Hi zusammen,
fail2ban arbeitet für mail, drupal, apache usw problemlos
aber pure-ftpd versuche gehen problemlos durch ...
jail.local
Fail2ban startet mit
ein
fail2ban-regex /var/log/messages /etc/fail2ban/filter.d/pure-ftpd.conf
liefert
fail2ban arbeitet für mail, drupal, apache usw problemlos
aber pure-ftpd versuche gehen problemlos durch ...
jail.local
Code:
.....
[pure-ftpd]
enabled = true
port = ftp
filter = pure-ftpd
logpath = /var/log/messages
maxretry = 2
....
Code:
Creating new jail 'pure-ftpd'
fail2ban.jail : INFO Jail 'pure-ftpd' uses poller
fail2ban.filter : INFO Added logfile = /var/log/messages
fail2ban.filter : INFO Set maxRetry = 2
fail2ban.filter : INFO Set findtime = 600
fail2ban.actions: INFO Set banTime = 600
fail2ban-regex /var/log/messages /etc/fail2ban/filter.d/pure-ftpd.conf
liefert
Code:
Use regex file : /etc/fail2ban/filter.d/pure-ftpd.conf
Use log file : /var/log/messages
Results
=======
Failregex
|- Regular expressions:
| [1] pure-ftpd(?:\[\d+\])?: \(.+?@<HOST>\) \[WARNING] Authentication failed for user \[.+\]\s*$
|
`- Number of matches:
[1] 148 match(es)
Ignoreregex
|- Regular expressions:
|
`- Number of matches:
Zuletzt bearbeitet: