Commit Graph

1131 Commits (f61aa3225cea6814ba91e23d363d371a6cb2d0b3)

Author SHA1 Message Date
Yaroslav Halchenko 345820d2aa Merge pull request #1056 from ipoddubny/asterisk_security_log
10 years ago
Yaroslav Halchenko f41872f034 Merge pull request #1013 from szepeviktor/patch-4
10 years ago
Yaroslav Halchenko eb091d9b8c Merge remote-tracking branch 'origin/master' into pr-1039
10 years ago
Yaroslav Halchenko 8c4d4aa7fb minor: no tripple empty lines
10 years ago
Joern Muehlencord 4296d1a9a9 add froxlor-auth filter and jail
10 years ago
Joern Muehlencord 964cdb5d9b add froxlor-auth filter and jail
10 years ago
Ivan Poddubny 7a4e6fa6e5 Asterisk security log: add support for websocket protocol events
10 years ago
Ivan Poddubny 988d9a08da Asterisk security log: accept events containing Response/ExpectedResponse
10 years ago
Ivan Poddubny 189265a323 Asterisk security log: accept SessionID of PJSIP events
10 years ago
Ivan Poddubny ab2ac1a367 Asterisk security log: accept <unknown> in AccountID
10 years ago
Ivan Poddubny 977f9955e7 Asterisk security log: accept EventTV in ISO8601
10 years ago
Anton Shestakov 56e5821c06 Match unknown user in dovecot's passwd-file auth database
10 years ago
Aaron Brice 7ae0ef2408 Fix actions in ufw.conf
10 years ago
Lee Clemens 8f792f52fb Add drupal-auth filter and jail
10 years ago
Lee Clemens b530d88eca Merge remote-tracking branch 'upstream/master' into bf/1000-asteriskBlocksSelf
10 years ago
Markus Oesterle f8c7247f42 added \s after host
10 years ago
Markus Oesterle 5f2807b41f replaced .* before rhost with regex matching all the previous fields
10 years ago
Markus Oesterle 8825a5f31b updated filter.d/sshd.conf
10 years ago
Viktor Szépe e776a4e1ab Update proftpd.conf
10 years ago
Viktor Szépe f9e8a99a79 Non-US locale warning for proftpd
10 years ago
Thomas Mayer 923d807ef8 use human-readable variable names (issue #1003)
10 years ago
Thomas Mayer 675c3a7c95 use printf instead of echo for POSIX compatibility (issue #1003)
10 years ago
Thomas Mayer ac1e41ea70 Revert "remove '-ne' option as it's not interpreted any way (issue #1003)"
10 years ago
Thomas Mayer 4a598070c8 remove '-ne' option as it's not interpreted any way (issue #1003)
10 years ago
Thomas Mayer 80f11a4d28 Add empty Init Section to pass tests (issue #1003)
10 years ago
Thomas Mayer c9b24839e4 Character detection heuristics for whois output via optional setting in mail-whois*.conf (Closes #1003)
10 years ago
Csaba Tóth 0720c831b7 Fix of LC_TIME usage, it should be LC_ALL
10 years ago
Lee Clemens 72f4bcfbff Match hacking attempt IP instead of asterisk server IP (closes #1000)
10 years ago
Yaroslav Halchenko d28880fdca Merge pull request #997 from yarikoptic/bf/long-purge-for-recidive
10 years ago
ediazrod 5fdd1d1ded Update shorewall-ipset-proto6.conf
10 years ago
ediazrod e26a1ad6b6 Update shorewall-ipset-proto6.conf
10 years ago
Yaroslav Halchenko 56aacf872c Merge pull request #952 from ache/master
10 years ago
Yaroslav Halchenko 02836b599c Added a comment about systemd backend for jails with logs outside of journal (Closes #959)
10 years ago
Yaroslav Halchenko 320a28a4a4 DOC: make a warning for recidive jail to increase dbpurgeage (Closes #964)
10 years ago
