From 8ac6081555dd95574692e93c0c985a28582c6595 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 31 Oct 2013 01:23:00 +1100 Subject: [PATCH 001/125] ENH: fix to use upstream --remove-rules https://fedorahosted.org/firewalld/ticket/10 --- config/action.d/firewall-cmd-direct-new.conf | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) diff --git a/config/action.d/firewall-cmd-direct-new.conf b/config/action.d/firewall-cmd-direct-new.conf index ac06aa57..0f7388a2 100644 --- a/config/action.d/firewall-cmd-direct-new.conf +++ b/config/action.d/firewall-cmd-direct-new.conf @@ -15,15 +15,8 @@ actionstart = firewall-cmd --direct --add-chain ipv4 filter fail2ban- firewall-cmd --direct --add-rule ipv4 filter fail2ban- 1000 -j RETURN firewall-cmd --direct --add-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- -# The following rule does not work, because firewalld keeps its own database of firewall rules. -# firewall-cmd --direct --passthrough ipv4 -F fail2ban- -# The better rule would be the following, but firewall-cmd has not implemented this command with firewalld-0.3.3-2.fc19 . -# firewall-cmd --direct --flush-chain ipv4 filter fail2ban- -# The following is a workaround using a loop to implement the --flush-chain command. -# https://fedorahosted.org/firewalld/ticket/10 - actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- - ( IFS='|' ; for r in $( firewall-cmd --direct --get-rules ipv4 filter fail2ban- | tr '\n' '|' ) ; do eval firewall-cmd --direct --remove-rule ipv4 filter fail2ban- $r ; done ) + firewall-cmd --direct --remove-rules ipv4 filter fail2ban- firewall-cmd --direct --remove-chain ipv4 filter fail2ban- actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'fail2ban-[ \t]' From 5eddd5d12dbb7a4d82d74598df2c9efb548f2e12 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 31 Oct 2013 09:10:59 +1100 Subject: [PATCH 002/125] DOC: document required firewalld version as > 0.3.7.1 --- config/action.d/firewall-cmd-direct-new.conf | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/config/action.d/firewall-cmd-direct-new.conf b/config/action.d/firewall-cmd-direct-new.conf index 0f7388a2..3fd4e52b 100644 --- a/config/action.d/firewall-cmd-direct-new.conf +++ b/config/action.d/firewall-cmd-direct-new.conf @@ -3,7 +3,8 @@ # Author: Edgar Hoch # Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. # It uses "firewall-cmd" instead of "iptables". -# firewall-cmd is based on the command of version firewalld-0.3.4-1.fc19. +# +# Because of the --remove-rules in stop it requires a version AFTER (but not including) 0.3.7.1 [INCLUDES] From 87f68d7564ff375eda6c423b28ca09e3f53123ae Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 6 Nov 2013 11:37:56 +1100 Subject: [PATCH 003/125] firewalld-0.3.8 release that support --remove-rules out so documenting this. --- ChangeLog | 1 + config/action.d/firewall-cmd-direct-new.conf | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index f77d9491..623d998e 100644 --- a/ChangeLog +++ b/ChangeLog @@ -54,6 +54,7 @@ ver. 0.8.11 (2013/XX/XXX) - loves-unittests Edgar Hoch * action.d/firewall-cmd-direct-new.conf - action for firewalld from https://bugzilla.redhat.com/show_bug.cgi?id=979622 + NOTE: requires firewalld-0.3.8+ Andy Fragen and Daniel Black * filter.d/osx-ipfw.conf - ipfw action for OSX based on random rule numbers. diff --git a/config/action.d/firewall-cmd-direct-new.conf b/config/action.d/firewall-cmd-direct-new.conf index 3fd4e52b..55b6762d 100644 --- a/config/action.d/firewall-cmd-direct-new.conf +++ b/config/action.d/firewall-cmd-direct-new.conf @@ -4,7 +4,7 @@ # Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. # It uses "firewall-cmd" instead of "iptables". # -# Because of the --remove-rules in stop it requires a version AFTER (but not including) 0.3.7.1 +# Because of the --remove-rules in stop this action requires firewalld-0.3.8+ [INCLUDES] From d22214da798a9175bf0fec11fef1253534561baa Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 6 Nov 2013 12:03:19 +1100 Subject: [PATCH 004/125] Add Fedora git repo of fail2ban package to DEVELOP --- DEVELOP | 1 + 1 file changed, 1 insertion(+) diff --git a/DEVELOP b/DEVELOP index a8f8899f..bf0bb863 100644 --- a/DEVELOP +++ b/DEVELOP @@ -732,6 +732,7 @@ Which indicates that testcases/files/logs/mysqld.log has been moved or is a dire http://svnweb.freebsd.org/ports/head/security/py-fail2ban/Makefile?view=markup * Fedora: Axel Thimm https://apps.fedoraproject.org/packages/fail2ban + http://pkgs.fedoraproject.org/cgit/fail2ban.git * Gentoo: netmon@gentoo.org http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/net-analyzer/fail2ban/metadata.xml?view=markup * openSUSE: Stephan Kulow From 8b54523316022d2f4e017f353ad1892f06b6bd8e Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 6 Nov 2013 12:13:37 +1100 Subject: [PATCH 005/125] BF: fix to filter.d/wuftp to support pam authentication - Debian bug #665925 --- ChangeLog | 2 ++ config/filter.d/wuftpd.conf | 3 +++ testcases/files/logs/wuftpd | 2 ++ 3 files changed, 7 insertions(+) diff --git a/ChangeLog b/ChangeLog index 6497a731..4fcc7cd0 100644 --- a/ChangeLog +++ b/ChangeLog @@ -80,6 +80,8 @@ IMPORTANT incompatible changes: * filter.d/mysqld-auth.conf - mysql can use syslog * filter.d/sshd - regex enhancements to support openssh-6.3. Closes Debian bug #722970 + * filter.d/wuftpd - regex enhancements to support pam and wuftpd. Closes + Debian bug #665925 Rolf Fokkens * action.d/dshield.conf and complain.conf -- reorder mailx arguments. https://bugzilla.redhat.com/show_bug.cgi?id=998020 diff --git a/config/filter.d/wuftpd.conf b/config/filter.d/wuftpd.conf index 942de82a..45149f60 100644 --- a/config/filter.d/wuftpd.conf +++ b/config/filter.d/wuftpd.conf @@ -11,8 +11,11 @@ before = common.conf [Definition] _daemon = wu-ftpd +__pam_re=\(?pam_unix(?:\(wu-ftpd:auth\))?\)?:? failregex = ^%(__prefix_line)sfailed login from \S+ \[\]\s*$ + ^%(__prefix_line)s%(__pam_re)s\s+authentication failure; logname=\S* uid=\S* euid=\S* tty=(ftp)? ruser=\S* rhost=(?:\s+user=.*)?\s*$ + ignoreregex = diff --git a/testcases/files/logs/wuftpd b/testcases/files/logs/wuftpd index bbb816cc..948e848f 100644 --- a/testcases/files/logs/wuftpd +++ b/testcases/files/logs/wuftpd @@ -3,3 +3,5 @@ Oct 6 09:59:26 myserver wu-ftpd[18760]: failed login from hj-145-173-a8.bta.net.cn [202.108.145.173] # failJSON: { "time": "2004-10-11T16:45:07", "match": true , "host": "198.51.100.71" } Oct 11 16:45:07 ubuntu wu-ftpd[2360]: failed login from example.com [198.51.100.71] +# failJSON: { "time": "2005-03-22T09:35:02", "match": true , "host": "198.51.100.71" } +Mar 22 09:35:02 SiD wu-ftpd[31278]: pam_unix(wu-ftpd:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=198.51.100.71 user=root From e55b24c533d105cb284c414a2df34b7b48eb3680 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 6 Nov 2013 12:51:21 +1100 Subject: [PATCH 006/125] BF: fix dovecot filter for newer failure message. Closes Debian bug #709324 --- ChangeLog | 2 ++ config/filter.d/dovecot.conf | 2 +- testcases/files/logs/dovecot | 3 +++ 3 files changed, 6 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 6497a731..9cacd141 100644 --- a/ChangeLog +++ b/ChangeLog @@ -66,6 +66,8 @@ IMPORTANT incompatible changes: closes gh-266. hostsdeny supports daemon_list now too. * action.d/bsd-ipfw - action option unsed. Change blocktype to port unreach instead of deny for consistancy. + * filter.d/dovecot - added to support different dovecot failure + "..disallowed plaintext auth". Closes Debian bug #709324 * filter.d/roundcube-auth - timezone offset can be positive or negative * action.d/bsd-ipfw - action option unsed. Fixed to blocktype for consistency. default to port unreach instead of deny diff --git a/config/filter.d/dovecot.conf b/config/filter.d/dovecot.conf index 2caa04b3..a51ce259 100644 --- a/config/filter.d/dovecot.conf +++ b/config/filter.d/dovecot.conf @@ -10,7 +10,7 @@ before = common.conf _daemon = (auth|dovecot(-auth)?|auth-worker) failregex = ^%(__prefix_line)s(pam_unix(\(dovecot:auth\))?:)?\s+authentication failure; logname=\S* uid=\S* euid=\S* tty=dovecot ruser=\S* rhost=(\s+user=\S*)?\s*$ - ^%(__prefix_line)s(pop3|imap)-login: (Info: )?(Aborted login|Disconnected)(: Inactivity)? \(((no auth attempts|auth failed, \d+ attempts)( in \d+ secs)?|tried to use disabled \S+ auth)\):( user=<\S*>,)?( method=\S+,)? rip=, lip=(\d{1,3}\.){3}\d{1,3}(, session=<\w+>)?(, TLS( handshaking)?(: Disconnected)?)?\s*$ + ^%(__prefix_line)s(pop3|imap)-login: (Info: )?(Aborted login|Disconnected)(: Inactivity)? \(((no auth attempts|auth failed, \d+ attempts)( in \d+ secs)?|tried to use (disabled|disallowed) \S+ auth)\):( user=<\S*>,)?( method=\S+,)? rip=, lip=(\d{1,3}\.){3}\d{1,3}(, session=<\w+>)?(, TLS( handshaking)?(: Disconnected)?)?\s*$ ^%(__prefix_line)s(Info|dovecot: auth\(default\)): pam\(\S+,\): pam_authenticate\(\) failed: (User not known to the underlying authentication module: \d+ Time\(s\)|Authentication failure \(password mismatch\?\))\s*$ ignoreregex = diff --git a/testcases/files/logs/dovecot b/testcases/files/logs/dovecot index d2aa59ca..aa79e65a 100644 --- a/testcases/files/logs/dovecot +++ b/testcases/files/logs/dovecot @@ -12,6 +12,9 @@ # failJSON: { "time": "2004-12-12T11:19:11", "match": true , "host": "190.210.136.21" } Dec 12 11:19:11 dunnart dovecot: pop3-login: Aborted login (tried to use disabled plaintext auth): rip=190.210.136.21, lip=113.212.99.193 +# failJSON: { "time": "2004-12-12T11:19:11", "match": true , "host": "190.210.136.21" } +Dec 12 11:19:11 dunnart dovecot: pop3-login: Aborted login (tried to use disallowed plaintext auth): rip=190.210.136.21, lip=113.212.99.193, session= + # failJSON: { "time": "2005-06-13T16:30:54", "match": true , "host": "49.176.98.87" } Jun 13 16:30:54 platypus dovecot: imap-login: Disconnected (auth failed, 2 attempts): user=, method=PLAIN, rip=49.176.98.87, lip=113.212.99.194, TLS # failJSON: { "time": "2005-06-14T00:48:21", "match": true , "host": "59.167.242.100" } From 5ebc38683355fbaf3137b8053b29fd74d513e22a Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 6 Nov 2013 13:35:04 +1100 Subject: [PATCH 007/125] DOC: few more links for DEVELOP --- DEVELOP | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/DEVELOP b/DEVELOP index bf0bb863..9a3be94b 100644 --- a/DEVELOP +++ b/DEVELOP @@ -730,15 +730,20 @@ Which indicates that testcases/files/logs/mysqld.log has been moved or is a dire http://packages.qa.debian.org/f/fail2ban.html * FreeBSD: Christoph Theis theis@gmx.at>, Nick Hilliard http://svnweb.freebsd.org/ports/head/security/py-fail2ban/Makefile?view=markup + http://www.freebsd.org/cgi/query-pr-summary.cgi?text=fail2ban * Fedora: Axel Thimm https://apps.fedoraproject.org/packages/fail2ban http://pkgs.fedoraproject.org/cgit/fail2ban.git + https://admin.fedoraproject.org/pkgdb/acls/bugs/fail2ban * Gentoo: netmon@gentoo.org http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/net-analyzer/fail2ban/metadata.xml?view=markup + https://bugs.gentoo.org/buglist.cgi?quicksearch=fail2ban * openSUSE: Stephan Kulow - https://build.opensuse.org/package/users?package=fail2ban&project=openSUSE%3AFactory + https://build.opensuse.org/package/show/openSUSE:Factory/fail2ban * Mac Ports: @Malbrouck on github (gh-49) https://trac.macports.org/browser/trunk/dports/security/fail2ban/Portfile + * Mageia: + https://bugs.mageia.org/buglist.cgi?quicksearch=fail2ban An potentially to the fail2ban-users directory. # Wait for feedback from distributors From f26fba9c19bdf319d8750f2c04e71b28edc29d79 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Wed, 6 Nov 2013 13:47:45 -0500 Subject: [PATCH 008/125] DOC: Untabifying and reindenting a bit ChangeLog --- ChangeLog | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/ChangeLog b/ChangeLog index 4f69b4a1..87944c76 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,7 +4,7 @@ |_| \__,_|_|_/___|_.__/\__,_|_||_| ================================================================================ -Fail2Ban (version 0.8.11.pre1) 2013/10/30 +Fail2Ban (version 0.8.11.pre1) 2013/10/30 ================================================================================ ver. 0.8.11 (2013/11/XXX) - loves-unittests and tight, DoS free, filter regexes @@ -27,12 +27,12 @@ possibility that we have inadvertently, despite our best intentions, incorrectly allowed a failure to continue. We will fix this as quickly as humanly possible. -IMPORTANT incompatible changes: - Filter name changes: - * 'lighttpd-fastcgi' filter has been renamed to 'suhosin' - * 'sasl' has been renamed to 'postfix-sasl' - These will require changing in jail.{conf,local} if using these filters. - Exim filter has been split into an spam and a relay/auth filter. +- IMPORTANT incompatible changes: + Filter name changes: + * 'lighttpd-fastcgi' filter has been renamed to 'suhosin' + * 'sasl' has been renamed to 'postfix-sasl' + These will require changing in jail.{conf,local} if using these filters. + Exim filter has been split into an spam and a relay/auth filter. - Fixes: Daniel Black & Marcel Dopita @@ -110,7 +110,7 @@ IMPORTANT incompatible changes: Daniel Black & ykimon * filter.d/3proxy.conf -- filter added * fail2ban-regex - now generates http://www.debuggex.com urls for debugging - regular expressions with the -D parameter. + regular expressions with the -D parameter. Daniel Black * filter.d/exim-spam.conf -- a splitout of exim's spam regexes with additions for greater control over filtering spam. @@ -131,8 +131,8 @@ IMPORTANT incompatible changes: * reorder parsing of jail.conf, jail.d/*.conf, jail.local, jail.d/*.local and likewise for fail2ban.{conf|local|d/*.conf|d/*.local}. Closes gh-392 * jail.conf now has asterisk jail - no need for asterisk-tcp and - asterisk-udp. Users should replace existing jails with asterisk to - reduce duplicate parsing of the asterisk log file. + asterisk-udp. Users should replace existing jails with asterisk to + reduce duplicate parsing of the asterisk log file. * filter.d/{suhosin,pam-generic,gssftpd,sogo-auth,webmin}- regex anchor at start * filter.d/vsftpd - anchored regex at start. disable old pam format regex From 28ee7ba12303faf1d6c81c60506d79a090099bae Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Wed, 6 Nov 2013 14:04:30 -0500 Subject: [PATCH 009/125] DOC: keeping Changelog release-phrases uniform, simplified intro, unified --- ChangeLog | 41 +++++++++++++++++++---------------------- 1 file changed, 19 insertions(+), 22 deletions(-) diff --git a/ChangeLog b/ChangeLog index 87944c76..fc001187 100644 --- a/ChangeLog +++ b/ChangeLog @@ -7,36 +7,33 @@ Fail2Ban (version 0.8.11.pre1) 2013/10/30 ================================================================================ -ver. 0.8.11 (2013/11/XXX) - loves-unittests and tight, DoS free, filter regexes +ver. 0.8.11 (2013/11/XXX) - loves-unittests-and-tight-DoS-free-filter-regexes ----------- -In light of CVE-2013-2178 that triggered our last release we have put a -significant effort into tightening all of the regexs of our filters to avoid -another similar vulnerability. All filters have been updated and some to -include more failure regexs supporting previously unbanned failures and -support for newer application versions too. There are test cases for most log +In light of CVE-2013-2178 that triggered our last release we have put +a significant effort into tightening all of the regexs of our filters +to avoid another similar vulnerability. All filters have been updated +and some to catch more login/authentication failures and to support +for newer application versions. There are test cases for most log cases of failures now. -As usual if you have other examples that demonstrate that a filter is -insufficient please give us an example log line on the github issue tracker -http://github.com/fail2ban/fail2ban/issues and NOT on a random blog in some -obscure corner of the Internet. - -During the tightening of the regexs to avoid DoS vulnerabilities there is the -possibility that we have inadvertently, despite our best intentions, -incorrectly allowed a failure to continue. We will fix this as quickly as -humanly possible. +As usual, if you have other examples that demonstrate that a filter is +insufficient, or if we have inadvertently introduced a regression, +please provide us with example log lines on the github issue tracker +http://github.com/fail2ban/fail2ban/issues and NOT on a random blog in +some obscure corner of the Internet. - IMPORTANT incompatible changes: Filter name changes: * 'lighttpd-fastcgi' filter has been renamed to 'suhosin' * 'sasl' has been renamed to 'postfix-sasl' - These will require changing in jail.{conf,local} if using these filters. - Exim filter has been split into an spam and a relay/auth filter. + * 'exim' spam catching failregexes was split out into 'exim-spam' + These changes will require changing jail.{conf,local} if any of + those filters were used. - Fixes: Daniel Black & Marcel Dopita - * filter.d/apache-auth -- fixed and apache auth samples provide. closes #286 + * filter.d/apache-auth -- fixed and apache auth samples provide. Closes gh-286 Yaroslav Halchenko * filter.d/common.conf -- make colon after [daemon] optional. Closes gh-267 * filter.d/apache-common.conf -- support apache 2.4 more detailed error @@ -62,8 +59,8 @@ humanly possible. * filter.d/asterisk -- more regexes Daniel Black * action.d/hostsdeny -- NOTE: new dependancy 'ed'. Switched to use 'ed' across - all platforms to ensure permissions are the same before and after a ban - - closes gh-266. hostsdeny supports daemon_list now too. + all platforms to ensure permissions are the same before and after a ban. + Closes gh-266. hostsdeny supports daemon_list now too. * action.d/bsd-ipfw - action option unsed. Change blocktype to port unreach instead of deny for consistancy. * filter.d/dovecot - added to support different dovecot failure @@ -89,7 +86,7 @@ humanly possible. https://bugzilla.redhat.com/show_bug.cgi?id=998020 John Doe (ache) * action.d/bsd-ipfw.conf - invert actionstop logic to make exist status 0. - closes gh-343. + Closes gh-343. JP Espinosa (Reviewed by O.Poplawski) * files/redhat-initd - rewritten to use stock init.d functions thus avoiding problems with getpid. Also $network and iptables moved @@ -163,7 +160,7 @@ humanly possible. * filter.d/{courier{login,smtp},proftpd,sieve,wuftpd,xinetd} - General regex impovements Zurd - * filter.d/postfix - add filter for VRFY failures. closes gh-322. + * filter.d/postfix - add filter for VRFY failures. Closes gh-322. Orion Poplawski * fail2ban.d/ and jail.d/ directories are added to etc/fail2ban to facilitate their use From 6f321068f1c92a338aa08dfaa12db83a2ba475dd Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Thu, 7 Nov 2013 14:25:57 -0800 Subject: [PATCH 010/125] NF: gen_badbots script to (re)generate/update config/filter.d/apache-badbots.conf --- files/gen_badbots | 75 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 75 insertions(+) create mode 100755 files/gen_badbots diff --git a/files/gen_badbots b/files/gen_badbots new file mode 100755 index 00000000..278058f7 --- /dev/null +++ b/files/gen_badbots @@ -0,0 +1,75 @@ +#!/bin/bash +#-------------------------- =+- Shell script -+= -------------------------- +# +# Yaroslav Halchenko CS@UNM, CS@NJIT +# web: http://www.onerussian.com & PSYCH@RUTGERS +# e-mail: yoh@onerussian.com ICQ#: 60653192 +# +# DESCRIPTION (NOTES): +# +# Script to fetch list of agent strings from http://www.user-agents.org +# which are known to be from mailicious bots, and create apache-badbots.conf +# filter for fail2ban +# +# COPYRIGHT: Yaroslav Halchenko 2007-2013 +# +# LICENSE: +# +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program; if not, write to the +# Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, +# MA 02110-1301, USA. +# +# On Debian system see /usr/share/common-licenses/GPL for the full license. +# +#-----------------\____________________________________/------------------ + +url=http://www.user-agents.org/index.shtml +badbots=$( +for f in "" "?g_m" "?moz" "?n_s" "?t_z"; do + wget -q -O- $url$f; +done \ +| grep -h -B4 'S '\ +| sed -e 's/ //g' \ +| awk '/^--/{getline; gsub(" ",""); print $0}' \ +| sed -e 's/\([.\:|()]\)/\\\1/g' \ +| uniq \ +| tr '\n' '|' \ +| sed -e 's/|$//g' +) + +echo $badbots >| /tmp/badbots.tmp + +cat >| config/filter.d/apache-badbots.conf < -.*"(GET|POST).*HTTP.*"(?:%(badbots)s|%(badbotscustom)s)"$ + +ignoreregex = + +# DEV Notes: +# List of bad bots fetched from http://www.user-agents.org +# Generated on `date` by $0. +# +# Author: Yaroslav Halchenko +EOF From 452230835411fcc86624aa0096fbb74c69be33d6 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Thu, 7 Nov 2013 14:26:18 -0800 Subject: [PATCH 011/125] ENH: regenerated config/filter.d/apache-badbots.conf --- config/filter.d/apache-badbots.conf | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/config/filter.d/apache-badbots.conf b/config/filter.d/apache-badbots.conf index 9ee44c69..b2ac9626 100644 --- a/config/filter.d/apache-badbots.conf +++ b/config/filter.d/apache-badbots.conf @@ -3,12 +3,12 @@ # Regexp to catch known spambots and software alike. Please verify # that it is your intent to block IPs which were driven by # above mentioned bots. - + [Definition] badbotscustom = EmailCollector|WebEMailExtrac|TrackBack/1\.02|sogou music spider -badbots = atSpider/1\.0|autoemailspider|China Local Browse 2\.6|ContentSmartz|DataCha0s/2\.0|DBrowse 1\.4b|DBrowse 1\.4d|Demo Bot DOT 16b|Demo Bot Z 16b|DSurf15a 01|DSurf15a 71|DSurf15a 81|DSurf15a VA|EBrowse 1\.4b|Educate Search VxB|EmailSiphon|EmailWolf 1\.00|ESurf15a 15|ExtractorPro|Franklin Locator 1\.8|FSurf15a 01|Full Web Bot 0416B|Full Web Bot 0516B|Full Web Bot 2816B|Industry Program 1\.0\.x|ISC Systems iRc Search 2\.1|IUPUI Research Bot v 1\.9a|LARBIN-EXPERIMENTAL \(efp@gmx\.net\)|LetsCrawl\.com/1\.0 +http\://letscrawl\.com/|Lincoln State Web Browser|LWP\:\:Simple/5\.803|Mac Finder 1\.0\.xx|MFC Foundation Class Library 4\.0|Microsoft URL Control - 6\.00\.8xxx|Missauga Locate 1\.0\.0|Missigua Locator 1\.9|Missouri College Browse|Mizzu Labs 2\.2|Mo College 1\.9|Mozilla/2\.0 \(compatible; NEWT ActiveX; Win32\)|Mozilla/3\.0 \(compatible; Indy Library\)|Mozilla/4\.0 \(compatible; Advanced Email Extractor v2\.xx\)|Mozilla/4\.0 \(compatible; Iplexx Spider/1\.0 http\://www\.iplexx\.at\)|Mozilla/4\.0 \(compatible; MSIE 5\.0; Windows NT; DigExt; DTS Agent|Mozilla/4\.0 efp@gmx\.net|Mozilla/5\.0 \(Version\: xxxx Type\:xx\)|MVAClient|NASA Search 1\.0|Nsauditor/1\.x|PBrowse 1\.4b|PEval 1\.4b|Poirot|Port Huron Labs|Production Bot 0116B|Production Bot 2016B|Production Bot DOT 3016B|Program Shareware 1\.0\.2|PSurf15a 11|PSurf15a 51|PSurf15a VA|psycheclone|RSurf15a 41|RSurf15a 51|RSurf15a 81|searchbot admin@google\.com|sogou spider|sohu agent|SSurf15a 11 |TSurf15a 11|Under the Rainbow 2\.2|User-Agent\: Mozilla/4\.0 \(compatible; MSIE 6\.0; Windows NT 5\.1\)|WebVulnCrawl\.blogspot\.com/1\.0 libwww-perl/5\.803|Wells Search II|WEP Search 00 +badbots = Atomic_Email_Hunter/4\.0|atSpider/1\.0|autoemailspider|bwh3_user_agent|China Local Browse 2\.6|ContactBot/0\.2|ContentSmartz|DataCha0s/2\.0|DBrowse 1\.4b|DBrowse 1\.4d|Demo Bot DOT 16b|Demo Bot Z 16b|DSurf15a 01|DSurf15a 71|DSurf15a 81|DSurf15a VA|EBrowse 1\.4b|Educate Search VxB|EmailSiphon|EmailSpider|EmailWolf 1\.00|ESurf15a 15|ExtractorPro|Franklin Locator 1\.8|FSurf15a 01|Full Web Bot 0416B|Full Web Bot 0516B|Full Web Bot 2816B|Guestbook Auto Submitter|Industry Program 1\.0\.x|ISC Systems iRc Search 2\.1|IUPUI Research Bot v 1\.9a|LARBIN-EXPERIMENTAL \(efp@gmx\.net\)|LetsCrawl\.com/1\.0 +http\://letscrawl\.com/|Lincoln State Web Browser|LMQueueBot/0\.2|LWP\:\:Simple/5\.803|Mac Finder 1\.0\.xx|MFC Foundation Class Library 4\.0|Microsoft URL Control - 6\.00\.8xxx|Missauga Locate 1\.0\.0|Missigua Locator 1\.9|Missouri College Browse|Mizzu Labs 2\.2|Mo College 1\.9|MVAClient|Mozilla/2\.0 \(compatible; NEWT ActiveX; Win32\)|Mozilla/3\.0 \(compatible; Indy Library\)|Mozilla/3\.0 \(compatible; scan4mail \(advanced version\) http\://www\.peterspages\.net/?scan4mail\)|Mozilla/4\.0 \(compatible; Advanced Email Extractor v2\.xx\)|Mozilla/4\.0 \(compatible; Iplexx Spider/1\.0 http\://www\.iplexx\.at\)|Mozilla/4\.0 \(compatible; MSIE 5\.0; Windows NT; DigExt; DTS Agent|Mozilla/4\.0 efp@gmx\.net|Mozilla/5\.0 \(Version\: xxxx Type\:xx\)|NameOfAgent \(CMS Spider\)|NASA Search 1\.0|Nsauditor/1\.x|PBrowse 1\.4b|PEval 1\.4b|Poirot|Port Huron Labs|Production Bot 0116B|Production Bot 2016B|Production Bot DOT 3016B|Program Shareware 1\.0\.2|PSurf15a 11|PSurf15a 51|PSurf15a VA|psycheclone|RSurf15a 41|RSurf15a 51|RSurf15a 81|searchbot admin@google\.com|ShablastBot 1\.0|snap\.com beta crawler v0|Snapbot/1\.0|Snapbot/1\.0 \(Snap Shots, +http\://www\.snap\.com\)|sogou develop spider|Sogou Orion spider/3\.0\(+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sogou spider|Sogou web spider/3\.0\(+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sohu agent|SSurf15a 11 |TSurf15a 11|Under the Rainbow 2\.2|User-Agent\: Mozilla/4\.0 \(compatible; MSIE 6\.0; Windows NT 5\.1\)|VadixBot|WebVulnCrawl\.unknown/1\.0 libwww-perl/5\.803|Wells Search II|WEP Search 00 failregex = ^ -.*"(GET|POST).*HTTP.*"(?:%(badbots)s|%(badbotscustom)s)"$ @@ -16,6 +16,6 @@ ignoreregex = # DEV Notes: # List of bad bots fetched from http://www.user-agents.org -# Generated on Sun Feb 11 01:09:15 EST 2007 by ./badbots.sh +# Generated on Thu Nov 7 14:23:35 PST 2013 by files/gen_badbots. # # Author: Yaroslav Halchenko From a148d35d705b84fd97f3c2e00d28483f2eb4b92c Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 8 Nov 2013 10:06:40 +1100 Subject: [PATCH 012/125] ENH: add filter.d/nginx-http-auth. Partially forfills #405 --- ChangeLog | 2 ++ THANKS | 1 + config/filter.d/nginx-http-auth.conf | 15 +++++++++++++++ config/jail.conf | 7 +++++++ testcases/files/logs/nginx-http-auth | 6 ++++++ 5 files changed, 31 insertions(+) create mode 100644 config/filter.d/nginx-http-auth.conf create mode 100644 testcases/files/logs/nginx-http-auth diff --git a/ChangeLog b/ChangeLog index fc001187..813213ed 100644 --- a/ChangeLog +++ b/ChangeLog @@ -112,6 +112,8 @@ some obscure corner of the Internet. * filter.d/exim-spam.conf -- a splitout of exim's spam regexes with additions for greater control over filtering spam. * add date expression for apache-2.4 - milliseconds + * filter.d/nginx-http-auth -- filter added for http basic authentication + failures in nginx. Partially forfills gh-405. Christophe Carles & Daniel Black * filter.d/perdition.conf -- filter added Mark McKinstry diff --git a/THANKS b/THANKS index e70ca9c9..5f6d1b2b 100644 --- a/THANKS +++ b/THANKS @@ -54,6 +54,7 @@ Michael Hanselmann Nick Munger Patrick Börjesson Raphaël Marichez +RealRancor René Berber Robert Edeker Rolf Fokkens diff --git a/config/filter.d/nginx-http-auth.conf b/config/filter.d/nginx-http-auth.conf new file mode 100644 index 00000000..00f152b7 --- /dev/null +++ b/config/filter.d/nginx-http-auth.conf @@ -0,0 +1,15 @@ +# fail2ban filter configuration for nginx + + +[Definition] + + +failregex = ^ \[error\] \d+#\d+: \*\d+ user "\S+":? (password mismatch|was not found in ".*"), client: , server: \S+, request: "\S+ \S+ HTTP/\d+\.\d+", host: "\S+" + +ignoreregex = + +# DEV NOTES: +# Based on samples in https://github.com/fail2ban/fail2ban/pull/43/files +# Extensive search of all nginx auth failures not done yet. +# +# Author: Daniel Black diff --git a/config/jail.conf b/config/jail.conf index 23e30c83..4bda3c4a 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -181,6 +181,13 @@ logpath = /var/log/apache*/*error.log maxretry = 6 +[nginx-http-auth] + +enabled = false +filter = nginx-http-auth +logpath = /var/log/nginx/error.log + + # The hosts.deny path can be defined with the "file" argument if it is # not in /etc. [postfix-tcpwrapper] diff --git a/testcases/files/logs/nginx-http-auth b/testcases/files/logs/nginx-http-auth new file mode 100644 index 00000000..0fa7a7bd --- /dev/null +++ b/testcases/files/logs/nginx-http-auth @@ -0,0 +1,6 @@ + +# failJSON: { "time": "2012-04-09T11:53:29", "match": true , "host": "192.0.43.10" } +2012/04/09 11:53:29 [error] 2865#0: *66647 user "xyz" was not found in "/var/www/.htpasswd", client: 192.0.43.10, server: www.myhost.com, request: "GET / HTTP/1.1", host: "www.myhost.com" +# failJSON: { "time": "2012-04-09T11:53:36", "match": true , "host": "192.0.43.10" } +2012/04/09 11:53:36 [error] 2865#0: *66647 user "xyz": password mismatch, client: 192.0.43.10, server: www.myhost.com, request: "GET / HTTP/1.1", host: "www.myhost.com" + From ab9d921162038a22cbea48611c63b6e42f3a8b17 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 8 Nov 2013 10:09:19 +1100 Subject: [PATCH 013/125] BF: missed action in nginx-http-auth --- config/jail.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/config/jail.conf b/config/jail.conf index 4bda3c4a..486ea078 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -185,6 +185,7 @@ maxretry = 6 enabled = false filter = nginx-http-auth +action = iptables-multiport[name=nginx-http-auth,port="80,443"] logpath = /var/log/nginx/error.log From d7560d4041e90d99fd306ad5fb8d5d89424e45e0 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 8 Nov 2013 10:24:50 +1100 Subject: [PATCH 014/125] ENH: condense asterisk regexs for speed --- config/filter.d/asterisk.conf | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/config/filter.d/asterisk.conf b/config/filter.d/asterisk.conf index 35906d11..f77a1557 100644 --- a/config/filter.d/asterisk.conf +++ b/config/filter.d/asterisk.conf @@ -8,13 +8,7 @@ __pid_re = (?:\[\d+\]) # All Asterisk log messages begin like this: log_prefix= \[\]\s*(?:NOTICE|SECURITY)%(__pid_re)s:?(?:\[\S+\d*\])? \S+:\d* -failregex = ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - Wrong password$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - No matching peer found$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - Username/auth name mismatch$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - Device does not match ACL$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - Peer is not supposed to register$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - ACL error \(permit/deny\)$ - ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - Not a local domain$ +failregex = ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - (Wrong password|No matching peer found|Username/auth name mismatch|Device does not match ACL|Peer is not supposed to register|ACL error \(permit/deny\)|Not a local domain)$ ^%(log_prefix)s Call from '[^']*' \(:\d+\) to extension '\d+' rejected because extension not found in context 'default'\.$ ^%(log_prefix)s Host failed to authenticate as '[^']*'$ ^%(log_prefix)s No registration for peer '[^']*' \(from \)$ From eace931c19d7da6ae8a81de9db6258d605a749f2 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Thu, 7 Nov 2013 15:47:25 -0800 Subject: [PATCH 015/125] Changelog for prior changes (gen_buildbots) --- ChangeLog | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ChangeLog b/ChangeLog index fc001187..3d9d1a96 100644 --- a/ChangeLog +++ b/ChangeLog @@ -149,6 +149,9 @@ some obscure corner of the Internet. * filter.d/roundcube-auth.conf -- anchored version * date matching - for standard asctime formats prefer more detailed first (thus use year if available) + * files/gen_badbots was added and filter.d/apache-badbots.conf was + regenerated to get updated (although now still an old) list of + "bad" bots Alexander Dietrich * action.d/sendmail-common.conf -- added common sendmail settings file and made the sender display name configurable From abb012ae5c90c4bfc2b83512bc168f1ecaa0d10e Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 8 Nov 2013 10:00:37 -0800 Subject: [PATCH 016/125] BF: fixing injection for OpenSSH 6.3 -- making .* before non-greedy --- config/filter.d/sshd.conf | 2 +- testcases/files/logs/sshd | 4 ++++ 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/config/filter.d/sshd.conf b/config/filter.d/sshd.conf index 08456177..be80b02f 100644 --- a/config/filter.d/sshd.conf +++ b/config/filter.d/sshd.conf @@ -14,7 +14,7 @@ _daemon = sshd failregex = ^%(__prefix_line)s(?:error: PAM: )?[aA]uthentication (?:failure|error) for .* from ( via \S+)?\s*$ ^%(__prefix_line)s(?:error: PAM: )?User not known to the underlying authentication module for .* from \s*$ - ^%(__prefix_line)sFailed \S+ for .* from (?: port \d*)?(?: ssh\d*)?(: (ruser .{0,100}|(\S+ ID \S+ \(serial \d+\) CA )?\S+ %(__md5hex)s(, client user ".{0,100}", client host ".{0,100}")?))?\s*$ + ^%(__prefix_line)sFailed \S+ for .*? from (?: port \d*)?(?: ssh\d*)?(: (ruser .{0,100}|(\S+ ID \S+ \(serial \d+\) CA )?\S+ %(__md5hex)s(, client user ".{0,100}", client host ".{0,100}")?))?\s*$ ^%(__prefix_line)sROOT LOGIN REFUSED.* FROM \s*$ ^%(__prefix_line)s[iI](?:llegal|nvalid) user .* from \s*$ ^%(__prefix_line)sUser .+ from not allowed because not listed in AllowUsers\s*$ diff --git a/testcases/files/logs/sshd b/testcases/files/logs/sshd index 96338220..def0ebb5 100644 --- a/testcases/files/logs/sshd +++ b/testcases/files/logs/sshd @@ -94,3 +94,7 @@ Sep 29 17:15:02 spaceman sshd[12946]: Failed hostbased for dan from 127.0.0.1 po # failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1" } Sep 29 17:15:02 spaceman sshd[12946]: Failed hostbased for dan from 127.0.0.1 port 45785 ssh2: DSA 01:c0:79:41:91:31:9a:7d:95:23:91:ac:b1:6d:59:81, client user "dan", client host "localhost.localdomain" + +# Injecting into rhost for the format of OpenSSH >=6.3 +# failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1" } +Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser from 1.2.3.4 From 750e0c1e3dbce856437c115142d57f18b6c1fac7 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 8 Nov 2013 10:06:24 -0800 Subject: [PATCH 017/125] BF: disallow exploiting of non-greedy .* in previous fix by providing too long rhost -- do not impose length limits for user-provided input since daemon might eventually change reported length and we would need to adjust anyways. So limiting in length does not provide additional security but allows for a possible injection vector --- ChangeLog | 2 +- config/filter.d/sshd.conf | 2 +- testcases/files/logs/sshd | 6 ++++-- 3 files changed, 6 insertions(+), 4 deletions(-) diff --git a/ChangeLog b/ChangeLog index 3d9d1a96..5120c139 100644 --- a/ChangeLog +++ b/ChangeLog @@ -78,7 +78,7 @@ some obscure corner of the Internet. * filter.d/recidive -- support f2b syslog target and anchor regex at start * filter.d/mysqld-auth.conf - mysql can use syslog * filter.d/sshd - regex enhancements to support openssh-6.3. Closes Debian - bug #722970 + bug #722970. Thanks Colin Watson for the regex analysis. * filter.d/wuftpd - regex enhancements to support pam and wuftpd. Closes Debian bug #665925 Rolf Fokkens diff --git a/config/filter.d/sshd.conf b/config/filter.d/sshd.conf index be80b02f..d97fd675 100644 --- a/config/filter.d/sshd.conf +++ b/config/filter.d/sshd.conf @@ -14,7 +14,7 @@ _daemon = sshd failregex = ^%(__prefix_line)s(?:error: PAM: )?[aA]uthentication (?:failure|error) for .* from ( via \S+)?\s*$ ^%(__prefix_line)s(?:error: PAM: )?User not known to the underlying authentication module for .* from \s*$ - ^%(__prefix_line)sFailed \S+ for .*? from (?: port \d*)?(?: ssh\d*)?(: (ruser .{0,100}|(\S+ ID \S+ \(serial \d+\) CA )?\S+ %(__md5hex)s(, client user ".{0,100}", client host ".{0,100}")?))?\s*$ + ^%(__prefix_line)sFailed \S+ for .*? from (?: port \d*)?(?: ssh\d*)?(: (ruser .*|(\S+ ID \S+ \(serial \d+\) CA )?\S+ %(__md5hex)s(, client user ".*", client host ".*")?))?\s*$ ^%(__prefix_line)sROOT LOGIN REFUSED.* FROM \s*$ ^%(__prefix_line)s[iI](?:llegal|nvalid) user .* from \s*$ ^%(__prefix_line)sUser .+ from not allowed because not listed in AllowUsers\s*$ diff --git a/testcases/files/logs/sshd b/testcases/files/logs/sshd index def0ebb5..4f862d89 100644 --- a/testcases/files/logs/sshd +++ b/testcases/files/logs/sshd @@ -95,6 +95,8 @@ Sep 29 17:15:02 spaceman sshd[12946]: Failed hostbased for dan from 127.0.0.1 po # failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1" } Sep 29 17:15:02 spaceman sshd[12946]: Failed hostbased for dan from 127.0.0.1 port 45785 ssh2: DSA 01:c0:79:41:91:31:9a:7d:95:23:91:ac:b1:6d:59:81, client user "dan", client host "localhost.localdomain" -# Injecting into rhost for the format of OpenSSH >=6.3 -# failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1" } +# failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1", "desc": "Injecting into rhost for the format of OpenSSH >=6.3" } Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser from 1.2.3.4 + +# failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1", "desc": "Injecting while exhausting initially present {0,100} match length limits set for ruser etc" } +Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX from 1.2.3.4 From bf245f9640e3a957f1deb751f9eb28742f957107 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 8 Nov 2013 14:34:31 -0800 Subject: [PATCH 018/125] DOC: adding DEV Notes for for non-greedy matchin within sshd.conf --- config/filter.d/sshd.conf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/config/filter.d/sshd.conf b/config/filter.d/sshd.conf index d97fd675..a36b050c 100644 --- a/config/filter.d/sshd.conf +++ b/config/filter.d/sshd.conf @@ -26,4 +26,11 @@ failregex = ^%(__prefix_line)s(?:error: PAM: )?[aA]uthentication (?:failure|erro ignoreregex = +# DEV Notes: +# +# "Failed \S+ for .*? from ..." failregex uses non-greedy catch-all because +# it is coming before use of which is not hard-anchored at the end as well, +# and later catch-all's could contain user-provided input, which need to be greedily +# matched away first. +# # Author: Cyril Jaquier, Yaroslav Halchenko, Petr Voralek, Daniel Black From 49024fe6ea1283c1bec69a2547237dd1e4adf117 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 8 Nov 2013 14:36:56 -0800 Subject: [PATCH 019/125] DOC: minor typos in ChangeLog --- ChangeLog | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 648f1e1a..27e598ef 100644 --- a/ChangeLog +++ b/ChangeLog @@ -96,7 +96,7 @@ some obscure corner of the Internet. - New Features: Edgar Hoch - * action.d/firewall-cmd-direct-new.conf - action for firewalld + * action.d/firewall-cmd-direct-new.conf - action for firewalld from https://bugzilla.redhat.com/show_bug.cgi?id=979622 NOTE: requires firewalld-0.3.8+ Andy Fragen and Daniel Black @@ -113,7 +113,7 @@ some obscure corner of the Internet. with additions for greater control over filtering spam. * add date expression for apache-2.4 - milliseconds * filter.d/nginx-http-auth -- filter added for http basic authentication - failures in nginx. Partially forfills gh-405. + failures in nginx. Partially fulfills gh-405. Christophe Carles & Daniel Black * filter.d/perdition.conf -- filter added Mark McKinstry From ac061155f093464fb6cd2329d3d513b15c68e256 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 8 Nov 2013 14:40:52 -0800 Subject: [PATCH 020/125] BF: anchor introduced nginx-http-auth at the end needed since request probably could be not a correct HTTP statement but continue with all those to match till the end and then injected ", client: VICTIM, server..." thus allowing injection. We better anchor at the end then --- config/filter.d/nginx-http-auth.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/filter.d/nginx-http-auth.conf b/config/filter.d/nginx-http-auth.conf index 00f152b7..79dda30b 100644 --- a/config/filter.d/nginx-http-auth.conf +++ b/config/filter.d/nginx-http-auth.conf @@ -4,7 +4,7 @@ [Definition] -failregex = ^ \[error\] \d+#\d+: \*\d+ user "\S+":? (password mismatch|was not found in ".*"), client: , server: \S+, request: "\S+ \S+ HTTP/\d+\.\d+", host: "\S+" +failregex = ^ \[error\] \d+#\d+: \*\d+ user "\S+":? (password mismatch|was not found in ".*"), client: , server: \S+, request: "\S+ \S+ HTTP/\d+\.\d+", host: "\S+"\s*$ ignoreregex = From 724c6bfd922638ecc1eddf9197df5369eeb7cd0b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 9 Nov 2013 10:35:13 +1100 Subject: [PATCH 021/125] DOC: filter regex debugging --- DEVELOP | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/DEVELOP b/DEVELOP index 9a3be94b..0e37a0c3 100644 --- a/DEVELOP +++ b/DEVELOP @@ -289,15 +289,19 @@ TIP: Some applications log spaces at the end. If you are not sure add \s*$ as the end part of the regex. If your regex is not matching, http://www.debuggex.com/?flavor=python can help -to tune it: +to tune it. fail2ban-regex -D ... will present Debuggex URLs for the regexs +and sample log files that you pass into it. +In general use when using regex debuggers for generating fail2ban filters: * use regex from the ./fail2ban-regex output (to ensure all substitutions are -done) and replace with (?&.ipv4). Make sure that regex type set to -Python; -* for the test data put your log output with the time removed; -- when you have fixed the regex put it back into your filter file. +done) +* replace with (?&.ipv4) +* make sure that regex type set to Python +* for the test data put your log output with the date/time removed -Please spread the good word about debuggex - Serge Toarca is kindly continuing +When you have fixed the regex put it back into your filter file. + +Please spread the good word about Debuggex - Serge Toarca is kindly continuing its free availability to Open Source developers. Finishing up: From b8f40fef1bf362f5645b912b651797e4d2b83de2 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 08:08:10 +1100 Subject: [PATCH 022/125] DOC: more on filter regexes - DEVELOP --- DEVELOP | 81 ++++++++++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 78 insertions(+), 3 deletions(-) diff --git a/DEVELOP b/DEVELOP index 0e37a0c3..d776d8f7 100644 --- a/DEVELOP +++ b/DEVELOP @@ -331,7 +331,7 @@ failregex, while matching inserted text to the part, they have the ability to deny any host they choose. So the part must be anchored on text generated by the application, and -not the user, to a extent sufficient to prevent user inserting the entire text +not the user, to an extent sufficient to prevent user inserting the entire text matching this or any other failregex. Ideally filter regex should anchor at the beginning and at the end of log line. @@ -381,7 +381,7 @@ Note if we'd just had the expression: Then provided the user put a space in their command they would have never been banned. -2. Filter regex can match other user injected data +2. Unanchored regex can match other user injected data From the Apache vulnerability CVE-2013-2178 ( original ref: https://vndh.net/note:fail2ban-089-denial-service ). @@ -402,7 +402,82 @@ Now the log line will be: As this log line doesn't match other expressions hence it matches the above regex and blocks 192.168.33.1 as a denial of service from the HTTP requester. -3. Application generates two identical log messages with different meanings +3. Over greedy pattern matching + +From: https://github.com/fail2ban/fail2ban/pull/426 + +An example ssh log (simplified) + + Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser remoteuser + +As we assume username can include anything including spaces its prudent to put +.* here. The remote user can also exist as anything so lets not make assumptions again. + + failregex = ^%(__prefix_line)sFailed \S+ for .* from ( port \d*)?( ssh\d+)?(: ruser .*)?$ + +So this works. The problem is if the .* after remote user is injected by the +user to be 'from 1.2.3.4'. The resultant log line is. + + Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser from 1.2.3.4 + +Testing with: + + fail2ban-regex -v 'Sep 29 17:15:02 Failed password for user from 127.0.0.1 port 20000 ssh1: ruser from 1.2.3.4' '^ Failed \S+ for .* from ( port \d*)?( ssh\d+)?(: ruser .*)?$' + +TIP: I've removed the bit that matches __prefix_line from the regex and log. + +Shows: + + 1) [1] ^ Failed \S+ for .* from ( port \d*)?( ssh\d+)?(: ruser .*)?$ + 1.2.3.4 Sun Sep 29 17:15:02 2013 + +It should of matched 127.0.0.1. So the first greedy part of the greedy regex +matched until the end of the string. The was no "from " so the regex +engine worked backwards from the end of the string until this was matched. + +The result was that 1.2.3.4 was matched, injected by the user, and the wrong IP +was banned. + +The solution here is to make the first .* non-greedy with .*?. Here it matches +as little as required and the fail2ban-regex tool shows the output: + + fail2ban-regex -v 'Sep 29 17:15:02 Failed password for user from 127.0.0.1 port 20000 ssh1: ruser from 1.2.3.4' '^ Failed \S+ for .*? from ( port \d*)?( ssh\d+)?(: ruser .*)?$' + + 1) [1] ^ Failed \S+ for .*? from ( port \d*)?( ssh\d+)?(: ruser .*)?$ + 127.0.0.1 Sun Sep 29 17:15:02 2013 + +So the general case here is a log line that contains: + + (fixed_data_1)(fixed_data_2)(user_injectable_data) + +Where the regex that matches fixed_data_1 is gready and matches the entire +string, before moving backwards and user_injectable_data can match the entire +string. + +Another case: + +ref: https://www.debuggex.com/r/CtAbeKMa2sDBEfA2/0 + +A webserver logs the following without URL escaping: + + [error] 2865#0: *66647 user "xyz" was not found in "/file", client: 1.2.3.1, server: www.host.com, request: "GET ", client: 3.2.1.1, server: fake.com, request: "GET exploited HTTP/3.3", host: "injected.host", host: "www.myhost.com" + +regex: + + failregex = ^ \[error\] \d+#\d+: \*\d+ user "\S+":? (?:password mismatch|was not found in ".*"), client: , server: \S+, request: "\S+ .+ HTTP/\d+\.\d+", host: "\S+" + +The .* matches to the end of the string. Finds that it can't continue to match +", client ... so it moves from the back and find that the user injected web URL: + + ", client: 3.2.1.1, server: fake.com, request: "GET exploited HTTP/3.3", host: "injected.host + +In this case there is a fixed host: "www.myhost.com" at the end so the solution +is to anchor the regex at the end with a $. + +If this wasn't the case then first .* needed to be made so it didn't capture +beyond . + +4. Application generates two identical log messages with different meanings If the application generates the following two messages under different circumstances: From d955714d26ba78f11999b4bd99a7c36ff8c55679 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 08:11:32 +1100 Subject: [PATCH 023/125] TST: test case that shows injection --- testcases/files/logs/sshd | 3 +++ 1 file changed, 3 insertions(+) diff --git a/testcases/files/logs/sshd b/testcases/files/logs/sshd index 4f862d89..ed4857bd 100644 --- a/testcases/files/logs/sshd +++ b/testcases/files/logs/sshd @@ -100,3 +100,6 @@ Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 po # failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1", "desc": "Injecting while exhausting initially present {0,100} match length limits set for ruser etc" } Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX from 1.2.3.4 + +# failJSON: { "time": "2004-11-11T08:04:51", "match": true , "host": "127.0.0.1", "desc": "Injecting on username ssh 'from 10.10.1.1'@localhost" +Nov 11 08:04:51 redbamboo sshd[2737]: Failed password for invalid user from 10.10.1.1 from 127.0.0.1 port 58946 ssh2 From 061a26c40815b8594e9ffce1e9056aeac7dff5cd Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 08:28:09 +1100 Subject: [PATCH 024/125] TST: fix space in sshd sample log --- testcases/files/logs/sshd | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/testcases/files/logs/sshd b/testcases/files/logs/sshd index ed4857bd..541afb19 100644 --- a/testcases/files/logs/sshd +++ b/testcases/files/logs/sshd @@ -101,5 +101,5 @@ Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 po # failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1", "desc": "Injecting while exhausting initially present {0,100} match length limits set for ruser etc" } Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX from 1.2.3.4 -# failJSON: { "time": "2004-11-11T08:04:51", "match": true , "host": "127.0.0.1", "desc": "Injecting on username ssh 'from 10.10.1.1'@localhost" +# failJSON: { "time": "2004-11-11T08:04:51", "match": true , "host": "127.0.0.1", "desc": "Injecting on username ssh 'from 10.10.1.1'@localhost" Nov 11 08:04:51 redbamboo sshd[2737]: Failed password for invalid user from 10.10.1.1 from 127.0.0.1 port 58946 ssh2 From d90130234dfba1fd389118941dcf4ec8db031c8b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 08:29:54 +1100 Subject: [PATCH 025/125] TST: end of json in sshd sample log --- testcases/files/logs/sshd | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/testcases/files/logs/sshd b/testcases/files/logs/sshd index 541afb19..3c50dcfd 100644 --- a/testcases/files/logs/sshd +++ b/testcases/files/logs/sshd @@ -101,5 +101,5 @@ Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 po # failJSON: { "time": "2004-09-29T17:15:02", "match": true , "host": "127.0.0.1", "desc": "Injecting while exhausting initially present {0,100} match length limits set for ruser etc" } Sep 29 17:15:02 spaceman sshd[12946]: Failed password for user from 127.0.0.1 port 20000 ssh1: ruser XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX from 1.2.3.4 -# failJSON: { "time": "2004-11-11T08:04:51", "match": true , "host": "127.0.0.1", "desc": "Injecting on username ssh 'from 10.10.1.1'@localhost" +# failJSON: { "time": "2004-11-11T08:04:51", "match": true , "host": "127.0.0.1", "desc": "Injecting on username ssh 'from 10.10.1.1'@localhost" } Nov 11 08:04:51 redbamboo sshd[2737]: Failed password for invalid user from 10.10.1.1 from 127.0.0.1 port 58946 ssh2 From 87516eb92b5792ce1202a5d67da481f6019ad52a Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 09:46:40 +1100 Subject: [PATCH 026/125] ENH: apache-overflows - more detail on "request failed: URI too long (longer than %d)" with test case --- config/filter.d/apache-overflows.conf | 8 +++++++- testcases/files/logs/apache-overflows | 3 +++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/config/filter.d/apache-overflows.conf b/config/filter.d/apache-overflows.conf index de1c770d..68669222 100644 --- a/config/filter.d/apache-overflows.conf +++ b/config/filter.d/apache-overflows.conf @@ -8,8 +8,14 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s (Invalid (method|URI) in request|request failed: URI too long|erroneous characters after protocol string) +failregex = ^%(_apache_error_client)s (Invalid (method|URI) in request|request failed: URI too long \(longer than \d+\)|erroneous characters after protocol string) ignoreregex = +# DEV Noptes: +# +# fgrep -r 'URI too long' httpd-2.* +# httpd-2.2.25/server/protocol.c: "request failed: URI too long (longer than %d)", r->server->limit_req_line); +# httpd-2.4.4/server/protocol.c: "request failed: URI too long (longer than %d)", +# # Author: Tim Connors diff --git a/testcases/files/logs/apache-overflows b/testcases/files/logs/apache-overflows index d40c1c4f..69e5fd49 100644 --- a/testcases/files/logs/apache-overflows +++ b/testcases/files/logs/apache-overflows @@ -2,3 +2,6 @@ [Tue Mar 16 15:39:29 2010] [error] [client 58.179.109.179] Invalid URI in request \xf9h\xa9\xf3\x88\x8cXKj \xbf-l*4\x87n\xe4\xfe\xd4\x1d\x06\x8c\xf8m\\rS\xf6n\xeb\x8 # failJSON: { "time": "2010-03-15T15:44:47", "match": true , "host": "121.222.2.133" } [Mon Mar 15 15:44:47 2010] [error] [client 121.222.2.133] Invalid URI in request n\xed*\xbe*\xab\xefd\x80\xb5\xae\xf6\x01\x10M?\xf2\xce\x13\x9c\xd7\xa0N\xa7\xdb%0\xde\xe0\xfc\xd2\xa0\xfe\xe9w\xee\xc4`v\x9b[{\x0c:\xcb\x93\xc6\xa0\x93\x9c`l\\\x8d\xc9 +# http://forum.nconf.org/viewtopic.php?f=14&t=427&p=1488 +# failJSON: { "time": "2010-07-30T11:23:54", "match": true , "host": "10.85.6.69" } +[Fri Jul 30 11:23:54 2010] [error] [client 10.85.6.69] request failed: URI too long (longer than 8190) From a4718eb64402d2329bc3891c68024e7d1c61277f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 10:38:02 +1100 Subject: [PATCH 027/125] ENH: apache-overflow filter to have HTTP-2.4 message IDs and test samples --- config/filter.d/apache-overflows.conf | 19 +++++++++++++++++-- testcases/files/logs/apache-overflows | 18 ++++++++++++++++++ 2 files changed, 35 insertions(+), 2 deletions(-) diff --git a/config/filter.d/apache-overflows.conf b/config/filter.d/apache-overflows.conf index 68669222..92551525 100644 --- a/config/filter.d/apache-overflows.conf +++ b/config/filter.d/apache-overflows.conf @@ -8,14 +8,29 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s (Invalid (method|URI) in request|request failed: URI too long \(longer than \d+\)|erroneous characters after protocol string) +failregex = ^%(_apache_error_client)s ((AH0013[456]: )?Invalid (method|URI) in request .*( - possible attempt to establish SSL connection on non-SSL port)?|(AH00565: )?request failed: URI too long \(longer than \d+\)|request failed: erroneous characters after protocol string: .*|AH00566: request failed: invalid characters in URI)$ ignoreregex = -# DEV Noptes: +# DEV Notes: # # fgrep -r 'URI too long' httpd-2.* # httpd-2.2.25/server/protocol.c: "request failed: URI too long (longer than %d)", r->server->limit_req_line); # httpd-2.4.4/server/protocol.c: "request failed: URI too long (longer than %d)", # +# fgrep -r 'in request' ../httpd-2.* | fgrep Invalid +# httpd-2.2.25/server/core.c: "Invalid URI in request %s", r->the_request); +# httpd-2.2.25/server/core.c: "Invalid method in request %s", r->the_request); +# httpd-2.2.25/docs/manual/rewrite/flags.html.fr:avertissements 'Invalid URI in request'. +# httpd-2.4.4/server/core.c: "Invalid URI in request %s", r->the_request); +# httpd-2.4.4/server/core.c: "Invalid method in request %s - possible attempt to establish SSL connection on non-SSL port", r->the_request); +# httpd-2.4.4/server/core.c: "Invalid method in request %s", r->the_request); +# +# fgrep -r 'invalid characters in URI' httpd-2.* +# httpd-2.4.4/server/protocol.c: "request failed: invalid characters in URI"); +# +# http://svn.apache.org/viewvc/httpd/httpd/trunk/server/core.c?r1=739382&r2=739620&pathrev=739620 +# ...possible attempt to establish SSL connection on non-SSL port +# +# https://wiki.apache.org/httpd/ListOfErrors # Author: Tim Connors diff --git a/testcases/files/logs/apache-overflows b/testcases/files/logs/apache-overflows index 69e5fd49..01f54c7d 100644 --- a/testcases/files/logs/apache-overflows +++ b/testcases/files/logs/apache-overflows @@ -1,7 +1,25 @@ +# http://osdir.com/ml/debian-bugs-dist/2010-03/msg05840.html # failJSON: { "time": "2010-03-16T15:39:29", "match": true , "host": "58.179.109.179" } [Tue Mar 16 15:39:29 2010] [error] [client 58.179.109.179] Invalid URI in request \xf9h\xa9\xf3\x88\x8cXKj \xbf-l*4\x87n\xe4\xfe\xd4\x1d\x06\x8c\xf8m\\rS\xf6n\xeb\x8 # failJSON: { "time": "2010-03-15T15:44:47", "match": true , "host": "121.222.2.133" } [Mon Mar 15 15:44:47 2010] [error] [client 121.222.2.133] Invalid URI in request n\xed*\xbe*\xab\xefd\x80\xb5\xae\xf6\x01\x10M?\xf2\xce\x13\x9c\xd7\xa0N\xa7\xdb%0\xde\xe0\xfc\xd2\xa0\xfe\xe9w\xee\xc4`v\x9b[{\x0c:\xcb\x93\xc6\xa0\x93\x9c`l\\\x8d\xc9 + # http://forum.nconf.org/viewtopic.php?f=14&t=427&p=1488 # failJSON: { "time": "2010-07-30T11:23:54", "match": true , "host": "10.85.6.69" } [Fri Jul 30 11:23:54 2010] [error] [client 10.85.6.69] request failed: URI too long (longer than 8190) +# failJSON: { "time": "2010-10-27T23:16:37", "match": true , "host": "187.117.240.164" } +[Wed Oct 27 23:16:37 2010] [error] [client 187.117.240.164] Invalid URI in request x\xb2\xa1:SMl\xcc{\xfd"\xd1\x91\x84!d\x0e~\xf6:\xfbVu\xdf\xc3\xdb[\xa9\xfe\xd3lpz\x92\xbf\x9f5\xa3\xbbvF\xbc\xee\x1a\xb1\xb0\xf8K\xecE\xbc\xe8r\xacx=\xc7>\xb5\xbd\xa3\xda\xe9\xf09\x95"fd\x1c\x05\x1c\xd5\xf3#:\x91\xe6WE\xdb\xadN;k14;\xdcr\xad\x9e\xa8\xde\x95\xc3\xebw\xa0\xb1N\x8c~\xf1\xcfSY\xd5zX\xd7\x0f\vH\xe4\xb5(\xcf,3\xc98\x19\xefYq@\xd2I\x96\xfb\xc7\xa9\xae._{S\xd1\x9c\xad\x17\xdci\x9b\xca\x93\xafSM\xb8\x99\xd9|\xc2\xd8\xc9\xe7\xe9O\x99\xad\x19\xc3V]\xcc\xddR\xf7$\xaa\xb8\x18\xe0f\xb8\xff + + +# Could be apache-2.2 or earlier +# http://www.aota.net/forums/showthread.php?t=15796 +# failJSON: { "time": "2003-11-14T16:11:55", "match": true , "host": "1.2.3.4" } +[Fri Nov 14 16:11:55 2003] [error] [client 1.2.3.4] request failed: erroneous characters after protocol string: User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; m18) Gecko/20001108 Netscape6/6.0 + +# http://forum.directadmin.com/showthread.php?t=22412 +# failJSON: { "time": "2007-11-15T03:09:59", "match": true , "host": "89.189.71.87" } +[Thu Nov 15 03:09:59 2007] [error] [client 89.189.71.87] Invalid method in request NOOP + +# https://issues.apache.org/bugzilla/show_bug.cgi?id=46123 +# failJSON: { "time": "2008-10-29T11:55:14", "match": true , "host": "127.0.0.1" } +[Wed Oct 29 11:55:14 2008] [error] [client 127.0.0.1] Invalid method in request \x16\x03\x01 - possible attempt to establish SSL connection when the server isn't expecting it From c81ed538056c2a9ed163de2354fbd93de731b98c Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 10:40:12 +1100 Subject: [PATCH 028/125] TST: change source URL --- testcases/files/logs/apache-overflows | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/testcases/files/logs/apache-overflows b/testcases/files/logs/apache-overflows index 01f54c7d..376114c4 100644 --- a/testcases/files/logs/apache-overflows +++ b/testcases/files/logs/apache-overflows @@ -1,4 +1,4 @@ -# http://osdir.com/ml/debian-bugs-dist/2010-03/msg05840.html +# http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574182 # failJSON: { "time": "2010-03-16T15:39:29", "match": true , "host": "58.179.109.179" } [Tue Mar 16 15:39:29 2010] [error] [client 58.179.109.179] Invalid URI in request \xf9h\xa9\xf3\x88\x8cXKj \xbf-l*4\x87n\xe4\xfe\xd4\x1d\x06\x8c\xf8m\\rS\xf6n\xeb\x8 # failJSON: { "time": "2010-03-15T15:44:47", "match": true , "host": "121.222.2.133" } From 648d48c35516b5781b36dfa504a77764456dcbfe Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 11 Nov 2013 10:49:11 +1100 Subject: [PATCH 029/125] ENH: apache-2.4 message IDs for filter apache-noscript --- config/filter.d/apache-noscript.conf | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/config/filter.d/apache-noscript.conf b/config/filter.d/apache-noscript.conf index 4ecf349a..f3c6246a 100644 --- a/config/filter.d/apache-noscript.conf +++ b/config/filter.d/apache-noscript.conf @@ -9,10 +9,16 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s (File does not exist|script not found or unable to stat): /\S*(\.php|\.asp|\.exe|\.pl)\s*$ +failregex = ^%(_apache_error_client)s ((AH001(28|30): )?File does not exist|(AH01264: )?script not found or unable to stat): /\S*(\.php|\.asp|\.exe|\.pl)\s*$ ^%(_apache_error_client)s script '/\S*(\.php|\.asp|\.exe|\.pl)\S*' not found or unable to stat\s*$ ignoreregex = +# DEV Notes: +# +# https://wiki.apache.org/httpd/ListOfErrors for apache error IDs +# +# Second regex, script '/\S*(\.php|\.asp|\.exe|\.pl)\S*' not found or unable to stat\s*$ is Before http-2.2 +# # Author: Cyril Jaquier From eb9663eb4fd8248c7a6ce82d04edabb3a701c798 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 12 Nov 2013 09:22:41 +1100 Subject: [PATCH 030/125] BF/ENH: asterisk connection ID is a hex not decimal number. Add "Rejecting unknown SIP connection from " regex thanks to Jonathan Lanning --- ChangeLog | 3 +++ THANKS | 1 + config/filter.d/asterisk.conf | 3 ++- testcases/files/logs/asterisk | 3 +++ 4 files changed, 9 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 27e598ef..50b8bb8e 100644 --- a/ChangeLog +++ b/ChangeLog @@ -32,6 +32,9 @@ some obscure corner of the Internet. those filters were used. - Fixes: + Jonathan Lanning + * filter.d/asterisk -- identified another regex for blocking. Also channel + ID is hex not decimal as noted in sample logs provided. Daniel Black & Marcel Dopita * filter.d/apache-auth -- fixed and apache auth samples provide. Closes gh-286 Yaroslav Halchenko diff --git a/THANKS b/THANKS index 5f6d1b2b..13303c21 100644 --- a/THANKS +++ b/THANKS @@ -34,6 +34,7 @@ Guillaume Delvit Hanno 'Rince' Wagner Iain Lea Jonathan Kamens +Jonathan Lanning Jonathan Underwood Joël Bertrand JP Espinosa diff --git a/config/filter.d/asterisk.conf b/config/filter.d/asterisk.conf index f77a1557..3c1a97df 100644 --- a/config/filter.d/asterisk.conf +++ b/config/filter.d/asterisk.conf @@ -6,7 +6,7 @@ __pid_re = (?:\[\d+\]) # All Asterisk log messages begin like this: -log_prefix= \[\]\s*(?:NOTICE|SECURITY)%(__pid_re)s:?(?:\[\S+\d*\])? \S+:\d* +log_prefix= \[\]\s*(?:NOTICE|SECURITY)%(__pid_re)s:?(?:\[C-[\da-f]*\])? \S+:\d* failregex = ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' - (Wrong password|No matching peer found|Username/auth name mismatch|Device does not match ACL|Peer is not supposed to register|ACL error \(permit/deny\)|Not a local domain)$ ^%(log_prefix)s Call from '[^']*' \(:\d+\) to extension '\d+' rejected because extension not found in context 'default'\.$ @@ -16,6 +16,7 @@ failregex = ^%(log_prefix)s Registration from '[^']*' failed for '(:\d+)?' ^%(log_prefix)s Failed to authenticate (user|device) [^@]+@\S*$ ^%(log_prefix)s (?:handle_request_subscribe: )?Sending fake auth rejection for (device|user) \d*>;tag=\w+\S*$ ^%(log_prefix)s SecurityEvent="(FailedACL|InvalidAccountID|ChallengeResponseFailed|InvalidPassword)",EventTV="[\d-]+",Severity="[\w]+",Service="[\w]+",EventVersion="\d+",AccountID="\d+",SessionID="0x[\da-f]+",LocalAddress="IPV[46]/(UD|TC)P/[\da-fA-F:.]+/\d+",RemoteAddress="IPV[46]/(UD|TC)P//\d+"(,Challenge="\w+",ReceivedChallenge="\w+")?(,ReceivedHash="[\da-f]+")?$ + ^\[\]\s*WARNING%(__pid_re)s:?