Pure-ftpd fail2ban

etron770

Member
Hi zusammen,
fail2ban arbeitet für mail, drupal, apache usw problemlos
aber pure-ftpd versuche gehen problemlos durch ...
jail.local
Code:
.....
[pure-ftpd]
enabled  = true
port     = ftp
filter   = pure-ftpd
logpath  = /var/log/messages
maxretry = 2
....
Fail2ban startet mit
Code:
Creating new jail 'pure-ftpd'
fail2ban.jail   : INFO   Jail 'pure-ftpd' uses poller
fail2ban.filter : INFO   Added logfile = /var/log/messages
fail2ban.filter : INFO   Set maxRetry = 2
fail2ban.filter : INFO   Set findtime = 600
fail2ban.actions: INFO   Set banTime = 600
ein

fail2ban-regex /var/log/messages /etc/fail2ban/filter.d/pure-ftpd.conf
liefert
Code:
Use regex file : /etc/fail2ban/filter.d/pure-ftpd.conf
Use log file   : /var/log/messages


Results
=======

Failregex
|- Regular expressions:
|  [1] pure-ftpd(?:\[\d+\])?: \(.+?@<HOST>\) \[WARNING] Authentication failed for user \[.+\]\s*$

|
`- Number of matches:
   [1] 148 match(es)

Ignoreregex
|- Regular expressions:
|
`- Number of matches:
 
Zuletzt bearbeitet:

Werbung

Top