ediazrod d0887f3234 This is a especific configuration for shorewall ipset proto6
10 years ago
Yaroslav Halchenko e788e3823e Merge pull request #965 from TorontoMedia/master
10 years ago
TorontoMedia b4f1f613bb Update firewallcmd-allports.conf
10 years ago
TorontoMedia 0fac7e40b6 Update firewallcmd-multiport.conf
10 years ago
Yaroslav Halchenko 07b0ab07ad Merge branch 'master' of https://github.com/rumple010/fail2ban
10 years ago
Yaroslav Halchenko d5e68abf95 ENH: check badips.com response on presence of "categories" in it
10 years ago
Ache ae1451b29f Update bsd-ipfw.conf
10 years ago
Yaroslav Halchenko 3fb2becddb Merge pull request #949 from leeclemens/enh/configSyslogSocket
10 years ago
Lee Clemens 6268eb32be Use syslogsocket value "auto" to determine syslog socket's path
10 years ago
Luke Hollins 549ab24e70 Fixed grammatical error in emails sent
10 years ago
Yaroslav Halchenko 119a7bbb16 Merge pull request #939 from szepeviktor/geoip
10 years ago
Viktor Szépe 4c88a00c28 Line notes implemented
10 years ago
Lee Clemens 445fd7367f Configure Syslog Socket Path
10 years ago
František Šumšal eb0d086ed0 Merge branch 'master' into nginx-botsearch
10 years ago
František Šumšal 1c6d2074fb Changed default settings for nginx-botseach filter
10 years ago
Orion Poplawski e7ff7e90b7 [postfix-sasl] update regexes
10 years ago
František Šumšal fb0f463eac Include consistency
10 years ago
František Šumšal 705718be52 Filter apache-botsearch.conf now loads variables from botsearch-common.conf
10 years ago
František Šumšal 18778d9174 Created botsearch-common.conf
10 years ago
Yaroslav Halchenko 73af02ffc6 Merge pull request #940 from leeclemens/ENH/ApacheFakeGoogleBot
10 years ago
Yaroslav Halchenko df581fe6e2 Merge pull request #929 from opoplawski/pam_auth
10 years ago
Yaroslav Halchenko 7ada96b4e9 Merge pull request #932 from opoplawski/dovecot
10 years ago
František Šumšal f8fe165cd2 Switched from tabs to spaces for indents
10 years ago
Yaroslav Halchenko 8f6d9c6a5a Merge branch 'enh/local_time_zone' of https://github.com/yarikoptic/fail2ban
10 years ago
Lee Clemens 841c476045 Merge branch 'enh/fakegooglebot' of https://github.com/yarikoptic/fail2ban into yarikoptic-enh/fakegooglebot
10 years ago
Yaroslav Halchenko 15b65c7ad2 NF: apache-fakegooglebot ignorecommand + DNSUtils.ipToName
10 years ago
Lee Clemens 7e94ba6f0c Remove implementation specific suffix
10 years ago
Lee Clemens 854915920f Remove implementation specific suffix
10 years ago
Lee Clemens af078532ac New jail: apache-fakegooglebot
10 years ago
Viktor Szépe 1619ab3145 Added sendmail-geoip-lines.conf
10 years ago
Yaroslav Halchenko ec6a30efcf ENH: define ignoreregex for all filters explicitly, to avoid warnings (Closes #934)
10 years ago
František Šumšal c8e82f18b6 Add jail nginx-botsearch
10 years ago
Orion Poplawski b4776a1ba0 Match dovecot unknown user line
10 years ago
Orion Poplawski 3bc92610f7 Add dovecot auth failure from EL7
10 years ago
Andrew St. Jean 6bdfe756cf Changed default TTL value to 60 seconds.
10 years ago
Orion Poplawski 79b5a2617f Add filter variable __pam_auth to allow easier changing of pam auth backend
10 years ago
Andrew St. Jean 43732acae1 Added a reminder to create an nsupdate.local file to set required options.