(?:\[C-[\da-f]*\])? Ext\. s: "Rejecting unknown SIP connection from "$ ignoreregex = diff --git a/testcases/files/logs/asterisk b/testcases/files/logs/asterisk index b2eb7738..60c89d5f 100644 --- a/testcases/files/logs/asterisk +++ b/testcases/files/logs/asterisk @@ -40,3 +40,6 @@ [2009-12-22 16:35:24] NOTICE[14916]: chan_sip.c:15644 handle_request_subscribe: Sending fake auth rejection for user ;tag=6pwd6erg54 # failJSON: { "time": "2013-07-06T09:09:25", "match": true , "host": "141.255.164.106" } [2013-07-06 09:09:25] SECURITY[3308] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="1373098165-824497",Severity="Error",Service="SIP",EventVersion="2",AccountID="972592891005",SessionID="0x88aab6c",LocalAddress="IPV4/UDP/92.28.73.180/5060",RemoteAddress="IPV4/UDP/141.255.164.106/5084",Challenge="41d26de5",ReceivedChallenge="41d26de5",ReceivedHash="7a6a3a2e95a05260aee612896e1b4a39" + +# failJSON: { "time": "2013-11-11T14:33:38", "match": true , "host": "192.168.55.152" } +[2013-11-11 14:33:38] WARNING[6756][C-0000001d] Ext. s: "Rejecting unknown SIP connection from 192.168.55.152" From c272573fe3318b18cd76d0655481d4fe04b6d9e1 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 12 Nov 2013 18:06:16 +1100 Subject: [PATCH 031/125] ENH: DoS resistant dropbear filter --- config/filter.d/dropbear.conf | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/config/filter.d/dropbear.conf b/config/filter.d/dropbear.conf index 54d8166b..288b0882 100644 --- a/config/filter.d/dropbear.conf +++ b/config/filter.d/dropbear.conf @@ -23,8 +23,8 @@ before = common.conf _daemon = dropbear -failregex = ^%(__prefix_line)s[Ll]ogin attempt for nonexistent user ('.*' )?from :.*$ - ^%(__prefix_line)s[Bb]ad (PAM )?password attempt for .+ from .*$ +failregex = ^%(__prefix_line)s[Ll]ogin attempt for nonexistent user ('.*' )?from :\d+$ + ^%(__prefix_line)s[Bb]ad (PAM )?password attempt for .+ from (:\d+)?$ ^%(__prefix_line)s[Ee]xit before auth \(user '.+', \d+ fails\): Max auth tries reached - user '.+' from :\d+\s*$ ignoreregex = @@ -37,5 +37,12 @@ ignoreregex = # # The second last failregex line we need to match with the modified dropbear. # +# For the second regex the following apply: +# +# http://www.netmite.com/android/mydroid/external/dropbear/svr-authpam.c +# http://svn.dd-wrt.com/changeset/16642#file64 +# +# http://svn.dd-wrt.com/changeset/16642/src/router/dropbear/svr-authpasswd.c +# # Author: Francis Russell # Zak B. Elep From 52972164a273963ded6f0a244deab2f938e49cd4 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 12 Nov 2013 18:13:35 +1100 Subject: [PATCH 032/125] BF: exim filter to be DoS resistant --- config/filter.d/exim.conf | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/config/filter.d/exim.conf b/config/filter.d/exim.conf index 5f786594..66743390 100644 --- a/config/filter.d/exim.conf +++ b/config/filter.d/exim.conf @@ -16,7 +16,7 @@ before = exim-common.conf failregex = ^%(pid)s %(host_info)ssender verify fail for <\S+>: (?:Unknown user|Unrouteable address|all relevant MX records point to non-existent hosts)\s*$ ^%(pid)s (plain|login) authenticator failed for (\S+ )?\(\S+\) \[\]: 535 Incorrect authentication data( \(set_id=.*\)|: \d+ Time\(s\))?\s*$ ^%(pid)s %(host_info)sF=(<>|[^@]+@\S+) rejected RCPT [^@]+@\S+: (relay not permitted|Sender verify failed|Unknown user)\s*$ - ^%(pid)s SMTP protocol synchronization error \(.*\): rejected (connection from|"\S+") %(host_info)s(next )?input=".*"\s*$ + ^%(pid)s SMTP protocol synchronization error \([^)]*\): rejected (connection from|"\S+") %(host_info)s(next )?input=".*"\s*$ ^%(pid)s SMTP call from \S+ \[\](:\d+)? (I=\[\S+\]:\d+ )?dropped: too many nonmail commands \(last was "\S+"\)\s*$ ignoreregex = @@ -24,5 +24,9 @@ ignoreregex = # DEV Notes: # The %(host_info) defination contains a match # +# SMTP protocol synchronization error \([^)]*\) <- This needs to be non-greedy +# to void capture beyond ")" to avoid a DoS Injection vulnerabilty as input= is +# user injectable data. +# # Author: Cyril Jaquier # Daniel Black (rewrote with strong regexs) From be60518218cc859af4e7ee57e4d22beab27205d5 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 12 Nov 2013 18:57:01 +1100 Subject: [PATCH 033/125] BF/ENH: DoS resistant roundcube-auth with test cases and more variation in IMAP error given --- config/filter.d/roundcube-auth.conf | 19 ++++++++++++++++--- testcases/files/logs/roundcube-auth | 18 ++++++++++++++++++ 2 files changed, 34 insertions(+), 3 deletions(-) diff --git a/config/filter.d/roundcube-auth.conf b/config/filter.d/roundcube-auth.conf index 279c5edd..b093f69c 100644 --- a/config/filter.d/roundcube-auth.conf +++ b/config/filter.d/roundcube-auth.conf @@ -9,8 +9,21 @@ before = common.conf [Definition] -failregex = ^\s*(\[(\s[+-][0-9]{4})?\])?(%(__hostname)s roundcube: IMAP Error)?: (FAILED login|Login failed) for .*? from (\. AUTHENTICATE .*)?\s*$ +failregex = ^\s*(\[(\s[+-][0-9]{4})?\])?(%(__hostname)s roundcube: IMAP Error)?: (FAILED login|Login failed) for .*? from (\. .* in .*?/rcube_imap\.php on line \d+ \(\S+ \S+\))?$ ignoreregex = - -# Author: Teodor Micu & Yaroslav Halchenko & terence namusonge +# DEV Notes: +# +# Source: https://github.com/roundcube/roundcubemail/blob/master/program/lib/Roundcube/rcube_imap.php#L180 +# +# Part after comes straight from IMAP server up until the " in ....." +# Earlier versions didn't log the IMAP response hence optional. +# +# DoS resistance: +# +# Assume that the user can inject "from " into the imap response +# somehow. Write test cases around this to ensure that the combination of +# arbitary user input and IMAP response doesn't inject the wrong IP for +# fail2ban +# +# Author: Teodor Micu & Yaroslav Halchenko & terence namusonge & Daniel Black diff --git a/testcases/files/logs/roundcube-auth b/testcases/files/logs/roundcube-auth index 7c16efbd..43a42192 100644 --- a/testcases/files/logs/roundcube-auth +++ b/testcases/files/logs/roundcube-auth @@ -4,3 +4,21 @@ May 26 07:12:40 hamster roundcube: IMAP Error: Login failed for sales@example.com from 10.1.1.47 # failJSON: { "time": "2005-07-11T03:06:37", "match": true , "host": "1.2.3.4" } Jul 11 03:06:37 myhostname roundcube: IMAP Error: Login failed for admin from 1.2.3.4. AUTHENTICATE PLAIN: A0002 NO Login failed. in /usr/share/roundcube/program/include/rcube_imap.php on line 205 (POST /wmail/?_task=login&_action=login) + +# Made up to attempts to inject a DoS on the server. Assume the user can manipulate the IMAP error response +# +# user = admin from 127.0.0.1 +# failJSON: { "time": "2005-07-11T03:06:37", "match": true , "host": "1.2.3.4" } +Jul 11 03:06:37 myhostname roundcube: IMAP Error: Login failed for admin from 127.0.0.1 from 1.2.3.4. AUTHENTICATE PLAIN: A0002 NO Login failed. in /usr/share/roundcube/program/include/rcube_imap.php on line 205 (POST /wmail/?_task=login&_action=login) +# +# IMAP server logs user=${username} +# failJSON: { "time": "2005-07-11T03:06:37", "match": true , "host": "1.2.3.4" } +Jul 11 03:06:37 myhostname roundcube: IMAP Error: Login failed for admin from 127.0.0.1 from 1.2.3.4. AUTHENTICATE PLAIN: A0002 NO Login failed. user=admin from 127.0.0.1 in /usr/share/roundcube/program/include/rcube_imap.php on line 205 (POST /wmail/?_task=login&_action=login) +# +# Old roundcube version - no IMAP response +# failJSON: { "time": "2005-07-11T03:06:37", "match": true , "host": "1.2.3.4" } +Jul 11 03:06:37 myhostname roundcube: IMAP Error: Login failed for admin from 127.0.0.1 from 1.2.3.4 +# +# user = admin from 127.0.0.1 in +# failJSON: { "time": "2005-07-11T03:06:37", "match": true , "host": "1.2.3.4" } +Jul 11 03:06:37 myhostname roundcube: IMAP Error: Login failed for admin from 127.0.0.1 in from 1.2.3.4. AUTHENTICATE PLAIN: A0002 NO Login failed. user=admin from 127.0.0.1 in in /usr/share/roundcube/program/include/rcube_imap.php on line 205 (POST /wmail/?_task=login&_action=login) From d0498bec691ab31a8b0968b873c3d11b24609224 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 13 Nov 2013 08:05:08 +1100 Subject: [PATCH 034/125] DOC: finalise 0.8.11 release --- ChangeLog | 10 ++++++++-- MANIFEST | 3 +++ README.md | 2 +- common/version.py | 2 +- man/fail2ban-client.1 | 6 +++--- man/fail2ban-regex.1 | 4 ++-- man/fail2ban-server.1 | 6 +++--- 7 files changed, 21 insertions(+), 12 deletions(-) diff --git a/ChangeLog b/ChangeLog index 50b8bb8e..e901d9af 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,10 +4,10 @@ |_| \__,_|_|_/___|_.__/\__,_|_||_| ================================================================================ -Fail2Ban (version 0.8.11.pre1) 2013/10/30 +Fail2Ban (version 0.8.11) 2013/11/13 ================================================================================ -ver. 0.8.11 (2013/11/XXX) - loves-unittests-and-tight-DoS-free-filter-regexes +ver. 0.8.11 (2013/11/13) - loves-unittests-and-tight-DoS-free-filter-regexes ----------- In light of CVE-2013-2178 that triggered our last release we have put @@ -23,6 +23,12 @@ please provide us with example log lines on the github issue tracker http://github.com/fail2ban/fail2ban/issues and NOT on a random blog in some obscure corner of the Internet. +Many thanks to our contributors for this release Daniel Black, Yaroslav +Halchenko, Steven Hiscocks, Mark McKinstry, Andy Fragen, Orion Poplawski, +Alexander Dietrich, JP Espinosa, Jamyn Shanley, Beau Raines, François +Boulogne and others who have helped on IRC and mailing list, logged issues +and bug requests. + - IMPORTANT incompatible changes: Filter name changes: * 'lighttpd-fastcgi' filter has been renamed to 'suhosin' diff --git a/MANIFEST b/MANIFEST index 43927a7a..0e0eb327 100644 --- a/MANIFEST +++ b/MANIFEST @@ -60,6 +60,7 @@ testcases/files/logs/exim testcases/files/logs/suhosin testcases/files/logs/mysqld-auth testcases/files/logs/named-refused +testcases/files/logs/nginx-http-auth testcases/files/logs/pam-generic testcases/files/logs/postfix testcases/files/logs/proftpd @@ -139,6 +140,7 @@ config/filter.d/apache-badbots.conf config/filter.d/apache-nohome.conf config/filter.d/apache-noscript.conf config/filter.d/apache-overflows.conf +config/filter.d/nginx-http-auth.conf config/filter.d/courierlogin.conf config/filter.d/couriersmtp.conf config/filter.d/cyrus-imap.conf @@ -239,3 +241,4 @@ files/bash-completion files/fail2ban-tmpfiles.conf files/fail2ban.service files/ipmasq-ZZZzzz_fail2ban.rul +files/gen_badbots diff --git a/README.md b/README.md index 7c00233f..24ed11ff 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ / _|__ _(_) |_ ) |__ __ _ _ _ | _/ _` | | |/ /| '_ \/ _` | ' \ |_| \__,_|_|_/___|_.__/\__,_|_||_| - v0.8.11-pre1 2013/10/30 + v0.8.11 2013/11/13 ## Fail2Ban: ban hosts that cause multiple authentication errors diff --git a/common/version.py b/common/version.py index a0cb94ea..c699a8db 100644 --- a/common/version.py +++ b/common/version.py @@ -24,4 +24,4 @@ __author__ = "Cyril Jaquier, Yaroslav Halchenko" __copyright__ = "Copyright (c) 2004 Cyril Jaquier, 2011-2013 Yaroslav Halchenko" __license__ = "GPL" -version = "0.8.11.pre1" +version = "0.8.11" diff --git a/man/fail2ban-client.1 b/man/fail2ban-client.1 index aab2dde4..c5ccb803 100644 --- a/man/fail2ban-client.1 +++ b/man/fail2ban-client.1 @@ -1,12 +1,12 @@ -.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.12. -.TH FAIL2BAN-CLIENT "1" "October 2013" "fail2ban-client v0.8.11.pre1" "User Commands" +.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.4. +.TH FAIL2BAN-CLIENT "1" "November 2013" "fail2ban-client v0.8.11" "User Commands" .SH NAME fail2ban-client \- configure and control the server .SH SYNOPSIS .B fail2ban-client [\fIOPTIONS\fR] \fI\fR .SH DESCRIPTION -Fail2Ban v0.8.11.pre1 reads log file that contains password failure report +Fail2Ban v0.8.11 reads log file that contains password failure report and bans the corresponding IP addresses using firewall rules. .SH OPTIONS .TP diff --git a/man/fail2ban-regex.1 b/man/fail2ban-regex.1 index 4a0e272b..e2c99565 100644 --- a/man/fail2ban-regex.1 +++ b/man/fail2ban-regex.1 @@ -1,5 +1,5 @@ -.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.12. -.TH FAIL2BAN-REGEX "1" "October 2013" "fail2ban-regex 0.8.11.pre1" "User Commands" +.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.4. +.TH FAIL2BAN-REGEX "1" "November 2013" "fail2ban-regex 0.8.11" "User Commands" .SH NAME fail2ban-regex \- test Fail2ban "failregex" option .SH SYNOPSIS diff --git a/man/fail2ban-server.1 b/man/fail2ban-server.1 index 7e09b49e..147bdeaa 100644 --- a/man/fail2ban-server.1 +++ b/man/fail2ban-server.1 @@ -1,12 +1,12 @@ -.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.12. -.TH FAIL2BAN-SERVER "1" "October 2013" "fail2ban-server v0.8.11.pre1" "User Commands" +.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.40.4. +.TH FAIL2BAN-SERVER "1" "November 2013" "fail2ban-server v0.8.11" "User Commands" .SH NAME fail2ban-server \- start the server .SH SYNOPSIS .B fail2ban-server [\fIOPTIONS\fR] .SH DESCRIPTION -Fail2Ban v0.8.11.pre1 reads log file that contains password failure report +Fail2Ban v0.8.11 reads log file that contains password failure report and bans the corresponding IP addresses using firewall rules. .PP Only use this command for debugging purpose. Start the server with From 752ea054db514c0d7a47f86d7673fc63edaa304f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 13 Nov 2013 09:01:52 +1100 Subject: [PATCH 035/125] DOC: post release version change --- DEVELOP | 10 +++++----- common/version.py | 2 +- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/DEVELOP b/DEVELOP index d776d8f7..500f119f 100644 --- a/DEVELOP +++ b/DEVELOP @@ -770,23 +770,23 @@ Look for errors like: Which indicates that testcases/files/logs/mysqld.log has been moved or is a directory - tar -C /tmp -jxf dist/fail2ban-0.8.11.tar.bz2 + tar -C /tmp -jxf dist/fail2ban-0.8.12.tar.bz2 # clean up current direcory - diff -rul --exclude \*.pyc . /tmp/fail2ban-0.8.11/ + diff -rul --exclude \*.pyc . /tmp/fail2ban-0.8.12/ # Only differences should be files that you don't want distributed. # Ensure the tests work from the tarball - cd /tmp/fail2ban-0.8.11/ && ./fail2ban-testcases-all + cd /tmp/fail2ban-0.8.12/ && ./fail2ban-testcases-all # Add/finalize the corresponding entry in the ChangeLog To generate a list of committers use e.g. - git shortlog -sn 0.8.10.. | sed -e 's,^[ 0-9\t]*,,g' | tr '\n' '\|' | sed -e 's:|:, :g' + git shortlog -sn 0.8.11.. | sed -e 's,^[ 0-9\t]*,,g' | tr '\n' '\|' | sed -e 's:|:, :g' Ensure the top of the ChangeLog has the right version and current date. @@ -857,7 +857,7 @@ Post Release Add the following to the top of the ChangeLog -ver. 0.8.12 (2013/XX/XXX) - wanna-be-released +ver. 0.8.13 (2014/XX/XXX) - wanna-be-released ----------- - Fixes: diff --git a/common/version.py b/common/version.py index c699a8db..eec5e794 100644 --- a/common/version.py +++ b/common/version.py @@ -24,4 +24,4 @@ __author__ = "Cyril Jaquier, Yaroslav Halchenko" __copyright__ = "Copyright (c) 2004 Cyril Jaquier, 2011-2013 Yaroslav Halchenko" __license__ = "GPL" -version = "0.8.11" +version = "0.8.11.dev" From a7604c899fba5835891c7650939c0b0e0ed7293e Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 13 Nov 2013 09:43:36 +1100 Subject: [PATCH 036/125] DOC: list Wiki pages to update after a release --- DEVELOP | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/DEVELOP b/DEVELOP index 500f119f..3766d192 100644 --- a/DEVELOP +++ b/DEVELOP @@ -839,10 +839,15 @@ Which indicates that testcases/files/logs/mysqld.log has been moved or is a dire page: http://www.fail2ban.org/wiki/index.php/Commands * Update: - http://www.fail2ban.org/wiki/index.php/Downloads + http://www.fail2ban.org/wiki/index.php?title=Template:Fail2ban_Versions&action=edit + + http://www.fail2ban.org/wiki/index.php?title=Template:Fail2ban_News&action=edit + move old bits to: + http://www.fail2ban.org/wiki/index.php?title=Template:Fail2ban_OldNews&action=edit + + http://www.fail2ban.org/wiki/index.php?title=Template:Fail2ban_Versions&action=edit http://www.fail2ban.org/wiki/index.php/ChangeLog http://www.fail2ban.org/wiki/index.php/Requirements (Check requirement) - http://www.fail2ban.org/wiki/index.php/Main_Page (Add to News) http://www.fail2ban.org/wiki/index.php/Features * See if any filters are upgraded: From ed212fcdccd155ef3cb9b053082c1b843d14fc0f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 16 Nov 2013 09:40:05 +1100 Subject: [PATCH 037/125] DOC: new ChangeLog header --- ChangeLog | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index e901d9af..98792d9e 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,9 +4,21 @@ |_| \__,_|_|_/___|_.__/\__,_|_||_| ================================================================================ -Fail2Ban (version 0.8.11) 2013/11/13 +Fail2Ban (version 0.8.12.dev) 2013/11/13 ================================================================================ +ver. 0.8.12 (2013/12/XX) - things-can-only-get-better +----------- + +- IMPORTANT incompatible changes: + +- Fixes: + +- New Features: + +- Enhancements: + + ver. 0.8.11 (2013/11/13) - loves-unittests-and-tight-DoS-free-filter-regexes ----------- From 88eff70774fe96a5f241ae3d5365f504a3df4c8b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 16 Nov 2013 09:43:15 +1100 Subject: [PATCH 038/125] ENH: filter.d/solid-pop3d added --- ChangeLog | 3 +++ THANKS | 1 + config/filter.d/solid-pop3d.conf | 18 ++++++++++++++++++ testcases/files/logs/solid-pop3d | 2 ++ 4 files changed, 24 insertions(+) create mode 100644 config/filter.d/solid-pop3d.conf create mode 100644 testcases/files/logs/solid-pop3d diff --git a/ChangeLog b/ChangeLog index 98792d9e..b93a1c31 100644 --- a/ChangeLog +++ b/ChangeLog @@ -16,6 +16,9 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - New Features: + Daniel Black + * filter.d/solid-pop3d -- added thanks to Jacques Lav!gnotte on mailinglist. + - Enhancements: diff --git a/THANKS b/THANKS index 13303c21..ee3922dd 100644 --- a/THANKS +++ b/THANKS @@ -33,6 +33,7 @@ Georgiy Mernov Guillaume Delvit Hanno 'Rince' Wagner Iain Lea +Jacques Lav!gnotte Jonathan Kamens Jonathan Lanning Jonathan Underwood diff --git a/config/filter.d/solid-pop3d.conf b/config/filter.d/solid-pop3d.conf new file mode 100644 index 00000000..67deafb6 --- /dev/null +++ b/config/filter.d/solid-pop3d.conf @@ -0,0 +1,18 @@ +# Fail2Ban filter for unsuccesful solid-pop3 authentication attempts +# +# +[INCLUDES] + +before = common.conf + +[Definition] + +_daemon = solid-pop3d + +failregex = ^%(__prefix_line)sauthentication failed: no such user: .