.. |
ignorecommands
|
filter.d/ignorecommands/apache-fakegooglebot: added timeout parameter (default 55 seconds) - avoid fail with timeout (default 1 minute) by reverse lookup on some slow DNS services (googlebots must be resolved fast);
|
4 years ago |
3proxy.conf
|
…
|
|
apache-auth.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
apache-badbots.conf
|
…
|
|
apache-botsearch.conf
|
…
|
|
apache-common.conf
|
filter.d/apache-common.conf: remote besides client, gh-3622
|
8 months ago |
apache-fakegooglebot.conf
|
filter.d/apache-fakegooglebot.conf: better, more precise regex and datepattern (closes possible weakness like #3013)
|
4 years ago |
apache-modsecurity.conf
|
…
|
|
apache-nohome.conf
|
…
|
|
apache-noscript.conf
|
filter.d/apache-noscript.conf: extended to match "script not found" with error AH02811 (and cgi-bin path segment in script)
|
4 years ago |
apache-overflows.conf
|
`filter.d/apache-overflows.conf` - consider AH10244: invalid URI path;
|
5 months ago |
apache-pass.conf
|
…
|
|
apache-shellshock.conf
|
…
|
|
assp.conf
|
…
|
|
asterisk.conf
|
Add transport to asterisk RE
|
4 years ago |
bitwarden.conf
|
review and small tweaks (more precise and safe RE)
|
4 years ago |
botsearch-common.conf
|
…
|
|
centreon.conf
|
…
|
|
common.conf
|
common.conf: fixed typo in comment (rfc5424 for logtype)
|
3 years ago |
counter-strike.conf
|
…
|
|
courier-auth.conf
|
filter.d/courier-auth.conf: consider optional port after IP, regex is rewritten without catch-all's and right anchor, so it is more stable against further modifications now;
|
3 years ago |
courier-smtp.conf
|
filter.d/courier-smtp.conf: prefregex extended to consider port in log-message (closes gh-2697)
|
5 years ago |
cyrus-imap.conf
|
…
|
|
dante.conf
|
IPv6 fix (second IP logged in form for IPv6); pam authentication failure (part of gh-3410)
|
11 months ago |
directadmin.conf
|
…
|
|
domino-smtp.conf
|
…
|
|
dovecot.conf
|
fixes gh-3370: resolve extremely long search by repeated apply of non-greedy RE `(?:: (?:[^\(]+|\w+\([^\)]*\))+)?` with following branches (it may be extremely slow up to infinite search depending on message); added new regression tests
|
2 years ago |
dropbear.conf
|
…
|
|
drupal-auth.conf
|
more precise RE (avoids weakness with catch-all's and is injection safe)
|
4 years ago |
ejabberd-auth.conf
|
…
|
|
exim-common.conf
|
bypass additional pid in prefix (may be logged by syslog-ng, gh-3060); matches protocol error with authentication mechanism not supported
|
8 months ago |
exim-spam.conf
|
`filter.d/exim.conf`:
|
8 months ago |
exim.conf
|
bypass additional pid in prefix (may be logged by syslog-ng, gh-3060); matches protocol error with authentication mechanism not supported
|
8 months ago |
freeswitch.conf
|
…
|
|
froxlor-auth.conf
|
…
|
|
gitlab.conf
|
New Gitlab jail
|
5 years ago |
grafana.conf
|
no catch-alls, user name and error message stored in ticket
|
4 years ago |
groupoffice.conf
|
…
|
|
gssftpd.conf
|
…
|
|
guacamole.conf
|
Enhance Guacamole jail
|
4 years ago |
haproxy-http-auth.conf
|
…
|
|
horde.conf
|
…
|
|
kerio.conf
|
…
|
|
lighttpd-auth.conf
|
filter.d/lighttpd-auth.conf: adjusted to the current source code + avoiding catch-all's, etc (gh-3116)
|
3 years ago |
mongodb-auth.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
monit.conf
|
filter.d/common.conf: closes gh-2650, avoid substitute of default values in related `lt_*` section, `__prefix_line` should be interpolated in definition section (after the config considers all sections that can overwrite it);
|
5 years ago |
monitorix.conf
|
more precise anchored RE (also combining all 3 REs in a single regex)
|
4 years ago |
mssql-auth.conf