10 years ago
Yaroslav Halchenko 085d0f72ed ENH: use non-UTC date invocation (without -u) and report offset for localzone (%z)
10 years ago
Yaroslav Halchenko 65980a70fc Merge branch 'enh/recidive-allports' of https://github.com/yarikoptic/fail2ban
10 years ago
rumple010 eb76dcd5a0 add nsupdate action
10 years ago
sebres 12e3cca3f2 port[s] typo fixed in jail.conf/nginx-http-auth, issue gh-913
10 years ago
Yaroslav Halchenko 083031524d BF: adding missing Definition section header to firewallcmd-allports
10 years ago
TorontoMedia d7b7f4bc91 Update firewallcmd-allports.conf
10 years ago
Lee Clemens 77677e43df Merge branch 'master' of github.com:fail2ban/fail2ban into ENH/PostfixRBL
10 years ago
Lee Clemens bda8dc1926 Merge branch 'master' of github.com:fail2ban/fail2ban into ENH/PostfixRBL
10 years ago
TorontoMedia 7eed55266b Created firewallcmd-multiport
10 years ago
TorontoMedia 9f91cb2fd8 Created firewallcmd-allports
10 years ago
TorontoMedia 50e5fd9ed7 Create firewallcmd-multiport.conf
10 years ago
TorontoMedia 591e444753 Create firewallcmd-allports.conf
10 years ago
Lee Clemens 0f48cf4284 loosen up regex for spamhaus (spamcop says "Blocked" as part of url)
10 years ago
Lee Clemens fe72a5585c Create Jail for Postfix based on RBL
10 years ago
Lee Clemens 2d7429c47c Add 'Client host rejected error message' regex
10 years ago
Viktor Szépe 81b3dbde1d postfix-sasl failregex case insensitive
10 years ago
bes-internal ccc986b7d8 exim filter: correct failregex for exim with extended log options
10 years ago
Orion Poplawski d8867807f5 Separate php-url-fopen logpath by newline
10 years ago
Guillaume FRANCOIS a6a2dc868b Add ignoreregex to avoid warning on start
10 years ago
Guillaume FRANCOIS 9269664350 Add ignoreregex to avoid warning on start
10 years ago
Yaroslav Halchenko 2a3790f8e8 use iptables-allports for recidive
10 years ago
Yaroslav Halchenko 967485c2d0 improving grepping
10 years ago
Yaroslav Halchenko efbf5064a1 Merge pull request #807 from xslidian/patch-1
10 years ago
Orion Poplawski 01b2673e34 Use multiport for firewallcmd-new
10 years ago
Yaroslav Halchenko 36abb5ed96 BF: fix $ for % in jail.conf. Debian bug #767255
10 years ago
pacop e3a037ee3f merge master
10 years ago
pacop ce4f2d1c88 added filter for PortSentry with jail and samples
10 years ago
SlowRiot fc5f729f01 adding jail conf for shellshock filter
10 years ago
SlowRiot 4f636eb0e3 adding filter to detect Shellshock attack attempts against bash scripts through apache. See http://seclists.org/oss-sec/2014/q3/650
10 years ago
Nick Weeds 2c158fe168 Add apache filter for AH01630 client denied by server configuration
10 years ago
Yaroslav Halchenko 0e1f8f7f39 RF: remove those two additional failregexes for the postfix
10 years ago
Yaroslav Halchenko 96c20c8379 Merge pull request #804 from pleasantone/master
10 years ago
Yaroslav Halchenko c58c4de9bc ENH: add empty ignoreregex to avoid a warning (Close #805)
10 years ago
Dean Lee ba44ff312b grep IP at the start of lines
10 years ago
Paul Traina 249e169d8e Update test cases and also suport smtps per request.
10 years ago
Daniel Black 1864f75b3b Credits and notes from #806
10 years ago
weberho d2c086b187 fixed encoding
10 years ago
weberho 218ffe862e fixed encoding
10 years ago
Paul Traina 544cfaff2c Add support for postfix/submission/smtpd matching.
10 years ago
Yaroslav Halchenko 0d9cfb84e3 Merge pull request #778 from yarikoptic/enh/symbiosis
10 years ago
Yaroslav Halchenko 426ed7ff2f Merge pull request #780 from opoplawski/logpath
10 years ago
Yaroslav Halchenko 93243e7d57 ENH: Ignore errors while unbaning in symbiosis firewall
10 years ago
Luc Maisonobe 763115b1eb added systemd configuration for postfix-sasl.conf
10 years ago
Yaroslav Halchenko aee560b1c6 Merge branch 'master' of git://github.com/fail2ban/fail2ban
10 years ago
Yaroslav Halchenko 6fc04c2256 Merge branch 'bf+enh/cyrus-imap' of https://github.com/yarikoptic/fail2ban (with some tune up to Changelog entry)
10 years ago
Yaroslav Halchenko f403bad0ab Merge pull request #775 from alimony/patch-1
10 years ago
Yaroslav Halchenko b79a82ebdd minor typo
10 years ago
Orion Poplawski 6b554fbe98 Fxi jail.conf to use more syslog macros
10 years ago
Yaroslav Halchenko 818dd59d65 ENH: symbiosis-blacklist-allports action
10 years ago
Markus Amalthea Magnuson 7b76322898 Fix typos.