*? - $ + +ignoreregex = + +# DEV Notes: +# +# Authors: Daniel Black diff --git a/testcases/files/logs/solid-pop3d b/testcases/files/logs/solid-pop3d new file mode 100644 index 00000000..0574084d --- /dev/null +++ b/testcases/files/logs/solid-pop3d @@ -0,0 +1,2 @@ +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: authentication failed: no such user: adrian - 123.33.44.45 From d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sat, 16 Nov 2013 22:15:27 -0500 Subject: [PATCH 039/125] ENH: adding custom date format for proftpd when logging in its own log file (default on Debian) -- includes milliseconds Should resolve Debian #648276 --- server/datedetector.py | 7 +++++++ testcases/datedetectortestcase.py | 1 + testcases/files/logs/proftpd | 2 ++ 3 files changed, 10 insertions(+) diff --git a/server/datedetector.py b/server/datedetector.py index ab2dd174..b12a8d46 100644 --- a/server/datedetector.py +++ b/server/datedetector.py @@ -101,6 +101,13 @@ class DateDetector: template.setRegex("\d{2}/\d{2}/\d{4}:\d{2}:\d{2}:\d{2}") template.setPattern("%m/%d/%Y:%H:%M:%S") self._appendTemplate(template) + # proftpd 2013-11-16 21:43:03,296 + # So like Exim below but with ,subsecond + template = DateStrptime() + template.setName("Year-Month-Day Hour:Minute:Second[,subsecond]") + template.setRegex("\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d+") + template.setPattern("%Y-%m-%d %H:%M:%S,%f") + self._appendTemplate(template) # Exim 2006-12-21 06:43:20 template = DateStrptime() template.setName("Year-Month-Day Hour:Minute:Second") diff --git a/testcases/datedetectortestcase.py b/testcases/datedetectortestcase.py index de324aa6..4cc7dcfc 100644 --- a/testcases/datedetectortestcase.py +++ b/testcases/datedetectortestcase.py @@ -74,6 +74,7 @@ class DateDetectorTest(unittest.TestCase): (False, "23/Jan/2005:21:59:59"), (False, "01/23/2005:21:59:59"), (False, "2005-01-23 21:59:59"), + (False, "2005-01-23 21:59:59,099"), # proftpd (False, "23-Jan-2005 21:59:59"), (False, "23-01-2005 21:59:59"), (False, "01-23-2005 21:59:59.252"), # reported on f2b, causes Feb29 fix to break diff --git a/testcases/files/logs/proftpd b/testcases/files/logs/proftpd index 9687d992..b255e91e 100644 --- a/testcases/files/logs/proftpd +++ b/testcases/files/logs/proftpd @@ -14,3 +14,5 @@ Jun 14 00:09:59 platypus.ace-hosting.com.au proftpd[17839] platypus.ace-hosting. May 31 10:53:25 mail proftpd[15302]: xxxxxxxxxx (::ffff:1.2.3.4[::ffff:1.2.3.4]) - Maximum login attempts (3) exceeded # failJSON: { "time": "2004-12-05T15:44:32", "match": true , "host": "1.2.3.4" } Dec 5 15:44:32 serv1 proftpd[70944]: serv1.domain.com (example.com[1.2.3.4]) - USER jtittle@domain.org: no such user found from example.com [1.2.3.4] to 1.2.3.4:21 +# failJSON: { "time": "2013-11-16T21:59:30", "match": true , "host": "1.2.3.4", "desc": "proftpd-basic 1.3.5~rc3-2.1 on Debian uses date format with milliseconds if logging under /var/log/proftpd/proftpd.log" } +2013-11-16 21:59:30,121 novo proftpd[25891] localhost (andy[1.2.3.4]): USER kjsad: no such user found from andy [1.2.3.5] to ::ffff:192.168.1.14:21 From 82174ea4c4521731f3cb88cd84adfb261a8c74a0 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sat, 16 Nov 2013 22:18:51 -0500 Subject: [PATCH 040/125] Changelog for preceding proftpd date format change --- ChangeLog | 1 + 1 file changed, 1 insertion(+) diff --git a/ChangeLog b/ChangeLog index 98792d9e..2369bc21 100644 --- a/ChangeLog +++ b/ChangeLog @@ -13,6 +13,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - IMPORTANT incompatible changes: - Fixes: + - allow for ",milliseconds" in the custom date format of proftpd.log - New Features: From b3b9ea45597e4f8484afbefc6e0887617b61df82 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 18 Nov 2013 07:42:45 +1100 Subject: [PATCH 041/125] ENH: jail for solid-pop3d --- config/jail.conf | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/config/jail.conf b/config/jail.conf index 486ea078..0de7f524 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -518,6 +518,14 @@ action = iptables-multiport[name=dovecot-auth, port="pop3,pop3s,imap,imaps,subm logpath = /var/log/secure +[solid-pop3d] + +enabled = false +filter = solid-pop3d +action = iptables-multiport[name=solid-pop3, port="pop3,pop3s", protocol=tcp] +logpath = /var/log/mail.log + + [selinux-ssh] enabled = false filter = selinux-ssh From dab2ddb9dad9c1c9061bc40589d56ecb5368787b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 18 Nov 2013 07:57:16 +1100 Subject: [PATCH 042/125] ENH: recidive jail to block all protocols. Closes #440 --- ChangeLog | 1 + config/jail.conf | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 2369bc21..2e1a5b91 100644 --- a/ChangeLog +++ b/ChangeLog @@ -14,6 +14,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - Fixes: - allow for ",milliseconds" in the custom date format of proftpd.log + - recidive jail to block all protocols. Closes gh-440 - New Features: diff --git a/config/jail.conf b/config/jail.conf index 486ea078..e9ca3313 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -408,7 +408,7 @@ maxretry = 5 enabled = false filter = recidive logpath = /var/log/fail2ban.log -action = iptables-allports[name=recidive] +action = iptables-allports[name=recidive,protocol=all] sendmail-whois-lines[name=recidive, logpath=/var/log/fail2ban.log] bantime = 604800 ; 1 week findtime = 86400 ; 1 day From 8aa20a7b0efdb8020e59db0f423d8382cf4d8d05 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 18 Nov 2013 07:59:56 +1100 Subject: [PATCH 043/125] ENH: credits for #440 recidive jail protocol=all --- ChangeLog | 2 +- THANKS | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 2e1a5b91..dfecbc51 100644 --- a/ChangeLog +++ b/ChangeLog @@ -14,7 +14,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - Fixes: - allow for ",milliseconds" in the custom date format of proftpd.log - - recidive jail to block all protocols. Closes gh-440 + - recidive jail to block all protocols. Closes gh-440. Thanks Ioan Indreias - New Features: diff --git a/THANKS b/THANKS index 13303c21..ac2f4439 100644 --- a/THANKS +++ b/THANKS @@ -33,6 +33,7 @@ Georgiy Mernov Guillaume Delvit Hanno 'Rince' Wagner Iain Lea +Ioan Indreias Jonathan Kamens Jonathan Lanning Jonathan Underwood From 0eea0a35db8061d51c35cba7bed7911ed822ca38 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 18 Nov 2013 08:58:23 +1100 Subject: [PATCH 044/125] ENH: filter.d/solid-pop3d - added log messages and regexes --- config/filter.d/solid-pop3d.conf | 13 ++++++++++++- testcases/files/logs/solid-pop3d | 20 ++++++++++++++++++++ 2 files changed, 32 insertions(+), 1 deletion(-) diff --git a/config/filter.d/solid-pop3d.conf b/config/filter.d/solid-pop3d.conf index 67deafb6..68ac0a8e 100644 --- a/config/filter.d/solid-pop3d.conf +++ b/config/filter.d/solid-pop3d.conf @@ -1,5 +1,7 @@ # Fail2Ban filter for unsuccesful solid-pop3 authentication attempts # +# Doesn't currently provide PAM support. Please contribute sample logs +# to http://github.com/fail2ban/fail2ban/issues. # [INCLUDES] @@ -9,10 +11,19 @@ before = common.conf _daemon = solid-pop3d -failregex = ^%(__prefix_line)sauthentication failed: no such user: .*? - $ +failregex = ^%(__prefix_line)sauthentication failed: (no such user|can't map user name): .*? - $ + ^%(__prefix_line)s(APOP )?authentication failed for (mapped )?user .*? - $ + ^%(__prefix_line)sroot login not allowed - $ + ^%(__prefix_line)scan't find APOP secret for user .*? - $ ignoreregex = # DEV Notes: # +# solid-pop3d needs to be compiled with --enable-logextend to support +# IP addresses in log messages. +# +# solid-pop3d-0.15/src/main.c contains all authentication errors +# except for PAM authentication messages ( src/authenticate.c ) +# # Authors: Daniel Black diff --git a/testcases/files/logs/solid-pop3d b/testcases/files/logs/solid-pop3d index 0574084d..3fe27e58 100644 --- a/testcases/files/logs/solid-pop3d +++ b/testcases/files/logs/solid-pop3d @@ -1,2 +1,22 @@ # failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: authentication failed: no such user: adrian - 123.33.44.45 + +# All below are manufactured from looking at log +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: authentication failed: can't map user name: adrian - 123.33.44.45 + +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: authentication failed for user adrain - 123.33.44.45 + +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: authentication failed for mapped user adrain - 123.33.44.45 + +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: root login not allowed - 123.33.44.45 + +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: can't find APOP secret for user adrian - 123.33.44.45 + +# failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } +Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: APOP authentication failed for user adrian - 123.33.44.45 + From 1ea68b2d0c5415709cebec0edd6dbca85e15be5c Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 18 Nov 2013 09:44:26 +1100 Subject: [PATCH 045/125] DOC: filter.d/solid-pop3d - document lack of PAM support. Thanks to Jacques for the log messages --- config/filter.d/solid-pop3d.conf | 7 +++++-- testcases/files/logs/solid-pop3d | 3 +++ 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/config/filter.d/solid-pop3d.conf b/config/filter.d/solid-pop3d.conf index 68ac0a8e..d97cc134 100644 --- a/config/filter.d/solid-pop3d.conf +++ b/config/filter.d/solid-pop3d.conf @@ -1,7 +1,7 @@ # Fail2Ban filter for unsuccesful solid-pop3 authentication attempts # -# Doesn't currently provide PAM support. Please contribute sample logs -# to http://github.com/fail2ban/fail2ban/issues. +# Doesn't currently provide PAM support as PAM log messages don't include rhost as +# remote IP. # [INCLUDES] @@ -25,5 +25,8 @@ ignoreregex = # # solid-pop3d-0.15/src/main.c contains all authentication errors # except for PAM authentication messages ( src/authenticate.c ) +# +# A pam authentication failure message (note no IP for rhost). +# Nov 17 23:17:50 emf1pt2-2-35-70 solid-pop3d[17176]: pam_unix(solid-pop3d:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=jacques # # Authors: Daniel Black diff --git a/testcases/files/logs/solid-pop3d b/testcases/files/logs/solid-pop3d index 3fe27e58..45c4ecaf 100644 --- a/testcases/files/logs/solid-pop3d +++ b/testcases/files/logs/solid-pop3d @@ -20,3 +20,6 @@ Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: can't find APOP secret for us # failJSON: { "time": "2004-11-15T00:34:53", "match": true , "host": "123.33.44.45" } Nov 15 00:34:53 rmc1pt2-2-35-70 solid-pop3d[3822]: APOP authentication failed for user adrian - 123.33.44.45 +# Real log messages again: +# failJSON: { "time": "2004-11-17T23:10:03", "match": true , "host": "190.16.165.230" } +Nov 17 23:10:03 emf1pt2-2-35-70 solid-pop3d[16993]: authentication failed for user jacques - 190.16.165.230 From 284f811c912af2f683c7eb150011337912516934 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 19 Nov 2013 10:27:55 +1100 Subject: [PATCH 046/125] BF: apache filters using error log weren't matched when referer existed in HTTP header --- ChangeLog | 1 + THANKS | 1 + config/filter.d/apache-auth.conf | 26 ++++++++++++++------------ config/filter.d/apache-noscript.conf | 4 ++-- config/filter.d/apache-overflows.conf | 2 +- testcases/files/logs/apache-auth | 3 +++ 6 files changed, 22 insertions(+), 15 deletions(-) diff --git a/ChangeLog b/ChangeLog index 2369bc21..4eb8968c 100644 --- a/ChangeLog +++ b/ChangeLog @@ -14,6 +14,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - Fixes: - allow for ",milliseconds" in the custom date format of proftpd.log + - allow for ", referer ..." in apache-* filter for apache error logs. - New Features: diff --git a/THANKS b/THANKS index 13303c21..45528bc7 100644 --- a/THANKS +++ b/THANKS @@ -70,6 +70,7 @@ Tyler Vaclav Misek Vincent Deffontaines Yaroslav Halchenko +Winston Smith ykimon Yehuda Katz zugeschmiert diff --git a/config/filter.d/apache-auth.conf b/config/filter.d/apache-auth.conf index 3df91c15..f4213487 100644 --- a/config/filter.d/apache-auth.conf +++ b/config/filter.d/apache-auth.conf @@ -10,19 +10,19 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s (AH01797: )?client denied by server configuration: (uri )?\S*\s*$ - ^%(_apache_error_client)s (AH01617: )?user .* authentication failure for "\S*": Password Mismatch$ - ^%(_apache_error_client)s (AH01618: )?user .* not found(: )?\S*\s*$ - ^%(_apache_error_client)s (AH01614: )?client used wrong authentication scheme: \S*\s*$ +failregex = ^%(_apache_error_client)s (AH01797: )?client denied by server configuration: (uri )?\S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01617: )?user .*? authentication failure for "\S*": Password Mismatch(, referer: \S+)?$ + ^%(_apache_error_client)s (AH01618: )?user .*? not found(: )?\S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01614: )?client used wrong authentication scheme: \S*(, referer: \S+)?\s*$ ^%(_apache_error_client)s (AH\d+: )?Authorization of user \S+ to access \S* failed, reason: .*$ - ^%(_apache_error_client)s (AH0179[24]: )?(Digest: )?user .*: password mismatch: \S*\s*$ - ^%(_apache_error_client)s (AH0179[01]: |Digest: )user `.*' in realm `.+' (not found|denied by provider): \S*\s*$ - ^%(_apache_error_client)s (AH01631: )?user .*: authorization failure for "\S*":\s*$ - ^%(_apache_error_client)s (AH01775: )?(Digest: )?invalid nonce .* received - length is not \S+\s*$ - ^%(_apache_error_client)s (AH01788: )?(Digest: )?realm mismatch - got `.*' but expected `.+'\s*$ - ^%(_apache_error_client)s (AH01789: )?(Digest: )?unknown algorithm `.*' received: \S*\s*$ - ^%(_apache_error_client)s (AH01793: )?invalid qop `.*' received: \S*\s*$ - ^%(_apache_error_client)s (AH01777: )?(Digest: )?invalid nonce .* received - user attempted time travel\s*$ + ^%(_apache_error_client)s (AH0179[24]: )?(Digest: )?user .*?: password mismatch: \S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH0179[01]: |Digest: )user `.*?' in realm `.+' (not found|denied by provider): \S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01631: )?user .*?: authorization failure for "\S*":(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01775: )?(Digest: )?invalid nonce .* received - length is not \S+(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01788: )?(Digest: )?realm mismatch - got `.*?' but expected `.+'(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01789: )?(Digest: )?unknown algorithm `.*?' received: \S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01793: )?invalid qop `.*?' received: \S*(, referer: \S+)?\s*$ + ^%(_apache_error_client)s (AH01777: )?(Digest: )?invalid nonce .*? received - user attempted time travel(, referer: \S+)?\s*$ ignoreregex = @@ -50,5 +50,7 @@ ignoreregex = # ^%(_apache_error_client)s (AH01779: )?user .*: one-time-nonce mismatch - sending new nonce\s*$ # ^%(_apache_error_client)s (AH02486: )?realm mismatch - got `.*' but no realm specified\s*$ # +# referer is always in error log messages if it exists added as per the log_error_core function in server/log.c +# # Author: Cyril Jaquier # Major edits by Daniel Black diff --git a/config/filter.d/apache-noscript.conf b/config/filter.d/apache-noscript.conf index f3c6246a..7ea257b2 100644 --- a/config/filter.d/apache-noscript.conf +++ b/config/filter.d/apache-noscript.conf @@ -9,8 +9,8 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s ((AH001(28|30): )?File does not exist|(AH01264: )?script not found or unable to stat): /\S*(\.php|\.asp|\.exe|\.pl)\s*$ - ^%(_apache_error_client)s script '/\S*(\.php|\.asp|\.exe|\.pl)\S*' not found or unable to stat\s*$ +failregex = ^%(_apache_error_client)s ((AH001(28|30): )?File does not exist|(AH01264: )?script not found or unable to stat): /\S*(\.php|\.asp|\.exe|\.pl)(, referer: \S+)?\s*$ + ^%(_apache_error_client)s script '/\S*(\.php|\.asp|\.exe|\.pl)\S*' not found or unable to stat(, referer: \S+)?\s*$ ignoreregex = diff --git a/config/filter.d/apache-overflows.conf b/config/filter.d/apache-overflows.conf index 92551525..74e44b8e 100644 --- a/config/filter.d/apache-overflows.conf +++ b/config/filter.d/apache-overflows.conf @@ -8,7 +8,7 @@ before = apache-common.conf [Definition] -failregex = ^%(_apache_error_client)s ((AH0013[456]: )?Invalid (method|URI) in request .*( - possible attempt to establish SSL connection on non-SSL port)?|(AH00565: )?request failed: URI too long \(longer than \d+\)|request failed: erroneous characters after protocol string: .*|AH00566: request failed: invalid characters in URI)$ +failregex = ^%(_apache_error_client)s ((AH0013[456]: )?Invalid (method|URI) in request .*( - possible attempt to establish SSL connection on non-SSL port)?|(AH00565: )?request failed: URI too long \(longer than \d+\)|request failed: erroneous characters after protocol string: .*|AH00566: request failed: invalid characters in URI)(, referer: \S+)?$ ignoreregex = diff --git a/testcases/files/logs/apache-auth b/testcases/files/logs/apache-auth index d6c40ac5..787d160a 100644 --- a/testcases/files/logs/apache-auth +++ b/testcases/files/logs/apache-auth @@ -115,3 +115,6 @@ # failJSON: { "time": "2013-06-01T02:17:42", "match": true , "host": "192.168.0.2" } [Sat Jun 01 02:17:42 2013] [error] [client 192.168.0.2] user root not found + +# failJSON: { "time": "2013-11-18T22:39:33", "match": true , "host": "91.49.82.139" } +[Mon Nov 18 22:39:33 2013] [error] [client 91.49.82.139] user gg not found: /, referer: http://sj.hopto.org/management.html From 015b403df07b4bcafa367e1b8b04611aa988a9a0 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 20 Nov 2013 10:01:06 +1100 Subject: [PATCH 047/125] TST: more test cases for suhosin --- testcases/files/logs/suhosin | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/testcases/files/logs/suhosin b/testcases/files/logs/suhosin index 90ed7bf1..a9b0002a 100644 --- a/testcases/files/logs/suhosin +++ b/testcases/files/logs/suhosin @@ -2,3 +2,9 @@ Mar 11 22:52:12 lighttpd[53690]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - configured request variable name length limit exceeded - dropped variable 'upqchi07vFfAFuBjnIKGIwiLrHo3Vt68T3yqvhQu2TqetQ78roy7Q6bpTfDUtYFR593/MA' (attacker '198.51.100.167', file '/usr/local/captiveportal/index.php') # failJSON: { "time": "2005-02-26T22:52:29", "match": true , "host": "198.51.100.77" } Feb 26 22:52:29 host suhosin[9636]: ALERT - script tried to increase memory_limit to 268435456 bytes which is above the allowed value (attacker '198.51.100.77', file '/var/www/wordpress/wp-admin/includes/image.php', line 161) + +# failJSON: { "time": "2004-11-18T20:18:31", "match": true , "host": "188.132.244.3" } +Nov 18 20:18:31 platypus suhosin[28433]: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'templatefile' (attacker '188.132.244.3', file '/home/ace-hosting/public_html/cart.php') + +# failJSON: { "time": "2004-10-25T10:59:49", "match": true , "host": "38.111.147.83" } +Oct 25 10:59:49 platypus suhosin[13953]: ALERT - configured GET variable value length limit exceeded - dropped variable '_route_' (attacker '38.111.147.83', file '/home/thegoblin/public_html/index.php') From 28d8aec511a96470db3816aa0ba9d35b3c5f6239 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 21 Nov 2013 07:05:21 +1100 Subject: [PATCH 048/125] DOC: Arch Linux link --- DEVELOP | 2 ++ 1 file changed, 2 insertions(+) diff --git a/DEVELOP b/DEVELOP index 3766d192..40182ff9 100644 --- a/DEVELOP +++ b/DEVELOP @@ -805,6 +805,8 @@ Which indicates that testcases/files/logs/mysqld.log has been moved or is a dire # Provide a release sample to distributors + * Arch Linux: + https://www.archlinux.org/packages/community/any/fail2ban/ * Debian: Yaroslav Halchenko http://packages.qa.debian.org/f/fail2ban.html * FreeBSD: Christoph Theis theis@gmx.at>, Nick Hilliard From d34d8db3d2bf361853cf7f9fa8b2cd3ca0edc707 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Fri, 22 Nov 2013 15:57:03 -0500 Subject: [PATCH 049/125] BF/ENH: include [PID] into logging msgs, remove indentation from syslog messages Otherwise leads to incorrect parsing of the log messages by syslog(-ng). See http://bugs.debian.org/730202 I also removed %(levelname)-6s from syslog messages completely since they are passed to the syslog and it is up to the configuration/admin to decide include levels into the messages or not (I have checked that at least debug level indeed goes to /var/log/debug) --- server/server.py | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/server/server.py b/server/server.py index 773fdf0b..44d8ae68 100644 --- a/server/server.py +++ b/server/server.py @@ -347,13 +347,12 @@ class Server: try: self.__loggingLock.acquire() # set a format which is simpler for console use - formatter = logging.Formatter("%(asctime)s %(name)-16s: %(levelname)-6s %(message)s") + formatter = logging.Formatter("%(name)s[%(process)d]: %(levelname)-7s %(message)s") if target == "SYSLOG": # Syslog daemons already add date to the message. - formatter = logging.Formatter("%(name)-16s: %(levelname)-6s %(message)s") + formatter = logging.Formatter("%(name)s[%(process)d]: %(message)s") facility = logging.handlers.SysLogHandler.LOG_DAEMON - hdlr = logging.handlers.SysLogHandler("/dev/log", - facility = facility) + hdlr = logging.handlers.SysLogHandler("/dev/log", facility=facility) elif target == "STDOUT": hdlr = logging.StreamHandler(sys.stdout) elif target == "STDERR": From f2c529ca7ba558e44f3f0177cea96c70c0e70d4f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 23 Nov 2013 11:33:41 +1100 Subject: [PATCH 050/125] ENH: move signal.signal(signal.SIGHUP, signal.SIG_IGN) before fork in server. closes #446 --- server/server.py | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/server/server.py b/server/server.py index 773fdf0b..f5dbc3c8 100644 --- a/server/server.py +++ b/server/server.py @@ -409,6 +409,14 @@ class Server: http://aspn.activestate.com/ASPN/Cookbook/Python/Recipe/278731 """ + # When the first child terminates, all processes in the second child + # are sent a SIGHUP, so it's ignored. + + # We need to set this in the parent process, so it gets inherited by the + # child process, and this makes sure that it is effect even if the parent + # terminates quickly. + signal.signal(signal.SIGHUP, signal.SIG_IGN) + try: # Fork a child process so the parent can exit. This will return control # to the command line or shell. This is required so that the new process @@ -431,10 +439,6 @@ class Server: # leader. os.setsid() - # When the first child terminates, all processes in the second child - # are sent a SIGHUP, so it's ignored. - signal.signal(signal.SIGHUP, signal.SIG_IGN) - try: # Fork a second child to prevent zombies. Since the first child is # a session leader without a controlling terminal, it's possible for From 9a82bc3c617c488dd376571370d08b05bf1954af Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sun, 24 Nov 2013 18:21:02 +1100 Subject: [PATCH 051/125] BF: kernel messages can have space. Thanks ag4ve(shawn). Closes #448 --- ChangeLog | 1 + THANKS | 1 + config/filter.d/common.conf | 2 +- 3 files changed, 3 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 24f01e9a..6636ef76 100644 --- a/ChangeLog +++ b/ChangeLog @@ -15,6 +15,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - Fixes: - allow for ",milliseconds" in the custom date format of proftpd.log - allow for ", referer ..." in apache-* filter for apache error logs. + - allow for spaces at the beginning of kernel messages. Closes gh-448 - New Features: diff --git a/THANKS b/THANKS index 46c7bc5e..e71eefea 100644 --- a/THANKS +++ b/THANKS @@ -8,6 +8,7 @@ be added Adrien Clerc ache +ag4ve (Shawn) Amir Caspi Andrey G. Grozin Andy Fragen diff --git a/config/filter.d/common.conf b/config/filter.d/common.conf index b992e4b8..ae8e8b7b 100644 --- a/config/filter.d/common.conf +++ b/config/filter.d/common.conf @@ -34,7 +34,7 @@ __daemon_combs_re = (?:%(__pid_re)s?:\s+%(__daemon_re)s|%(__daemon_re)s%(__pid_r # Some messages have a kernel prefix with a timestamp # EXAMPLES: kernel: [769570.846956] -__kernel_prefix = kernel: \[\d+\.