipv6 = auto` by default); circumvent SF in some python's socket module by getaddrinfo with disabled IPv6 (closes gh-3438)
2 years ago
Sergey G. Brester
432e7e1e93
no warning if no config value but default (debug message now)
...
closes #3420
2 years ago
Sergey G. Brester
bd6e7aeff0
Merge pull request #2112 from al42and/dante
...
Create filter for Dante SOCKS server
2 years ago
Sergey G. Brester
efbbcb41ea
non capturing group
2 years ago
Sergey G. Brester
996553f330
review, simplify regex and capture user name
2 years ago
Andrey Alekseenko
df91b047d2
Dante SOCKS server: handle "1 byte/second" case
...
Thanks to @Loriowar and @sebres for pointing it out
2 years ago
Andrey Alekseenko
05c162ef10
Create filter for Dante SOCKS server
2 years ago
Sergey G. Brester
ae5fe2e003
amend to #3405 , eliminate catch-all
2 years ago
sebres
36af3f2502
Merge branch 'gh-3405'
2 years ago
sebres
a58fcb8786
fix cut out of match for pattern with `{EPOCH}` (similar to other datepatterns group capturing whole regex only added if no groups specified at all);
...
allows to specify more precise anchored patterns, for example `datepattern = ^type=\S+ msg=audit\(({EPOCH})` for selinux-filters
2 years ago
sebres
cbb097a2b3
small amend (non capturing group)
2 years ago
sebres
82506f0586
filter.d/selinux-ssh.conf, filter.d/selinux-common.conf: fixes #3405 (new format with GS and additional parameters, e. g. grantors)
2 years ago
sebres
eba33d6205
version bump
2 years ago
sebres
e1d3006b03
update 1.0.2 -- finally-war-game-test-tape-not-a-nuclear-alarm
2 years ago
sebres
fd3805b40a
changelog: backend `systemd`: code review and several fixes
2 years ago
sebres
cd17906afe
Merge branch '0.11'
2 years ago
sebres
d8e2b03a24
`filter.d/named-refused.conf` extended (closes gh-3388):
...
- support BIND named log categories
- allow `info:` as possible error prefix too ("query (cache) denied" may occur as info)
2 years ago