Bug#669063: [fail2ban] enhancement of filter for openssh

April 16th, 2012 - 05:40 pm ET by Petr Voralek | Report spam
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)

Package: fail2ban
Version: 0.8.6-3
Severity: wishlist

Please enter the report below this line.

Hello!

I think it would be useful to add to sshd filter
(/etc/fail2ban/filter.d/sshd.conf) following failregex:

^%(__prefix_line)sUser .+ from <HOST> not allowed because listed in
DenyUsers$


For the case when you have defined DenyUsers in sshd_config. So, as I
do. It's just a thought...

System information.
Architecture: amd64
Kernel: Linux 3.2.0-2-amd64

Debian Release: wheezy/sid
990 testing www.debian-multimedia.org
990 testing security.debian.org
990 testing ftp.cz.debian.org
990 testing dl.google.com
990 testing deb.opera.com
500 testing-proposed-updates ftp.cz.debian.org
200 unstable www.debian-multimedia.org
200 unstable ftp.cz.debian.org
1 experimental ftp.cz.debian.org

Package information.
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.

Petr Voralek (JabberID: nazir@jabber.cz)

... Beware of low-flying butterflies.







To UNSUBSCRIBE, email to debian-bugs-dist-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
email Follow the discussionReplies 1 replyReplies Make a reply

Similar topics

Replies

#1 Yaroslav Halchenko
April 16th, 2012 - 05:50 pm ET | Report spam
good idea

would you mind submitting a pull request against
https://github.com/fail2ban/fail2ban
also with a sample log line added to
testcases/files/logs/sshd
?

then you would become in official chronicles of the project ;)



I think it would be useful to add to sshd filter
(/etc/fail2ban/filter.d/sshd.conf) following failregex:

^%(__prefix_line)sUser .+ from <HOST> not allowed because listed in
DenyUsers$




=Keep in touch www.onerussian.com
Yaroslav Halchenko www.ohloh.net/accounts/yarikoptic



To UNSUBSCRIBE, email to
with a subject of "unsubscribe". Trouble? Contact
email Follow the discussion Replies Reply to this message
Help Create a new topicReplies Make a reply
Search Make your own search