|
precise regex (left anchor and fewer catch-all's); fixed tests (added failJSON and more tests for some corner-cases around new RE)
|
4 years ago |
murmur.conf
|
…
|
|
mysqld-auth.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
nagios.conf
|
…
|
|
named-refused.conf
|
loosening for denied suffix (would match no matter which reason in parenthesis);
|
8 months ago |
nginx-bad-request.conf
|
fix: add journalmatch to nginx filters
|
4 years ago |
nginx-botsearch.conf
|
fix: add journalmatch to nginx filters
|
4 years ago |
nginx-error-common.conf
|
more filters for nginx error-log supporting journal format now, added generalized include and __prefix_line
|
12 months ago |
nginx-forbidden.conf
|
more filters for nginx error-log supporting journal format now, added generalized include and __prefix_line
|
12 months ago |
nginx-http-auth.conf
|
more filters for nginx error-log supporting journal format now, added generalized include and __prefix_line
|
12 months ago |
nginx-limit-req.conf
|
more filters for nginx error-log supporting journal format now, added generalized include and __prefix_line
|
12 months ago |
nsd.conf
|
restore anchor (e. g. catch all in the middle), dot is optional now, RE rewritten a bit more precise
|
4 years ago |
openhab.conf
|
…
|
|
openwebmail.conf
|
…
|
|
oracleims.conf
|
…
|
|
pam-generic.conf
|
…
|
|
perdition.conf
|
…
|
|
php-url-fopen.conf
|
…
|
|
phpmyadmin-syslog.conf
|
typo
|
4 years ago |
portsentry.conf
|
…
|
|
postfix.conf
|
consider CONNECT and other rejected commands as a valid `_pref`;
|
4 months ago |
proftpd.conf
|
typo
|
4 years ago |
proxmox.conf
|
review (anchoring RE, etc)
|
4 months ago |
pure-ftpd.conf
|
…
|
|
qmail.conf
|
…
|
|
recidive.conf
|
`filter.d/recidive.conf` - restore possibility to set jail name in the filter, _jailname is positive now (but by default it uses now negative lookahead to exclude recidive jail);
|
5 months ago |
roundcube-auth.conf
|
Fixes unmatched tag (caused unmatched brace); review: combined to single regex, simple case without injection attempts faster, `<HOST>` replaced with `<ADDR>` (faster and fewer vulnerable on complex cases, since doesn't match text as hostname) etc.
|
3 months ago |
routeros-auth.conf
|
New filter: routeros-auth.conf (Closes #3469)
|
2 years ago |
scanlogd.conf
|
small amend: sport after saddr is optional
|
4 years ago |
screensharingd.conf
|
…
|
|
selinux-common.conf
|
small amend (non capturing group)
|
2 years ago |
selinux-ssh.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
sendmail-auth.conf
|
filter.d/sendmail-auth.conf: detect failures without user part
|
2 years ago |
sendmail-reject.conf
|
filter.d/sendmail-reject.conf: fix reverse DNS for ... (gh-3012)
|
4 years ago |
sieve.conf
|
…
|
|
slapd.conf
|
gh-3604: filter.d/slapd.conf - switched to single-line processing
|
1 year ago |
softethervpn.conf
|
small tweaks (both 2nd time and facility are optional, avoid catch-all, etc)
|
4 years ago |
sogo-auth.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
solid-pop3d.conf
|
…
|
|
squid.conf
|
…
|
|
squirrelmail.conf
|
…
|
|
sshd.conf
|
filter.d/sshd.conf: amend to #3747/#3812 (new ssh version would log with `_COMM=sshd-session`)
|
3 months ago |
stunnel.conf
|
…
|
|
suhosin.conf
|
…
|
|
tine20.conf
|
…
|
|
traefik-auth.conf
|
[DATALAD RUNCMD] run codespell throughout fixing typo automagically
|
1 year ago |
uwimap-auth.conf
|
…
|
|
vsftpd.conf
|
…
|
|
webmin-auth.conf
|
…
|
|
wuftpd.conf
|
…
|
|
xinetd-fail.conf
|
…
|
|
znc-adminlog.conf
|
…
|
|
zoneminder.conf
|
padding with space, prefregex, regex review (simplifying, capture user name, consider possible space char in user name)
|
4 years ago |