Commit Graph

4634 Commits (df9b352baca7b492f73581899a2a82637f5c15b7)
 

Author SHA1 Message Date
sebres 187514eda7 bump version (0.10.3 -> 0.10.4.dev1)
7 years ago
sebres 0a50f2e19e next release of 0.10: bump version, update ChangeLog, man's and MANIFEST etc.
7 years ago
sebres 5dfba17663 Merge pull request #2064 from mgrant0/0.11 (rebased)
7 years ago
sebres 4a8506fcca update ChangeLog
7 years ago
Michael Grant 57bc502d5c Update sendmail-reject.conf
7 years ago
Michael Grant 2ab6a5ae62 Update sendmail-auth.conf
7 years ago
Michael Grant 87520e8008 Sendmail logs IPv6 addresses with the prefix 'IPv6:'. Added (IPv6:)? before all <HOST> regexes to match the IPv6 address (but not the prefix).
7 years ago
sebres 2ff65f5d3c test_badips.py: increase timeout in normal mode (avoid sporadic CI errors if badips gets slowly).
7 years ago
Sergey G. Brester 521de5edfd
Merge pull request #2101 from mercurytoxic/mercurytoxic-patch-1
7 years ago
Sergey G. Brester d9525ad3aa
Update ChangeLog
7 years ago
Luis Aranguren fc76ccf192 Fixes abuseipdb curl cypher error and comment $f2bV_matches
7 years ago
Sergey G. Brester 7bbc26d67e
Merge pull request #2097 from benrubson/sni
7 years ago
Sergey G. Brester 28ae32f0ca
Update ChangeLog
7 years ago
sebres 02bae2962d fixed test cases: www.epfl.ch seems to change again the static IP address, tests rewritten using dynamic mechanism (via resolver).
7 years ago
benrubson bd74f7ba8b Detect Apache SNI error / misredirect attempts, typos
7 years ago
sebres e786dbf132 New logging parameter `padding`, default enabled, excepting the SYSLOG (for backwards compatibility purposes);
7 years ago
sebres 8423f017e7 Merge branch 'sshd-ddos-mode-closed-preauth' into 0.10
7 years ago
Sergey G. Brester 4ee7af742a
Merge pull request #2090 from sebres/fix-sshd-filter-suff
7 years ago
sebres 4ee07adde6 Merge branch '0.10' into fix-sshd-filter-suff
7 years ago
sebres 50d7c649ba Skip several test-cases of systemd backend, if journal seems to be not available (e. g. no rights to read journal);
7 years ago
sebres fd0471927d badips: increase age for /list/cat in the test-cases (default 24h is too short, so the tests can sporadic fail)
7 years ago
sebres 4963295729 Merge remote-tracking branch 'remotes/gh-upstream/master' into 0.10
7 years ago
benrubson 30dc22fb2e Detect Apache SNI error / misredirect attempts
7 years ago
Sergey G. Brester 088192ea9f
Merge pull request #1960 from comradekingu/patch-1
7 years ago
Sergey G. Brester 9710c8c996
minor fix with reindent
7 years ago
sebres 218905c924 performance optimization: findFailure, search regex etc, handling with buffer/tuple-lines optimized (especially multi-regex resp. multi-lines filters)
7 years ago
Sergey G. Brester 67df796f93
Merge pull request #2088 from sebres/fix-gh-2073
7 years ago
sebres 79019967a7 datepattern: fix epoch/long-epoch name, if custom pattern specified
7 years ago
Sergey G. Brester 6dc9c23a25
fixed typo in pragma-comment
7 years ago
Sergey G. Brester 80725ae870
Update sshd
7 years ago
sebres e5735b9951 ChangeLog updated
7 years ago
sebres 4f6532f810 filter.d/sshd.conf: mode `ddos` (and `aggressive`) extended to catch `Connection closed by ... [preauth]`, so in DDOS mode it causes failure now on closed within preauth stage;
7 years ago
sebres cd7f1354c6 remove end-anchors for expressions that are precise enough (with clear flow, simple branches, without catch-all's, etc.)
7 years ago
sebres ed7d5d8ea1 ChangeLog updated
7 years ago
sebres c31eb1c562 quick optimization: normalizes pam-generic prefregex (more similar to the same regex within sshd-filter) + datepattern anchored now;
7 years ago
sebres 4129f940bb revert non-empty incremental multi-line failure merge (just simply overwrite method used ATM);
7 years ago
sebres 25cc42129a hold all user names affected by interim attempts in order to avoid forget a failures after success login:
7 years ago
sebres a9c94686b6 fixed multiple regexs matched
7 years ago
sebres 5603055a58 failregex: introduced capturing alternate groups, for example non-empty values of `alt_user_1`, `alt_user_2` will overwrite `user` if it is empty (or `alt_host` -> `host`, etc.)
7 years ago
sebres 8028d3940d amend with better match of optional suffix-groups;
7 years ago
sebres 66d2436f21 filter.d/sshd.conf: extend suffix with optional port, move it to `prefregex` at end outside of the content
7 years ago
sebres 7b3442c4e2 amend to 185cb998e7c7f2509830bed4a9f2fe6179f77e7b: capture error prefix outside of the failure content;
7 years ago
sebres 185cb998e7 make `prefregex` more precise in order to avoid catch the content for non failure lines
7 years ago
sebres 8763cf0a36 ChangeLog updated
7 years ago
sebres e8ffab28fb filter.d/apache-noscript.conf: extended to match "Primary script unknown", got from php-fpm module.
7 years ago
Sergey G. Brester 20fffc44c1
Merge pull request #2087 from sebres/fix-recidive-by-syslog
7 years ago
sebres a6fb33bdec filter.d/recidive.conf: fixed if logging into systemd-journal (SYSLOG) with daemon name in prefix, gh-2069
7 years ago
sebres 2e533a3a3a better handling of default date templates (bounds, replacement using own expressions `...{DATE}...`, etc.)
7 years ago
sebres ce6ca0029a minimize log output in trace case (index instead of full-regexp by "matched" log-line)
7 years ago
sebres a3739bbf27 trim name and add one space after padding
7 years ago