10 years ago
Yaroslav Halchenko 4a23a7dcf1 Merge pull request #766 from leftyfb/master
10 years ago
leftyfb 6dbd449f77 Changed to Cloudflare JSON API
10 years ago
Jisoo Park 2e7b8adb3b Fix sieve filter to use correct option
10 years ago
Yaroslav Halchenko f19c5fc939 Merge pull request #770 from eltrai/master
10 years ago
Yaroslav Halchenko f9cfbd66e6 Merge pull request #771 from szepeviktor/patch-1
10 years ago
Szépe Viktor 143a55bf26 Update courier-smtp.conf
10 years ago
Yaroslav Halchenko 2d7f2fa33f Merge pull request #756 from marclaporte/patch-1
10 years ago
Yaroslav Halchenko 45c1095606 Merge pull request #750 from niorg/master
10 years ago
Yaroslav Halchenko 3339dc8d84 ENH: cyrus-imap -- catch also 'user not found' attempts
10 years ago
Yaroslav Halchenko 3e5c598b79 BF: cyrus-imaps -- catch also for secured daemons
10 years ago
Szépe Viktor d757ef584f Update courier-smtp.conf
11 years ago
Szépe Viktor a786e8a29b named users + smtp atuh probes
11 years ago
Pierre-Alain Dupont 3d7504c19e Forwards bantime to action scripts
11 years ago
leftyfb cba570cabd Updated comments
11 years ago
leftyfb 5471e99ebe Added cloudflare action
11 years ago
Yaroslav Halchenko 6cddc65cee BF: path to exim's mainlog on Fedora (Thanks Frantisek Sumsal) + changelog entry
11 years ago
Yaroslav Halchenko 43950d8b7e BF: fix path to the exim log on Debian systems (/var/log/exim4)
11 years ago
Marc Laporte 3777591ab0 typo
11 years ago
Cyril Roos add8e61036 Added Directadmin filter, jail and log test
11 years ago
Yaroslav Halchenko 0adb10f653 Merge branch 'ainfo-copy' of https://github.com/kwirk/fail2ban
11 years ago
Steven Hiscocks 2d54161696 Merge branch 'kwirk/harmonize-log-msgs'
11 years ago
Steven Hiscocks 76a5633ff9 Merge pull request #739 from ranvis/enh-iptables-ipsets
11 years ago
SATO Kentaro 65ff3e9604 ENH: Introduce iptables-common.conf.
11 years ago
Steven Hiscocks 94232d7c31 Merge pull request #726 from pmarrapese/master
11 years ago
Steven Hiscocks 8268c1641f BF: aInfo could be modified by actions, causing unexpected behaviour
11 years ago
Yaroslav Halchenko 93d5c363ca Merge branch 'enh/oracle_msg_server'
11 years ago
SATO Kentaro 1e1c4ac62a ENH: Add <chain> to iptables-ipsets.
11 years ago
Yaroslav Halchenko 994fe77e59 ENH: make oracleims failregex better anchored (more explicit)
11 years ago
JoelSnyder 5165d2f6ea Update oracleims.conf to be 'less greedy'
11 years ago
JoelSnyder 70ed93d8cc Update jail.conf for oracleims filter.
11 years ago
Steven Hiscocks e8131475cd ENH: Realign and harmonise log messages with getF2BLogger helper
11 years ago
Steven Hiscocks db023be09b BF: Fix bad syntax in badips.py action
11 years ago
JoelSnyder 9b7c35810a Create oracleims.conf in filter.d for new filter
11 years ago
pmarrapese 96918acee4 more explicit match for sshd filter & added test
11 years ago
pmarrapese 46d6e93800 adjusted sshd filter regex to catch more verbose lines
11 years ago
Steven Hiscocks 77ba065571 Merge pull request #697 from jhmartin/monit_admin_hack
11 years ago
Steven Hiscocks bc10b64c69 ENH: Match non "Bye Bye" for sshd locked accounts failregex
11 years ago
Yaroslav Halchenko 596b819bdc DOC: minor -- tabify docstring in badips.py action
11 years ago
Jason Martin 9c3cb31862 Even stricter monit regex, now covers entire line
11 years ago
Jason Martin 72bfd14330 Tidy up filter.d/monit.conf, make regex more complete.
