Pure-ftpd fail2ban

Dieses Thema im Forum "Server Administration" wurde erstellt von etron770, 13. Sep. 2013.

  1. etron770

    etron770 Member

    Hi zusammen,
    fail2ban arbeitet für mail, drupal, apache usw problemlos
    aber pure-ftpd versuche gehen problemlos durch ...
    jail.local
    Code:
    .....
    [pure-ftpd]
    enabled  = true
    port     = ftp
    filter   = pure-ftpd
    logpath  = /var/log/messages
    maxretry = 2
    ....
    
    Fail2ban startet mit
    Code:
    Creating new jail 'pure-ftpd'
    fail2ban.jail   : INFO   Jail 'pure-ftpd' uses poller
    fail2ban.filter : INFO   Added logfile = /var/log/messages
    fail2ban.filter : INFO   Set maxRetry = 2
    fail2ban.filter : INFO   Set findtime = 600
    fail2ban.actions: INFO   Set banTime = 600
    
    ein

    fail2ban-regex /var/log/messages /etc/fail2ban/filter.d/pure-ftpd.conf
    liefert
    Code:
    Use regex file : /etc/fail2ban/filter.d/pure-ftpd.conf
    Use log file   : /var/log/messages
    
    
    Results
    =======
    
    Failregex
    |- Regular expressions:
    |  [1] pure-ftpd(?:\[\d+\])?: \(.+?@<HOST>\) \[WARNING] Authentication failed for user \[.+\]\s*$
    
    |
    `- Number of matches:
       [1] 148 match(es)
    
    Ignoreregex
    |- Regular expressions:
    |
    `- Number of matches:
    
     
    Zuletzt bearbeitet: 19. Sep. 2013

Diese Seite empfehlen