\d+\] +__kernel_prefix = kernel: \[ *\d+\.\d+\] __hostname = \S+ From a989787e0dace5b609028b95526c1eb212e1ebef Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sun, 24 Nov 2013 18:43:23 +1100 Subject: [PATCH 052/125] DOC: more distro bug tracker urls --- DEVELOP | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/DEVELOP b/DEVELOP index 40182ff9..3939fe47 100644 --- a/DEVELOP +++ b/DEVELOP @@ -743,10 +743,14 @@ Releasing * https://github.com/fail2ban/fail2ban/issues?sort=updated&state=open * http://bugs.debian.org/cgi-bin/pkgreport.cgi?dist=unstable;package=fail2ban + * https://bugs.launchpad.net/ubuntu/+source/fail2ban * http://bugs.sabayon.org/buglist.cgi?quicksearch=net-analyzer%2Ffail2ban + * https://bugs.archlinux.org/?project=5&cat%5B%5D=33&string=fail2ban * https://bugs.gentoo.org/buglist.cgi?query_format=advanced&short_desc=fail2ban&bug_status=UNCONFIRMED&bug_status=CONFIRMED&bug_status=IN_PROGRESS&short_desc_type=allwords * https://bugzilla.redhat.com/buglist.cgi?query_format=advanced&bug_status=NEW&bug_status=ASSIGNED&component=fail2ban&classification=Red%20Hat&classification=Fedora * http://www.freebsd.org/cgi/query-pr-summary.cgi?text=fail2ban + * https://bugs.mageia.org/buglist.cgi?quicksearch=fail2ban + * https://build.opensuse.org/package/requests/openSUSE:Factory/fail2ban # Make sure the tests pass From a6f085786ca46485557c0adbe6b6510f1a06253b Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sun, 24 Nov 2013 09:50:39 -0500 Subject: [PATCH 053/125] ENH: reintroducing levelnameinto syslog msgs, time stamp and indentation in non-syslog msgs any indentation from syslog msgs wsa removed -- no need --- server/server.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/server/server.py b/server/server.py index 44d8ae68..6ac93a54 100644 --- a/server/server.py +++ b/server/server.py @@ -347,10 +347,10 @@ class Server: try: self.__loggingLock.acquire() # set a format which is simpler for console use - formatter = logging.Formatter("%(name)s[%(process)d]: %(levelname)-7s %(message)s") + formatter = logging.Formatter("%(asctime)s %(name)-16s[%(process)d]: %(levelname)-7s %(message)s") if target == "SYSLOG": # Syslog daemons already add date to the message. - formatter = logging.Formatter("%(name)s[%(process)d]: %(message)s") + formatter = logging.Formatter("%(name)s[%(process)d]: %(levelname)s %(message)s") facility = logging.handlers.SysLogHandler.LOG_DAEMON hdlr = logging.handlers.SysLogHandler("/dev/log", facility=facility) elif target == "STDOUT": From a26d4f42b7b4b3a7359e64eba4d5997eef25db46 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sun, 24 Nov 2013 09:59:45 -0500 Subject: [PATCH 054/125] ENH: added optional [PID] matching in recidive.conf --- config/filter.d/recidive.conf | 2 +- testcases/files/logs/recidive | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/config/filter.d/recidive.conf b/config/filter.d/recidive.conf index b29acaf3..13d2f53a 100644 --- a/config/filter.d/recidive.conf +++ b/config/filter.d/recidive.conf @@ -27,6 +27,6 @@ _daemon = fail2ban\.actions # jail using this filter 'recidive', or change this line! _jailname = recidive -failregex = ^(%(__prefix_line)s|,\d{3} fail2ban.actions:\s+)WARNING\s+\[(?!%(_jailname)s\])(?:.*)\]\s+Ban\s+\s*$ +failregex = ^(%(__prefix_line)s|,\d{3} fail2ban.actions%(__pid_re)s?:\s+)WARNING\s+\[(?!%(_jailname)s\])(?:.*)\]\s+Ban\s+\s*$ # Author: Tom Hendrikx, modifications by Amir Caspi diff --git a/testcases/files/logs/recidive b/testcases/files/logs/recidive index 6af85137..83acc3e1 100644 --- a/testcases/files/logs/recidive +++ b/testcases/files/logs/recidive @@ -1,5 +1,7 @@ # failJSON: { "time": "2006-02-13T15:52:30", "match": true , "host": "1.2.3.4" } 2006-02-13 15:52:30,388 fail2ban.actions: WARNING [sendmail] Ban 1.2.3.4 +# failJSON: { "time": "2006-02-13T15:52:30", "match": true , "host": "1.2.3.4", "desc": "Extended with [PID]" } +2006-02-13 15:52:30,388 fail2ban.actions[123]: WARNING [sendmail] Ban 1.2.3.4 # failJSON: { "match": false } 2006-02-13 16:07:31,183 fail2ban.actions: WARNING [sendmail] Unban 1.2.3.4 # failJSON: { "match": false } From 085ebbe1de7477733b28e06204ccbb19ea2c3d09 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sun, 24 Nov 2013 11:55:58 -0500 Subject: [PATCH 055/125] Changelog entries for the last changes --- ChangeLog | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ChangeLog b/ChangeLog index 24f01e9a..a26257f1 100644 --- a/ChangeLog +++ b/ChangeLog @@ -15,6 +15,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - Fixes: - allow for ",milliseconds" in the custom date format of proftpd.log - allow for ", referer ..." in apache-* filter for apache error logs. + - remove indentation of name and loglevel while logging to SYSLOG to + resolve syslog(-ng) parsing problems. Closes Debian bug #730202. - New Features: @@ -22,6 +24,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better * filter.d/solid-pop3d -- added thanks to Jacques Lav!gnotte on mailinglist. - Enhancements: + - loglines now also report "[PID]" after the name portion ver. 0.8.11 (2013/11/13) - loves-unittests-and-tight-DoS-free-filter-regexes From 093aee967622216c5d2d4023fb9842388f87c3b1 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 25 Nov 2013 07:54:49 +1100 Subject: [PATCH 056/125] TST: no python-2.5 any more - https://github.com/travis-ci/travis-ci/issues/1668 --- .travis.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.travis.yml b/.travis.yml index 2d091754..d693f975 100644 --- a/.travis.yml +++ b/.travis.yml @@ -2,7 +2,6 @@ # travis-ci.org definition for Fail2Ban build language: python python: - - "2.5" - "2.6" - "2.7" before_install: From dc154c792e6d09abe3592e1321581f9103dd47fe Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 25 Nov 2013 08:08:20 +1100 Subject: [PATCH 057/125] BF: add init section with name for action.d/apf. Closes #398 --- config/action.d/apf.conf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/config/action.d/apf.conf b/config/action.d/apf.conf index 9af3066d..f1d54dd2 100644 --- a/config/action.d/apf.conf +++ b/config/action.d/apf.conf @@ -41,3 +41,10 @@ actionban = apf --deny "banned by Fail2Ban " # Values: CMD # actionunban = apf --remove + +[Init] + +# Name used in APF configuration +# +name = default + From 99838440c8a7cb8c55d2479f6bf5fa32c8fc3640 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 28 Nov 2013 23:18:34 +1100 Subject: [PATCH 058/125] DOC: document rational behind 20 character jail name limit --- ChangeLog | 2 ++ server/jail.py | 6 ++++-- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 58f8f84a..e94a1338 100644 --- a/ChangeLog +++ b/ChangeLog @@ -17,6 +17,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - allow for ", referer ..." in apache-* filter for apache error logs. - allow for spaces at the beginning of kernel messages. Closes gh-448 - recidive jail to block all protocols. Closes gh-440. Thanks Ioan Indreias + - long names on jails documented based on iptables limit of 30 less + len("fail2ban-"). - New Features: diff --git a/server/jail.py b/server/jail.py index 5e60ec7f..7ce12e46 100644 --- a/server/jail.py +++ b/server/jail.py @@ -102,9 +102,11 @@ class Jail: self.__filter = FilterPyinotify(self) def setName(self, name): + # 20 based on iptable chain name limit of 30 less len('fail2ban-') if len(name) >= 20: - logSys.warning("Jail name %r might be too long and some commands " - "might not function correctly. Please shorten" + logSys.warning("Jail name %r might be too long and some commands" + " (e.g. iptables) might not function correctly." + " Please shorten" % name) self.__name = name From fb666b69ffff45d8cbd6e381e5ffccfc6419d939 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 28 Nov 2013 23:35:05 +1100 Subject: [PATCH 059/125] BF: firewall-cmd-direct-new was too long. Thanks Joel. --- ChangeLog | 2 + config/action.d/firewall-cmd-direct-new.conf | 52 -------------------- 2 files changed, 2 insertions(+), 52 deletions(-) delete mode 100644 config/action.d/firewall-cmd-direct-new.conf diff --git a/ChangeLog b/ChangeLog index 58f8f84a..7a210b2c 100644 --- a/ChangeLog +++ b/ChangeLog @@ -13,6 +13,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - IMPORTANT incompatible changes: - Fixes: + - Rename firewall-cmd-direct-new to firewall-cmd-new to fit within jail name + name length. As per gh-395 - allow for ",milliseconds" in the custom date format of proftpd.log - allow for ", referer ..." in apache-* filter for apache error logs. - allow for spaces at the beginning of kernel messages. Closes gh-448 diff --git a/config/action.d/firewall-cmd-direct-new.conf b/config/action.d/firewall-cmd-direct-new.conf deleted file mode 100644 index 55b6762d..00000000 --- a/config/action.d/firewall-cmd-direct-new.conf +++ /dev/null @@ -1,52 +0,0 @@ -# Fail2Ban configuration file -# -# Author: Edgar Hoch -# Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. -# It uses "firewall-cmd" instead of "iptables". -# -# Because of the --remove-rules in stop this action requires firewalld-0.3.8+ - -[INCLUDES] - -before = iptables-blocktype.conf - -[Definition] - -actionstart = firewall-cmd --direct --add-chain ipv4 filter fail2ban- - firewall-cmd --direct --add-rule ipv4 filter fail2ban- 1000 -j RETURN - firewall-cmd --direct --add-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- - -actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- - firewall-cmd --direct --remove-rules ipv4 filter fail2ban- - firewall-cmd --direct --remove-chain ipv4 filter fail2ban- - -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'fail2ban-[ \t]' - -actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j - -actionunban = firewall-cmd --direct --remove-rule ipv4 filter fail2ban- 0 -s -j - -[Init] - -# Default name of the chain -# -name = default - -# Option: port -# Notes.: specifies port to monitor -# Values: [ NUM | STRING ] -# -port = ssh - -# Option: protocol -# Notes.: internally used by config reader for interpolations. -# Values: [ tcp | udp | icmp | all ] -# -protocol = tcp - -# Option: chain -# Notes specifies the iptables chain to which the fail2ban rules should be -# added -# Values: [ STRING ] -# -chain = INPUT_direct From 9e538927087d2d7382631063c6423af8a4a6b95e Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 29 Nov 2013 19:26:24 +1100 Subject: [PATCH 060/125] BF: did remove instead of move --- config/action.d/firewalld-cmd-new.conf | 52 ++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 config/action.d/firewalld-cmd-new.conf diff --git a/config/action.d/firewalld-cmd-new.conf b/config/action.d/firewalld-cmd-new.conf new file mode 100644 index 00000000..837352e9 --- /dev/null +++ b/config/action.d/firewalld-cmd-new.conf @@ -0,0 +1,52 @@ +# Fail2Ban configuration file +# +# Author: Edgar Hoch +# Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. +# It uses "firewall-cmd" instead of "iptables". +# +# Because of the --remove-rules in stop this action requires firewalld-0.3.8+ + +[INCLUDES] + +before = iptables-blocktype.conf + +[Definition] + +actionstart = firewall-cmd --direct --add-chain ipv4 filter f2b- + firewall-cmd --direct --add-rule ipv4 filter f2b- 1000 -j RETURN + firewall-cmd --direct --add-rule ipv4 filter 0 -m state --state NEW -p --dport -j f2b- + +actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j f2b- + firewall-cmd --direct --remove-rules ipv4 filter f2b- + firewall-cmd --direct --remove-chain ipv4 filter f2b- + +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'f2b-[ \t]' + +actionban = firewall-cmd --direct --add-rule ipv4 filter f2b- 0 -s -j + +actionunban = firewall-cmd --direct --remove-rule ipv4 filter f2b- 0 -s -j + +[Init] + +# Default name of the chain +# +name = default + +# Option: port +# Notes.: specifies port to monitor +# Values: [ NUM | STRING ] +# +port = ssh + +# Option: protocol +# Notes.: internally used by config reader for interpolations. +# Values: [ tcp | udp | icmp | all ] +# +protocol = tcp + +# Option: chain +# Notes specifies the iptables chain to which the fail2ban rules should be +# added +# Values: [ STRING ] +# +chain = INPUT_direct From cade7463079a9601ffe50036ecd7a6077b2e8c39 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 29 Nov 2013 21:45:11 +1100 Subject: [PATCH 061/125] BF: jail name mysqld-syslog-iptables too long. removed -iptables. Thanks Stefan (#447) --- ChangeLog | 1 + THANKS | 1 + config/jail.conf | 2 +- 3 files changed, 3 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 58f8f84a..02c55bb7 100644 --- a/ChangeLog +++ b/ChangeLog @@ -17,6 +17,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - allow for ", referer ..." in apache-* filter for apache error logs. - allow for spaces at the beginning of kernel messages. Closes gh-448 - recidive jail to block all protocols. Closes gh-440. Thanks Ioan Indreias + - mysqld-syslog-iptables rule was too long. Part of gh-447. - New Features: diff --git a/THANKS b/THANKS index afc72aa3..04c8728d 100644 --- a/THANKS +++ b/THANKS @@ -66,6 +66,7 @@ Russell Odom Sebastian Arcus Sireyessire silviogarbes +Stefan Tatschner Stephen Gildea Steven Hiscocks Tom Pike diff --git a/config/jail.conf b/config/jail.conf index 433170a5..05f4b768 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -389,7 +389,7 @@ logpath = /var/log/mysqld.log maxretry = 5 -[mysqld-syslog-iptables] +[mysqld-syslog] enabled = false filter = mysqld-auth From b9b2ddf99625837ce8b76ab54ae9e2943b3159b2 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 29 Nov 2013 21:47:53 +1100 Subject: [PATCH 062/125] BF: smtps not IANA standard. Closes #447 --- ChangeLog | 2 ++ config/jail.conf | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 58f8f84a..299a89c8 100644 --- a/ChangeLog +++ b/ChangeLog @@ -17,6 +17,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - allow for ", referer ..." in apache-* filter for apache error logs. - allow for spaces at the beginning of kernel messages. Closes gh-448 - recidive jail to block all protocols. Closes gh-440. Thanks Ioan Indreias + - smtps not a IANA standard and has been removed from Arch. Replaced with + 465. Thanks Stefan. Closes gh-447 - New Features: diff --git a/config/jail.conf b/config/jail.conf index 433170a5..481f0880 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -506,7 +506,7 @@ logpath = /var/log/auth.log enabled = false filter = dovecot -action = iptables-multiport[name=dovecot, port="pop3,pop3s,imap,imaps,submission,smtps,sieve", protocol=tcp] +action = iptables-multiport[name=dovecot, port="pop3,pop3s,imap,imaps,submission,465,sieve", protocol=tcp] logpath = /var/log/mail.log @@ -514,7 +514,7 @@ logpath = /var/log/mail.log enabled = false filter = dovecot -action = iptables-multiport[name=dovecot-auth, port="pop3,pop3s,imap,imaps,submission,smtps,sieve", protocol=tcp] +action = iptables-multiport[name=dovecot-auth, port="pop3,pop3s,imap,imaps,submission,465,sieve", protocol=tcp] logpath = /var/log/secure From 86a0a5962a9ed2c8c3c5b4fd7b75adb2c740b803 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 30 Nov 2013 08:05:20 +1100 Subject: [PATCH 063/125] BF: revert to fail2ban- prefix as f2b- was intended for 0.9 --- config/action.d/firewalld-cmd-new.conf | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/config/action.d/firewalld-cmd-new.conf b/config/action.d/firewalld-cmd-new.conf index 837352e9..55b6762d 100644 --- a/config/action.d/firewalld-cmd-new.conf +++ b/config/action.d/firewalld-cmd-new.conf @@ -12,19 +12,19 @@ before = iptables-blocktype.conf [Definition] -actionstart = firewall-cmd --direct --add-chain ipv4 filter f2b- - firewall-cmd --direct --add-rule ipv4 filter f2b- 1000 -j RETURN - firewall-cmd --direct --add-rule ipv4 filter 0 -m state --state NEW -p --dport -j f2b- +actionstart = firewall-cmd --direct --add-chain ipv4 filter fail2ban- + firewall-cmd --direct --add-rule ipv4 filter fail2ban- 1000 -j RETURN + firewall-cmd --direct --add-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- -actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j f2b- - firewall-cmd --direct --remove-rules ipv4 filter f2b- - firewall-cmd --direct --remove-chain ipv4 filter f2b- +actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- + firewall-cmd --direct --remove-rules ipv4 filter fail2ban- + firewall-cmd --direct --remove-chain ipv4 filter fail2ban- -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'f2b-[ \t]' +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'fail2ban-[ \t]' -actionban = firewall-cmd --direct --add-rule ipv4 filter f2b- 0 -s -j +actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j -actionunban = firewall-cmd --direct --remove-rule ipv4 filter f2b- 0 -s -j +actionunban = firewall-cmd --direct --remove-rule ipv4 filter fail2ban- 0 -s -j [Init] From 56b6bf7d25766a47febba1a079629567a63892c7 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 30 Nov 2013 10:30:29 +1100 Subject: [PATCH 064/125] ENH: reduce firewalld-cmd-new -> firewallcmd-new --- config/action.d/{firewalld-cmd-new.conf => firewallcmd-new.conf} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename config/action.d/{firewalld-cmd-new.conf => firewallcmd-new.conf} (100%) diff --git a/config/action.d/firewalld-cmd-new.conf b/config/action.d/firewallcmd-new.conf similarity index 100% rename from config/action.d/firewalld-cmd-new.conf rename to config/action.d/firewallcmd-new.conf From 95845b7b6571cd80385777de6fdd932612165831 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 30 Nov 2013 17:47:10 +1100 Subject: [PATCH 065/125] BF: complain action could match too many IP addresses --- ChangeLog | 1 + config/action.d/complain.conf | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 3cc0f453..12fc70f1 100644 --- a/ChangeLog +++ b/ChangeLog @@ -20,6 +20,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - smtps not a IANA standard and has been removed from Arch. Replaced with 465. Thanks Stefan. Closes gh-447 - mysqld-syslog-iptables rule was too long. Part of gh-447. + - complain action - ensure where not matching other IPs in log sample. - Enhancements: - long names on jails documented based on iptables limit of 30 less diff --git a/config/action.d/complain.conf b/config/action.d/complain.conf index ad14a87e..d1ca25c7 100644 --- a/config/action.d/complain.conf +++ b/config/action.d/complain.conf @@ -58,7 +58,7 @@ actioncheck = actionban = ADDRESSES=`whois | perl -e 'while () { next if /^changed|@(ripe|apnic)\.net/io; $m += (/abuse|trouble:|report|spam|security/io?3:0); if (/([a-z0-9_\-\.+]+@[a-z0-9\-]+(\.[[a-z0-9\-]+)+)/io) { while (s/([a-z0-9_\-\.+]+@[a-z0-9\-]+(\.