main/fail2ban: adjust filter for openssh 9.8

This commit is contained in:
Lindsay Zhou 2024-07-18 09:22:54 +08:00 committed by Natanael Copa
parent 1dfa5d9f10
commit ef91ae27de
3 changed files with 8 additions and 8 deletions

View file

@ -3,7 +3,7 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=fail2ban
pkgver=1.1.0
pkgrel=0
pkgrel=1
pkgdesc="Scans log files for login failures then updates iptables to reject originating ip address"
url="https://www.fail2ban.org/"
arch="noarch"
@ -71,6 +71,6 @@ sha512sums="
1e7581dd04e7777d6fd5c40cc842a7ec5f4e6a0374673d020d89dd61bf4093d48934844bee89bcac9084f9ae44f3beb66e714cf3c2763d79c3e8feb790c5e43b fail2ban.confd
ee1c229db970239ebc707cd484a650fcf2347c70b411728ee2a4a35a72f4118cfccecf2a221275603320e0332efcc16e4979201933cec1aef1c5d5a082fc4940 fail2ban.logrotate
84915967ae1276f1e14a5813680ee2ebf081af1ff452a688ae5f9ac3363f4aff90e39f8e6456b5c33d5699917d28a16308797095fd1ef9bb1fbcb46d4cea3def alpine-ssh.jaild
4f982e26d3d066f40172607f20a30edc8a44222185413944584bde50c8ca11baaeedf341a67a7767355bccf88281a47ab80ac121297b2f059aba3d1c58bd567f alpine-sshd.filterd
36a81b771be0b36fe0dfb5ee4c72c9cb5b504e110618a8eb6f0f241b4e57d92df01dc5cc04b6b68d5bc6a5e6d68de1000092770285d7a328e5937e50b4b226a3 alpine-sshd-ddos.filterd
29f6d7c4da41ccfd92c425237c6fa69e7f195d04530da0cbe98e013a9ebd7512d638cccf08b39077effe82ac52695168f3390a13718b30c9ce923ad113444964 alpine-sshd.filterd
1b19318940852de590ad9b3b7e58ab98d71b686b91984aa7abc16c757cdab3a3a88a2707cdf9b1c008875e830f78b7e515a189c891963fa44626078aa00ca318 alpine-sshd-ddos.filterd
"

View file

@ -16,7 +16,7 @@ before = common.conf
[Definition]
_daemon = sshd
_daemon = sshd-session
failregex = Did not receive identification string from <HOST>\s*$

View file

@ -13,12 +13,12 @@ before = common.conf
[Definition]
_daemon = sshd
_daemon = sshd-session
failregex = Failed [-/\w]+ for .* from <HOST> port \d* ssh2
sshd\[.*\]: Invalid user .* from <HOST> port \d*
sshd\[.*\]: Received disconnect from <HOST> port \d*:[0-9]+: \[preauth\]
sshd\[.*\]: Disconnected from invalid user .* <HOST> port \d* \[preauth\]
sshd-session\[.*\]: Invalid user .* from <HOST> port \d*
sshd-session\[.*\]: Received disconnect from <HOST> port \d*:[0-9]+: \[preauth\]
sshd-session\[.*\]: Disconnected from invalid user .* <HOST> port \d* \[preauth\]
ignoreregex =