11 years ago
Steven Hiscocks 03d90c2f42 BF: recidive filter and samples at wrong log level: WARNING->NOTICE
11 years ago
Jason Martin 7d112430ca Block brute-force attempts against the Monit gui
11 years ago
Steven Hiscocks d4427e5a76 Merge pull request #683 from yarikoptic/fix/682
11 years ago
Steven Hiscocks 9fcb92524e BF: badips.py action logging of exc_info on debug typo
11 years ago
Yaroslav Halchenko 8bcb25c3a2 defining empty defaults for syslog_ log targets for common (Thanks @chtheis, partial fix to #682)
11 years ago
Yaroslav Halchenko 7dcea0d48d typos of paths-common (Thanks @chtheis, partial fix to #682)
11 years ago
Yaroslav Halchenko 5bccec61e4 ENH: adding pruned with previous merge trailing \s* in nginx filter
11 years ago
Yung-Chin Oei 941a38ea8e nginx-http-auth: match when "referrer" is present
11 years ago
shawn d7e888238c Correct grammar
11 years ago
yungchin 6e8c1b2871 nginx-http-auth filter: match server_name = ""
11 years ago
yungchin 3a155ed2e0 Update comments in shorewall.conf for new settings
11 years ago
Ruben Kerkhof 1c36da9df9 Fix 2 more typos that codespell didn't catch
11 years ago
Ruben Kerkhof 1695d5c076 Fix a few typos
11 years ago
Manuel Rüger 5a1ad75114 Fix typo in comment
11 years ago
Steven Hiscocks 41cbbbc248 BF: Remove unused imports and variables.
11 years ago
Steven Hiscocks 16125ec81a BF: badips.py action methods not static due to use of self._logSys
11 years ago
Steven Hiscocks 6c5a978d6f BF: journalmatch for recidive should be NOTICE level not WARNING
11 years ago
Daniel Black 7611096162 Merge branch '0.9' of https://github.com/fail2ban/fail2ban into 0.9
11 years ago
Daniel Black aa7e8fb9ce DOC: Credits. close gh-644
11 years ago
Steven Hiscocks 9e374b159e ENH: Allow setting of badips.py key for reporting and blacklisting
11 years ago
Steven Hiscocks de43d1d6d5 ENH: Change badips.py default score to "3"
11 years ago
Daniel Black 476d79d3cc ENH: asterisk filter to support syslog format
11 years ago
Daniel Black 415f187644 ENH: sendmail-reject for all smtp ports.
11 years ago
Steven Hiscocks a78a9d282c DOC: Document that badips.py action should be last action for jail
11 years ago
Steven Hiscocks 0222ff4677 Merge branch 'badips-blacklist' into 0.9
11 years ago
Steven Hiscocks 0c63d0061a DOC: Add documentation for badips.py action
11 years ago
Steven Hiscocks dfb46cfda6 BF: Require Python 2.7+ for badips.py action
11 years ago
Daniel Black df882feb16 ENH: expand sendmail-reject jail to 465,submission
11 years ago
Daniel Black ef29d7bd29 ENH: paths-{common,distro} normalisation
11 years ago
Daniel Black 50d938e0bf MRG: merge filter sendmail-spam into sendmail-reject
11 years ago
Daniel Black 666fd5eceb ENH: purge excessive jail variations
11 years ago
Daniel Black 69f5baae36 ENH: jail.conf to use syslog_mail
11 years ago
Daniel Black 2d45becb0e Merge branch '0.9' into distro-paths-gh-315
11 years ago
Daniel Black 2d8c497ce5 ENH: highlight missing osx paths
11 years ago
Daniel Black cc8ec826c5 MRG: from master 2014-03-02
11 years ago
Daniel Black 853bed8e4f ENH: more sendmail-reject filter items thanks to fab23
11 years ago
Daniel Black d0ec09a3b5 BF: move to right location
11 years ago
Daniel Black c10cc20928 ENH: rename sendmail-spam to sendmail-reject
11 years ago
Daniel Black d34569fb8d BF: email address as arg1 in sendmail filters
11 years ago