[[a-z0-9\-]+)+)//io) { if ($m) { $a{lc($1)}=$m } else { $b{lc($1)}=$m } } $m=0 } else { $m && --$m } } if (%%a) {print join(",",keys(%%a))} else {print join(",",keys(%%b))}'` IP= if [ ! -z "$ADDRESSES" ]; then - (printf %%b "\n"; date '+Note: Local timezone is %%z (%%Z)'; grep '' ) | "Abuse from " $ADDRESSES + (printf %%b "\n"; date '+Note: Local timezone is %%z (%%Z)'; grep '[^0-9][^0-9]' ) | "Abuse from " $ADDRESSES fi # Option: actionunban From 0495aa098eefb1ad7111c7f98ee761e8e642c65e Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 30 Nov 2013 18:01:45 +1100 Subject: [PATCH 066/125] BF: grep matches on shouldn't include other IPs --- config/action.d/ipfw.conf | 2 +- config/action.d/mail-whois-lines.conf | 2 +- config/action.d/sendmail-whois-lines.conf | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/config/action.d/ipfw.conf b/config/action.d/ipfw.conf index 09045815..37625209 100644 --- a/config/action.d/ipfw.conf +++ b/config/action.d/ipfw.conf @@ -43,7 +43,7 @@ actionban = ipfw add tcp from to # Tags: See jail.conf(5) man page # Values: CMD # -actionunban = ipfw delete `ipfw list | grep -i | awk '{print $1;}'` +actionunban = ipfw delete `ipfw list | grep -i "[^0-9][^0-9]" | awk '{print $1;}'` [Init] diff --git a/config/action.d/mail-whois-lines.conf b/config/action.d/mail-whois-lines.conf index 758c4eff..6b7b3841 100644 --- a/config/action.d/mail-whois-lines.conf +++ b/config/action.d/mail-whois-lines.conf @@ -42,7 +42,7 @@ actionban = printf %%b "Hi,\n Here are more information about :\n `whois `\n\n Lines containing IP: in \n - `grep '\<\>' `\n\n + `grep '[^0-9][^0-9]' `\n\n Regards,\n Fail2Ban"|mail -s "[Fail2Ban] : banned from `uname -n`" diff --git a/config/action.d/sendmail-whois-lines.conf b/config/action.d/sendmail-whois-lines.conf index 5a331e24..a0f0a9c3 100644 --- a/config/action.d/sendmail-whois-lines.conf +++ b/config/action.d/sendmail-whois-lines.conf @@ -58,7 +58,7 @@ actionban = printf %%b "Subject: [Fail2Ban] : banned from `uname -n` Here are more information about :\n `/usr/bin/whois `\n\n Lines containing IP: in \n - `grep '\<\>' `\n\n + `grep '[^0-9][^0-9]' `\n\n Regards,\n Fail2Ban" | /usr/sbin/sendmail -f From b5d6310d281c1c45112ffb285c77a858da99d6f6 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 4 Dec 2013 20:51:30 +1100 Subject: [PATCH 067/125] BF: create flushlogs command to prevent logrotation clobbering logtarget. Closes gh-458 --- ChangeLog | 2 ++ client/beautifier.py | 2 ++ common/protocol.py | 1 + files/fail2ban-logrotate | 2 +- server/server.py | 13 ++++++++++++- server/transmitter.py | 2 ++ 6 files changed, 20 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 3cc0f453..fcfe82cc 100644 --- a/ChangeLog +++ b/ChangeLog @@ -20,6 +20,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - smtps not a IANA standard and has been removed from Arch. Replaced with 465. Thanks Stefan. Closes gh-447 - mysqld-syslog-iptables rule was too long. Part of gh-447. + - add 'flushlogs' command to allow logrotation without clobbering logtarget + settings. Closes gh-458, Debian bug #697333, Redhat bug #891798. - Enhancements: - long names on jails documented based on iptables limit of 30 less diff --git a/client/beautifier.py b/client/beautifier.py index 8e690656..bc9e89b1 100644 --- a/client/beautifier.py +++ b/client/beautifier.py @@ -63,6 +63,8 @@ class Beautifier: msg = "Jail stopped" elif inC[0] == "add": msg = "Added jail " + response + elif inC[0] == "flushlogs": + msg = "logs: " + response elif inC[0:1] == ['status']: if len(inC) > 1: # Create IP list diff --git a/common/protocol.py b/common/protocol.py index 9309ce7f..278ccd53 100644 --- a/common/protocol.py +++ b/common/protocol.py @@ -43,6 +43,7 @@ protocol = [ ["get loglevel", "gets the logging level"], ["set logtarget ", "sets logging target to . Can be STDOUT, STDERR, SYSLOG or a file"], ["get logtarget", "gets logging target"], +["flushlogs", "flushes the logtarget if a file and reopens it. For log rotation."], ['', "JAIL CONTROL", ""], ["add ", "creates using "], ["start ", "starts the jail "], diff --git a/files/fail2ban-logrotate b/files/fail2ban-logrotate index 67c6364a..a09870af 100644 --- a/files/fail2ban-logrotate +++ b/files/fail2ban-logrotate @@ -13,6 +13,6 @@ missingok compress postrotate - /usr/bin/fail2ban-client set logtarget /var/log/fail2ban.log 1>/dev/null || true + /usr/bin/fail2ban-client flushlogs 1>/dev/null || true endscript } diff --git a/server/server.py b/server/server.py index 6ac93a54..1358391b 100644 --- a/server/server.py +++ b/server/server.py @@ -361,7 +361,7 @@ class Server: # Target should be a file try: open(target, "a").close() - hdlr = logging.FileHandler(target) + hdlr = logging.handlers.RotatingFileHandler(target) except IOError: logSys.error("Unable to log to " + target) logSys.info("Logging to previous target " + self.__logTarget) @@ -401,6 +401,17 @@ class Server: finally: self.__loggingLock.release() + def flushLogs(self): + if self.__logTarget not in ['STDERR', 'STDOUT', 'SYSLOG']: + for handler in logging.getLogger("fail2ban").handlers: + handler.doRollover() + return "rolled over" + else: + for handler in logging.getLogger("fail2ban").handlers: + handler.flush() + return "flushed" + + def __createDaemon(self): # pragma: no cover """ Detach a process from the controlling terminal and run it in the background as a daemon. diff --git a/server/transmitter.py b/server/transmitter.py index deaf9adf..cf65dada 100644 --- a/server/transmitter.py +++ b/server/transmitter.py @@ -92,6 +92,8 @@ class Transmitter: value = command[1] time.sleep(int(value)) return None + elif command[0] == "flushlogs": + return self.__server.flushLogs() elif command[0] == "set": return self.__commandSet(command[1:]) elif command[0] == "get": From e108de3f6d19eecb0a3860405ceb6bf37c6201ff Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 4 Dec 2013 22:27:23 +1100 Subject: [PATCH 068/125] ENH: banning an IP in the ignoreIPList now issues warning to log, but still continues --- server/filter.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/server/filter.py b/server/filter.py index 80433c01..66d3fbf0 100644 --- a/server/filter.py +++ b/server/filter.py @@ -219,6 +219,9 @@ class Filter(JailThread): # to enable banip fail2ban-client BAN command def addBannedIP(self, ip): + if self.inIgnoreIPList(ip): + logSys.warning('Requested to manually ban an ignored IP ' + ip + '. User knows best. Proceeding to ban it.') + unixTime = MyTime.time() for i in xrange(self.failManager.getMaxRetry()): self.failManager.addFailure(FailTicket(ip, unixTime)) From 97d7f46bb757514f5ccb9140ffcdbb7fd0f70d59 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 4 Dec 2013 22:40:48 +1100 Subject: [PATCH 069/125] DOC: correct grammar - s/Here are more information/Here is more information/ --- config/action.d/mail-whois-lines.conf | 2 +- config/action.d/mail-whois.conf | 2 +- config/action.d/sendmail-whois-lines.conf | 2 +- config/action.d/sendmail-whois.conf | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/config/action.d/mail-whois-lines.conf b/config/action.d/mail-whois-lines.conf index 758c4eff..bbf66a59 100644 --- a/config/action.d/mail-whois-lines.conf +++ b/config/action.d/mail-whois-lines.conf @@ -39,7 +39,7 @@ actioncheck = actionban = printf %%b "Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n - Here are more information about :\n + Here is more information about :\n `whois `\n\n Lines containing IP: in \n `grep '\<\>' `\n\n diff --git a/config/action.d/mail-whois.conf b/config/action.d/mail-whois.conf index fa133ab3..c132b086 100644 --- a/config/action.d/mail-whois.conf +++ b/config/action.d/mail-whois.conf @@ -39,7 +39,7 @@ actioncheck = actionban = printf %%b "Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n - Here are more information about :\n + Here is more information about :\n `whois `\n Regards,\n Fail2Ban"|mail -s "[Fail2Ban] : banned from `uname -n`" diff --git a/config/action.d/sendmail-whois-lines.conf b/config/action.d/sendmail-whois-lines.conf index 5a331e24..b40b1084 100644 --- a/config/action.d/sendmail-whois-lines.conf +++ b/config/action.d/sendmail-whois-lines.conf @@ -55,7 +55,7 @@ actionban = printf %%b "Subject: [Fail2Ban] : banned from `uname -n` Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n - Here are more information about :\n + Here is more information about :\n `/usr/bin/whois `\n\n Lines containing IP: in \n `grep '\<\>' `\n\n diff --git a/config/action.d/sendmail-whois.conf b/config/action.d/sendmail-whois.conf index a65f9875..f2b07d9e 100644 --- a/config/action.d/sendmail-whois.conf +++ b/config/action.d/sendmail-whois.conf @@ -55,7 +55,7 @@ actionban = printf %%b "Subject: [Fail2Ban] : banned from `uname -n` Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n - Here are more information about :\n + Here is more information about :\n `/usr/bin/whois `\n Regards,\n Fail2Ban" | /usr/sbin/sendmail -f From 4dc51e5defdc8ce56db4b71b9b6b53d654908d56 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 4 Dec 2013 22:43:06 +1100 Subject: [PATCH 070/125] BF: put notice in email if whois program could not provide more information. Closes gh-471 --- config/action.d/mail-whois-lines.conf | 2 +- config/action.d/mail-whois.conf | 2 +- config/action.d/sendmail-whois-lines.conf | 2 +- config/action.d/sendmail-whois.conf | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/config/action.d/mail-whois-lines.conf b/config/action.d/mail-whois-lines.conf index bbf66a59..067c5819 100644 --- a/config/action.d/mail-whois-lines.conf +++ b/config/action.d/mail-whois-lines.conf @@ -40,7 +40,7 @@ actionban = printf %%b "Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n Here is more information about :\n - `whois `\n\n + `whois || echo missing whois program`\n\n Lines containing IP: in \n `grep '\<\>' `\n\n Regards,\n diff --git a/config/action.d/mail-whois.conf b/config/action.d/mail-whois.conf index c132b086..e4c8450e 100644 --- a/config/action.d/mail-whois.conf +++ b/config/action.d/mail-whois.conf @@ -40,7 +40,7 @@ actionban = printf %%b "Hi,\n The IP has just been banned by Fail2Ban after attempts against .\n\n Here is more information about :\n - `whois `\n + `whois || echo missing whois program`\n Regards,\n Fail2Ban"|mail -s "[Fail2Ban] : banned from `uname -n`" diff --git a/config/action.d/sendmail-whois-lines.conf b/config/action.d/sendmail-whois-lines.conf index b40b1084..8cdafc0b 100644 --- a/config/action.d/sendmail-whois-lines.conf +++ b/config/action.d/sendmail-whois-lines.conf @@ -56,7 +56,7 @@ actionban = printf %%b "Subject: [Fail2Ban] : banned from `uname -n` The IP has just been banned by Fail2Ban after attempts against .\n\n Here is more information about :\n - `/usr/bin/whois `\n\n + `/usr/bin/whois || echo missing whois program`\n\n Lines containing IP: in \n `grep '\<\>' `\n\n Regards,\n diff --git a/config/action.d/sendmail-whois.conf b/config/action.d/sendmail-whois.conf index f2b07d9e..e428c44d 100644 --- a/config/action.d/sendmail-whois.conf +++ b/config/action.d/sendmail-whois.conf @@ -56,7 +56,7 @@ actionban = printf %%b "Subject: [Fail2Ban] : banned from `uname -n` The IP has just been banned by Fail2Ban after attempts against .\n\n Here is more information about :\n - `/usr/bin/whois `\n + `/usr/bin/whois || echo missing whois program`\n Regards,\n Fail2Ban" | /usr/sbin/sendmail -f From e810ec009d56a51478fd740c60f2770448a7a752 Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Thu, 5 Dec 2013 08:22:20 +0000 Subject: [PATCH 071/125] ENH: Added blocklist.de reporting API action --- config/action.d/blocklist_de.conf | 55 +++++++++++++++++++++++++++++++ config/jail.conf | 12 +++++++ 2 files changed, 67 insertions(+) create mode 100644 config/action.d/blocklist_de.conf diff --git a/config/action.d/blocklist_de.conf b/config/action.d/blocklist_de.conf new file mode 100644 index 00000000..d11b175b --- /dev/null +++ b/config/action.d/blocklist_de.conf @@ -0,0 +1,55 @@ +# Fail2Ban configuration file +# +# Author: Steven Hiscocks +# +# + +# Action to report IP address to blocklist.de +# Blocklist.de must be signed up to at www.blocklist.de +# Once registered, one or more servers can be added. +# This action requires the server 'email address' and the assoicate apikey. +# +# From blocklist.de: +# www.blocklist.de is a free and voluntary service provided by a +# Fraud/Abuse-specialist, whose servers are often attacked on SSH-, +# Mail-Login-, FTP-, Webserver- and other services. +# The mission is to report all attacks to the abuse deparments of the +# infected PCs/servers to ensure that the responsible provider can inform +# the customer about the infection and disable them +# + +[Definition] + +# Option: actionstart +# Notes.: command executed once at the start of Fail2Ban. +# Values: CMD +# +actionstart = + +# Option: actionstop +# Notes.: command executed once at the end of Fail2Ban +# Values: CMD +# +actionstop = + +# Option: actioncheck +# Notes.: command executed once before each actionban command +# Values: CMD +# +actioncheck = + +# Option: actionban +# Notes.: command executed when banning an IP. Take care that the +# command is executed with Fail2Ban user rights. +# Tags: See jail.conf(5) man page +# Values: CMD +# +actionban = ! curl --data-urlencode 'server=' --data 'apikey=' --data 'service=' --data 'ip=' --data-urlencode 'logs=' --data 'format=text' "https://www.blocklist.de/en/httpreports.html" | grep "status: error" + +# Option: actionunban +# Notes.: command executed when unbanning an IP. Take care that the +# command is executed with Fail2Ban user rights. +# Tags: See jail.conf(5) man page +# Values: CMD +# +actionunban = diff --git a/config/jail.conf b/config/jail.conf index 33d1d439..cbcfb758 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -532,3 +532,15 @@ filter = selinux-ssh action = iptables[name=SELINUX-SSH, port=ssh, protocol=tcp] logpath = /var/log/audit/audit.log maxretry = 5 + +# Report block via blocklist.de fail2ban reporting service API +# See action.d/blocklist_de.conf for more information +[ssh-blocklist] + +enabled = false +filter = sshd +action = iptables[name=SSH, port=ssh, protocol=tcp] + sendmail-whois[name=SSH, dest=you@example.com, sender=fail2ban@example.com, sendername="Fail2Ban"] + blocklist_de[email="fail2ban@example.com", apikey="xxxxxx", service=%(filter)s] +logpath = /var/log/sshd.log +maxretry = 5 From f742ed0e4bc3182f36f348345bce2858b6db4369 Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Thu, 5 Dec 2013 18:06:53 +0000 Subject: [PATCH 072/125] DOC: when to use blocklist.de reporting Taken from commit 1846056606d24abe4e7d3f2e1cf56407c65b9008 --- config/action.d/blocklist_de.conf | 10 ++++++++++ config/jail.conf | 5 ++++- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/config/action.d/blocklist_de.conf b/config/action.d/blocklist_de.conf index d11b175b..468f3fc9 100644 --- a/config/action.d/blocklist_de.conf +++ b/config/action.d/blocklist_de.conf @@ -17,6 +17,16 @@ # infected PCs/servers to ensure that the responsible provider can inform # the customer about the infection and disable them # +# IMPORTANT: +# +# Reporting an IP of abuse is a serious complaint. Make sure that it is +# serious. Fail2ban developers and network owners recommend you only use this +# action for: +# * The recidive where the IP has been banned multiple times +# * Where maxretry has been set quite high, beyond the normal user typing +# password incorrectly. +# * For filters that have a low likelyhood of receiving human errors +# [Definition] diff --git a/config/jail.conf b/config/jail.conf index cbcfb758..3b8220e5 100644 --- a/config/jail.conf +++ b/config/jail.conf @@ -533,6 +533,9 @@ action = iptables[name=SELINUX-SSH, port=ssh, protocol=tcp] logpath = /var/log/audit/audit.log maxretry = 5 +# See the IMPORTANT note in action.d/blocklist_de.conf for when to +# use this action +# # Report block via blocklist.de fail2ban reporting service API # See action.d/blocklist_de.conf for more information [ssh-blocklist] @@ -543,4 +546,4 @@ action = iptables[name=SSH, port=ssh, protocol=tcp] sendmail-whois[name=SSH, dest=you@example.com, sender=fail2ban@example.com, sendername="Fail2Ban"] blocklist_de[email="fail2ban@example.com", apikey="xxxxxx", service=%(filter)s] logpath = /var/log/sshd.log -maxretry = 5 +maxretry = 20 From a19b33cc7263c0758d6848ecbaa0e5ad4e24b962 Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Thu, 5 Dec 2013 18:12:15 +0000 Subject: [PATCH 073/125] ENH: blocklist.de action added fail2ban version as user agent --- config/action.d/blocklist_de.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/action.d/blocklist_de.conf b/config/action.d/blocklist_de.conf index 468f3fc9..6f47d87b 100644 --- a/config/action.d/blocklist_de.conf +++ b/config/action.d/blocklist_de.conf @@ -54,7 +54,7 @@ actioncheck = # Tags: See jail.conf(5) man page # Values: CMD # -actionban = ! curl --data-urlencode 'server=' --data 'apikey=' --data 'service=' --data 'ip=' --data-urlencode 'logs=' --data 'format=text' "https://www.blocklist.de/en/httpreports.html" | grep "status: error" +actionban = ! curl --data-urlencode 'server=' --data 'apikey=' --data 'service=' --data 'ip=' --data-urlencode 'logs=' --data 'format=text' --user-agent "`fail2ban-client --version | head -1`" "https://www.blocklist.de/en/httpreports.html" | grep "status: error" # Option: actionunban # Notes.: command executed when unbanning an IP. Take care that the From 008952035db55c803b1b33ed78bf93c6eb74cf62 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 6 Dec 2013 08:08:11 +1100 Subject: [PATCH 074/125] BF: files/redhat-initd - as per http://pkgs.fedoraproject.org/cgit/fail2ban.git/tree/fail2ban-init.patch --- files/redhat-initd | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/files/redhat-initd b/files/redhat-initd index 43147c95..08eb0f3c 100755 --- a/files/redhat-initd +++ b/files/redhat-initd @@ -1,6 +1,6 @@ #!/bin/bash # -# chkconfig: 345 92 08 +# chkconfig: - 92 08 # processname: fail2ban-server # config: /etc/fail2ban/fail2ban.conf # pidfile: /var/run/fail2ban/fail2ban.pid From b3c173795e1fe023adcc4a781674075d071bc756 Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Fri, 6 Dec 2013 08:22:21 +0000 Subject: [PATCH 075/125] ENH: blocklist.de action error on HTTP response code 4xx --- config/action.d/blocklist_de.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/action.d/blocklist_de.conf b/config/action.d/blocklist_de.conf index 6f47d87b..f45882d3 100644 --- a/config/action.d/blocklist_de.conf +++ b/config/action.d/blocklist_de.conf @@ -54,7 +54,7 @@ actioncheck = # Tags: See jail.conf(5) man page # Values: CMD # -actionban = ! curl --data-urlencode 'server=' --data 'apikey=' --data 'service=' --data 'ip=' --data-urlencode 'logs=' --data 'format=text' --user-agent "`fail2ban-client --version | head -1`" "https://www.blocklist.de/en/httpreports.html" | grep "status: error" +actionban = curl --fail --data-urlencode 'server=' --data 'apikey=' --data 'service=' --data 'ip=' --data-urlencode 'logs=' --data 'format=text' --user-agent "fail2ban v0.8.12" "https://www.blocklist.de/en/httpreports.html" # Option: actionunban # Notes.: command executed when unbanning an IP. Take care that the From 476bbdd284836b47b77f0ccafbfbb3776a5df807 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 7 Dec 2013 10:57:05 +1100 Subject: [PATCH 076/125] TST: test case for flushlogs --- testcases/servertestcase.py | 29 ++++++++++++++++++++++++++++- 1 file changed, 28 insertions(+), 1 deletion(-) diff --git a/testcases/servertestcase.py b/testcases/servertestcase.py index c93326a5..af6f538d 100644 --- a/testcases/servertestcase.py +++ b/testcases/servertestcase.py @@ -25,7 +25,7 @@ __copyright__ = "Copyright (c) 2004 Cyril Jaquier" __license__ = "GPL" import unittest, socket, time, tempfile, os, sys -from server.server import Server +from server.server import Server, logSys from server.jail import Jail from common.exceptions import UnknownJailException @@ -521,6 +521,33 @@ class TransmitterLogging(TransmitterBase): self.setGetTest("loglevel", "0", 0) self.setGetTestNOK("loglevel", "Bird") + def testFlushLogs(self): + self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "flushed")) + try: + f, fn = tempfile.mkstemp("fail2ban.log") + os.close(f) + self.server.setLogLevel(2) + self.assertEqual(self.transm.proceed(["set", "logtarget", fn]), (0, fn)) + logSys.warn("Before file moved") + try: + f2, fn2 = tempfile.mkstemp("fail2ban.log") + os.close(f2) + os.rename(fn, fn2) + logSys.warn("After file moved") + self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "flushed")) + logSys.warn("After flushlogs") + with open(fn2,'r') as f: + self.assertTrue(f.next().endswith("Before file moved\n")) + self.assertTrue(f.next().endswith("After file moved\n")) + self.assertRaises(StopIteration, f.next) + with open(fn,'r') as f: + self.assertTrue(f.next().endswith("After flushlogs\n")) + self.assertRaises(StopIteration, f.next) + finally: + os.remove(fn2) + finally: + os.remove(fn) + class JailTests(unittest.TestCase): From 8451f720f03c8b7535deba7b3b3993458edbe720 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 7 Dec 2013 11:04:06 +1100 Subject: [PATCH 077/125] TST: fix flushlogs and include test for STDERR flushing --- testcases/servertestcase.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/testcases/servertestcase.py b/testcases/servertestcase.py index af6f538d..e6137d2f 100644 --- a/testcases/servertestcase.py +++ b/testcases/servertestcase.py @@ -522,7 +522,7 @@ class TransmitterLogging(TransmitterBase): self.setGetTestNOK("loglevel", "Bird") def testFlushLogs(self): - self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "flushed")) + self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "rolled over")) try: f, fn = tempfile.mkstemp("fail2ban.log") os.close(f) @@ -534,7 +534,7 @@ class TransmitterLogging(TransmitterBase): os.close(f2) os.rename(fn, fn2) logSys.warn("After file moved") - self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "flushed")) + self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "rolled over")) logSys.warn("After flushlogs") with open(fn2,'r') as f: self.assertTrue(f.next().endswith("Before file moved\n")) @@ -547,6 +547,8 @@ class TransmitterLogging(TransmitterBase): os.remove(fn2) finally: os.remove(fn) + self.assertEqual(self.transm.proceed(["set", "logtarget", "STDERR"]), (0, "STDERR")) + self.assertEqual(self.transm.proceed(["flushlogs"]), (0, "flushed")) class JailTests(unittest.TestCase): From 630dd91dcdd6a3f5501b2e15a06577cee32dab0c Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Fri, 6 Dec 2013 18:01:36 +0000 Subject: [PATCH 078/125] BF: Add [Init] section to blocklist.de action --- config/action.d/blocklist_de.conf | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/config/action.d/blocklist_de.conf b/config/action.d/blocklist_de.conf index f45882d3..d4170cab 100644 --- a/config/action.d/blocklist_de.conf +++ b/config/action.d/blocklist_de.conf @@ -63,3 +63,24 @@ actionban = curl --fail --data-urlencode 'server=' --data 'apikey= Date: Mon, 9 Dec 2013 09:21:55 +1100 Subject: [PATCH 079/125] BF: action.d/complain - match IP at beginning and end of lines --- config/action.d/complain.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/action.d/complain.conf b/config/action.d/complain.conf index d1ca25c7..62331f19 100644 --- a/config/action.d/complain.conf +++ b/config/action.d/complain.conf @@ -58,7 +58,7 @@ actioncheck = actionban = ADDRESSES=`whois | perl -e 'while () { next if /^changed|@(ripe|apnic)\.net/io; $m += (/abuse|trouble:|report|spam|security/io?3:0); if (/([a-z0-9_\-\.+]+@[a-z0-9\-]+(\.[[a-z0-9\-]+)+)/io) { while (s/([a-z0-9_\-\.+]+@[a-z0-9\-]+(\.[[a-z0-9\-]+)+)//io) { if ($m) { $a{lc($1)}=$m } else { $b{lc($1)}=$m } } $m=0 } else { $m && --$m } } if (%%a) {print join(",",keys(%%a))} else {print join(",",keys(%%b))}'` IP= if [ ! -z "$ADDRESSES" ]; then - (printf %%b "\n"; date '+Note: Local timezone is %%z (%%Z)'; grep '[^0-9][^0-9]' ) | "Abuse from " $ADDRESSES + (printf %%b "\n"; date '+Note: Local timezone is %%z (%%Z)'; grep -E '(^|[^0-9])([^0-9]|$)' ) | "Abuse from " $ADDRESSES fi # Option: actionunban From e8eab11615e1d753f20345339e8a7bd0a8a12db6 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 9 Dec 2013 14:45:09 +1100 Subject: [PATCH 080/125] DOC: proftp - turn off ReverseDNS --- config/filter.d/proftpd.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/config/filter.d/proftpd.conf b/config/filter.d/proftpd.conf index bf8f9b5f..b7e13414 100644 --- a/config/filter.d/proftpd.conf +++ b/config/filter.d/proftpd.conf @@ -1,5 +1,7 @@ # Fail2Ban fitler for the Proftpd FTP daemon # +# Set "UseReverseDNS off" in proftpd to avoid the need for DNS. +# See: http://www.proftpd.org/docs/howto/DNS.html [INCLUDES] From db4c21acde6830eb8fbcdd34d1a5e71a11ed9e34 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 9 Dec 2013 14:46:01 +1100 Subject: [PATCH 081/125] BF/DOC: fix filename in documentation for filter.d/proftpd --- config/filter.d/proftpd.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/filter.d/proftpd.conf b/config/filter.d/proftpd.conf index b7e13414..ac714cc1 100644 --- a/config/filter.d/proftpd.conf +++ b/config/filter.d/proftpd.conf @@ -1,6 +1,6 @@ # Fail2Ban fitler for the Proftpd FTP daemon # -# Set "UseReverseDNS off" in proftpd to avoid the need for DNS. +# Set "UseReverseDNS off" in proftpd.conf to avoid the need for DNS. # See: http://www.proftpd.org/docs/howto/DNS.html [INCLUDES] From 916649119ef124e952f50e6c27cf3003897f15f9 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 9 Dec 2013 23:07:42 +1100 Subject: [PATCH 082/125] ENH: use format string rather than concatination on log message --- server/filter.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/filter.py b/server/filter.py index 66d3fbf0..0ef756d2 100644 --- a/server/filter.py +++ b/server/filter.py @@ -220,7 +220,7 @@ class Filter(JailThread): def addBannedIP(self, ip): if self.inIgnoreIPList(ip): - logSys.warning('Requested to manually ban an ignored IP ' + ip + '. User knows best. Proceeding to ban it.') + logSys.warning('Requested to manually ban an ignored IP %s. User knows best. Proceeding to ban it.' % ip) unixTime = MyTime.time() for i in xrange(self.failManager.getMaxRetry()): From 66374913ec773175ef921798d3efdd4c47f27e01 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 10 Dec 2013 21:24:37 +1100 Subject: [PATCH 083/125] ENH: add squid filter --- ChangeLog | 1 + THANKS | 1 + config/filter.d/squid.conf | 13 +++++++++++++ testcases/files/logs/squid | 13 +++++++++++++ 4 files changed, 28 insertions(+) create mode 100644 config/filter.d/squid.conf create mode 100644 testcases/files/logs/squid diff --git a/ChangeLog b/ChangeLog index 90b8ba27..a0624630 100644 --- a/ChangeLog +++ b/ChangeLog @@ -32,6 +32,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better len("fail2ban-"). - remove indentation of name and loglevel while logging to SYSLOG to resolve syslog(-ng) parsing problems. Closes Debian bug #730202. + - added squid filter. Thanks Roman Gelfand. - New Features: diff --git a/THANKS b/THANKS index 04c8728d..6d4845bb 100644 --- a/THANKS +++ b/THANKS @@ -62,6 +62,7 @@ RealRancor René Berber Robert Edeker Rolf Fokkens +Roman Gelfand Russell Odom Sebastian Arcus Sireyessire diff --git a/config/filter.d/squid.conf b/config/filter.d/squid.conf new file mode 100644 index 00000000..8cbf744f --- /dev/null +++ b/config/filter.d/squid.conf @@ -0,0 +1,13 @@ +# Fail2Ban filter for Squid attempted proxy bypasses +# +# + +[Definition] + +failregex = ^\s+\d\s\s+[A-Z]+_DENIED/403 .*$ + ^\s+\d\s\s+NONE/405 .*$ + + + +# Author: Daniel Black + diff --git a/testcases/files/logs/squid b/testcases/files/logs/squid new file mode 100644 index 00000000..fa2c593c --- /dev/null +++ b/testcases/files/logs/squid @@ -0,0 +1,13 @@ +# Logs thanks to Roman Gelfand +# +# failJSON: { "time": "2013-12-08T23:55:23", "match": true , "host": "91.188.124.227" } +1386543323.511 4 91.188.124.227 TCP_DENIED/403 4099 GET http://www.proxy-listen.de/azenv.php - HIER_NONE/- text/html + +# failJSON: { "time": "2013-12-08T23:58:20", "match": true , "host": "175.44.0.184" } +1386543500.220 5 175.44.0.184 NONE/405 3364 CONNECT error:method-not-allowed - HIER_NONE/- text/html + +# failJSON: { "time": "2013-12-09T00:08:04", "match": true , "host": "198.74.125.200" } +1386544084.763 3 198.74.125.200 TCP_DENIED/403 3722 GET http://www2t.biglobe.ne.jp/~take52/test/env.cgi - HIER_NONE/- text/html + +# failJSON: { "time": "2013-12-09T00:09:06", "match": true , "host": "175.42.91.151" } +1386544146.088 1 175.42.91.151 TCP_DENIED/403 3745 GET http://pkfsp.ru/wp-content/uploads/proxyc/engine.php - HIER_NONE/- text/html From 9d532828fcb51ca245b330c026a16da8bdecc941 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 07:44:41 +1100 Subject: [PATCH 084/125] BF: multiple _ separated values according to http://wiki.squid-cache.org/SquidFaq/SquidLogs#Squid_result_codes. Thanks Steven --- config/filter.d/squid.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/filter.d/squid.conf b/config/filter.d/squid.conf index 8cbf744f..da282692 100644 --- a/config/filter.d/squid.conf +++ b/config/filter.d/squid.conf @@ -4,7 +4,7 @@ [Definition] -failregex = ^\s+\d\s\s+[A-Z]+_DENIED/403 .*$ +failregex = ^\s+\d\s\s+[A-Z_]+_DENIED/403 .*$ ^\s+\d\s\s+NONE/405 .*$ From 5688c064ad757006bb268bb1e4d1ce6c120df0cd Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 09:50:17 +1100 Subject: [PATCH 085/125] ENH: separate out log capture framework for other test cases - now utils.LogCaptureTestCase --- testcases/actiontestcase.py | 27 +++++---------------------- testcases/utils.py | 29 ++++++++++++++++++++++++++++- 2 files changed, 33 insertions(+), 23 deletions(-) diff --git a/testcases/actiontestcase.py b/testcases/actiontestcase.py index 14356ee5..e0587b3d 100644 --- a/testcases/actiontestcase.py +++ b/testcases/actiontestcase.py @@ -24,40 +24,23 @@ __author__ = "Cyril Jaquier" __copyright__ = "Copyright (c) 2004 Cyril Jaquier" __license__ = "GPL" -import unittest, time +import time import logging, sys from server.action import Action -from StringIO import StringIO +from utils import LogCaptureTestCase -class ExecuteAction(unittest.TestCase): +class ExecuteAction(LogCaptureTestCase): def setUp(self): """Call before every test case.""" self.__action = Action("Test") - - # For extended testing of what gets output into logging - # system, we will redirect it to a string - logSys = logging.getLogger("fail2ban") - - # Keep old settings - self._old_level = logSys.level - self._old_handlers = logSys.handlers - # Let's log everything into a string - self._log = StringIO() - logSys.handlers = [logging.StreamHandler(self._log)] - logSys.setLevel(getattr(logging, 'DEBUG')) + LogCaptureTestCase.setUp(self) def tearDown(self): """Call after every test case.""" - # print "O: >>%s<<" % self._log.getvalue() - logSys = logging.getLogger("fail2ban") - logSys.handlers = self._old_handlers - logSys.level = self._old_level + LogCaptureTestCase.tearDown(self) self.__action.execActionStop() - def _is_logged(self, s): - return s in self._log.getvalue() - def testNameChange(self): self.assertEqual(self.__action.getName(), "Test") self.__action.setName("Tricky Test") diff --git a/testcases/utils.py b/testcases/utils.py index 643c9ad1..b048c8c6 100644 --- a/testcases/utils.py +++ b/testcases/utils.py @@ -22,8 +22,9 @@ __author__ = "Yaroslav Halchenko" __copyright__ = "Copyright (c) 2013 Yaroslav Halchenko" __license__ = "GPL" -import logging, os, re, tempfile, sys, time, traceback +import unittest, logging, os, re, tempfile, sys, time, traceback from os.path import basename, dirname +from StringIO import StringIO # # Following "traceback" functions are adopted from PyMVPA distributed @@ -105,3 +106,29 @@ def mtimesleep(): # no sleep now should be necessary since polling tracks now not only # mtime but also ino and size pass + +class LogCaptureTestCase(unittest.TestCase): + + def setUp(self): + + # For extended testing of what gets output into logging + # system, we will redirect it to a string + logSys = logging.getLogger("fail2ban") + + # Keep old settings + self._old_level = logSys.level + self._old_handlers = logSys.handlers + # Let's log everything into a string + self._log = StringIO() + logSys.handlers = [logging.StreamHandler(self._log)] + logSys.setLevel(getattr(logging, 'DEBUG')) + + def tearDown(self): + """Call after every test case.""" + # print "O: >>%s<<" % self._log.getvalue() + logSys = logging.getLogger("fail2ban") + logSys.handlers = self._old_handlers + logSys.level = self._old_level + + def _is_logged(self, s): + return s in self._log.getvalue() From f4661d81779683e0ef92b3278347639e3260bb36 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 09:56:04 +1100 Subject: [PATCH 086/125] ENH: rebase LogFileMonitor on LogCaptureTestCase --- testcases/filtertestcase.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 8bc24085..6ab99d82 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -39,7 +39,7 @@ from server.failmanager import FailManagerEmpty # Useful helpers # -from utils import mtimesleep +from utils import mtimesleep, LogCaptureTestCase # yoh: per Steven Hiscocks's insight while troubleshooting # https://github.com/fail2ban/fail2ban/issues/103#issuecomment-15542836 @@ -194,11 +194,12 @@ class LogFile(unittest.TestCase): self.assertTrue(self.filter.isModified(LogFile.FILENAME)) -class LogFileMonitor(unittest.TestCase): +class LogFileMonitor(LogCaptureTestCase): """Few more tests for FilterPoll API """ def setUp(self): """Call before every test case.""" + LogCaptureTestCase.setUp(self) self.filter = self.name = 'NA' _, self.name = tempfile.mkstemp('fail2ban', 'monitorfailures') self.file = open(self.name, 'a') @@ -208,6 +209,7 @@ class LogFileMonitor(unittest.TestCase): self.filter.addFailRegex("(?:(?:Authentication failure|Failed [-/\w+]+) for(?: [iI](?:llegal|nvalid) user)?|[Ii](?:llegal|nvalid) user|ROOT LOGIN REFUSED) .*(?: from|FROM) ") def tearDown(self): + LogCaptureTestCase.tearDown(self) _killfile(self.file, self.name) pass From f4531e7b45c97cb03480b5e58749bad83f914231 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:10:31 +1100 Subject: [PATCH 087/125] TST: test cases fro filter.delFailRegex and filter.delIgnoreRegex --- testcases/filtertestcase.py | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 6ab99d82..b7b161d3 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -227,6 +227,16 @@ class LogFileMonitor(LogCaptureTestCase): # shorter wait time for not modified status return not self.isModified(0.4) + def testRemovingFailRegex(self): + self.filter.delFailRegex(0) + self.assertFalse(self._is_logged('Cannot remove regular expression. Index 0 is not valid')) + self.filter.delFailRegex(0) + self.assertTrue(self._is_logged('Cannot remove regular expression. Index 0 is not valid')) + + def testRemovingIgnoreRegex(self): + self.filter.delIgnoreRegex(0) + self.assertTrue(self._is_logged('Cannot remove regular expression. Index 0 is not valid')) + def testNewChangeViaIsModified(self): # it is a brand new one -- so first we think it is modified self.assertTrue(self.isModified()) From 44bbaebfe511e679e8a0dfa251e1383138f90002 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:15:24 +1100 Subject: [PATCH 088/125] TST: CIDR for ignoreip --- testcases/filtertestcase.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index b7b161d3..892a4a6e 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -173,6 +173,15 @@ class IgnoreIP(unittest.TestCase): self.filter.addIgnoreIP("www.epfl.ch") self.assertFalse(self.filter.inIgnoreIPList("127.177.50.10")) + def testIgnoreIPCIDR(self): + self.filter.addIgnoreIP('192.168.1.0/25') + self.assertTrue(self.filter.inIgnoreIPList('192.168.1.0')) + self.assertTrue(self.filter.inIgnoreIPList('192.168.1.1')) + self.assertTrue(self.filter.inIgnoreIPList('192.168.1.127')) + self.assertFalse(self.filter.inIgnoreIPList('192.168.1.128')) + self.assertFalse(self.filter.inIgnoreIPList('192.168.1.255')) + self.assertFalse(self.filter.inIgnoreIPList('192.168.0.255')) + class LogFile(unittest.TestCase): From 988e14d8c652a077fcb47a0ec1a88eb3ca3fdb5f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:17:55 +1100 Subject: [PATCH 089/125] TST: negative match for DNS lookup test added --- testcases/filtertestcase.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 892a4a6e..0d2b58fb 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -163,6 +163,8 @@ class IgnoreIP(unittest.TestCase): self.filter.addIgnoreIP("www.epfl.ch") self.assertTrue(self.filter.inIgnoreIPList("128.178.50.12")) + self.assertFalse(self.filter.inIgnoreIPList("128.178.50.11")) + self.assertFalse(self.filter.inIgnoreIPList("128.178.50.13")) def testIgnoreIPNOK(self): ipList = "", "999.999.999.999", "abcdef", "192.168.0." From 60c4957a5278b033c41e71c18d2824441507ea14 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:21:19 +1100 Subject: [PATCH 090/125] DOC/TST: remove TODO as all regexs have samples --- testcases/samplestestcase.py | 1 - 1 file changed, 1 deletion(-) diff --git a/testcases/samplestestcase.py b/testcases/samplestestcase.py index d88be5e9..6b4d4530 100644 --- a/testcases/samplestestcase.py +++ b/testcases/samplestestcase.py @@ -123,7 +123,6 @@ def testSampleRegexsFactory(name): regexsUsed.add(failregex) - # TODO: Remove exception handling once all regexs have samples for failRegexIndex, failRegex in enumerate(self.filter.getFailRegex()): self.assertTrue( failRegexIndex in regexsUsed, From a8b5c5b5f3f5de2c5a103c22f40672481ab33906 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:31:58 +1100 Subject: [PATCH 091/125] TST: check IgnoreIP happens in filter.processLine --- testcases/filtertestcase.py | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 0d2b58fb..63f23400 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -144,15 +144,13 @@ def _copy_lines_between_files(fin, fout, n=None, skip=0, mode='a', terminal_line # Actual tests # -class IgnoreIP(unittest.TestCase): +class IgnoreIP(LogCaptureTestCase): def setUp(self): """Call before every test case.""" + LogCaptureTestCase.setUp(self) self.filter = FileFilter(None) - def tearDown(self): - """Call after every test case.""" - def testIgnoreIPOK(self): ipList = "127.0.0.1", "192.168.0.1", "255.255.255.255", "99.99.99.99" for ip in ipList: @@ -184,6 +182,12 @@ class IgnoreIP(unittest.TestCase): self.assertFalse(self.filter.inIgnoreIPList('192.168.1.255')) self.assertFalse(self.filter.inIgnoreIPList('192.168.0.255')) + def testIgnoreInProcessLine(self): + self.filter.addIgnoreIP('192.168.1.0/25') + self.filter.addFailRegex('') + self.filter.processLineAndAdd('Thu Jul 11 01:21:43 2013 192.168.1.32') + self.assertTrue(self._is_logged('Ignore 192.168.1.32')) + class LogFile(unittest.TestCase): From ebf4a02004ed2d312a3329f0dd4ab36cb0028f8f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:43:47 +1100 Subject: [PATCH 092/125] TST: get/set use DNS on Filters --- fail2ban-testcases | 1 + testcases/filtertestcase.py | 16 +++++++++++++++- 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/fail2ban-testcases b/fail2ban-testcases index f44e84d4..16c92c5f 100755 --- a/fail2ban-testcases +++ b/fail2ban-testcases @@ -174,6 +174,7 @@ tests.addTest(unittest.makeSuite(misctestcase.CustomDateFormatsTest)) # Filter if not opts.no_network: tests.addTest(unittest.makeSuite(filtertestcase.IgnoreIP)) +tests.addTest(unittest.makeSuite(filtertestcase.BasicFilter)) tests.addTest(unittest.makeSuite(filtertestcase.LogFile)) tests.addTest(unittest.makeSuite(filtertestcase.LogFileMonitor)) if not opts.no_network: diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 63f23400..7b09ffed 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -31,7 +31,7 @@ import tempfile from server.jail import Jail from server.filterpoll import FilterPoll -from server.filter import FileFilter, DNSUtils +from server.filter import Filter, FileFilter, DNSUtils from server.failmanager import FailManager from server.failmanager import FailManagerEmpty @@ -144,6 +144,20 @@ def _copy_lines_between_files(fin, fout, n=None, skip=0, mode='a', terminal_line # Actual tests # +class BasicFilter(unittest.TestCase): + + def setUp(self): + self.filter = Filter('name') + + def testGetSetUseDNS(self): + # default is warn + self.assertEqual(self.filter.getUseDns(), 'warn') + self.filter.setUseDns(True) + self.assertEqual(self.filter.getUseDns(), 'yes') + self.filter.setUseDns(False) + self.assertEqual(self.filter.getUseDns(), 'no') + + class IgnoreIP(LogCaptureTestCase): def setUp(self): From f3c42851180f08316a5b898ad5566000ab7b4af9 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:46:52 +1100 Subject: [PATCH 093/125] TST: no test coverage on subclass overwritten function _delLogPath --- server/filter.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/filter.py b/server/filter.py index 0ef756d2..52bb8c4c 100644 --- a/server/filter.py +++ b/server/filter.py @@ -446,7 +446,7 @@ class FileFilter(Filter): self._delLogPath(path) return - def _delLogPath(self, path): + def _delLogPath(self, path): # pragma: no cover - overwritten function # nothing to do by default # to be overridden by backends pass From 2b89457dc94249d44295cc5e79d17e0ec0fb3522 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 10:55:06 +1100 Subject: [PATCH 094/125] TST: addBanned IP when ignore exists --- testcases/filtertestcase.py | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 7b09ffed..29491ae5 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -34,6 +34,7 @@ from server.filterpoll import FilterPoll from server.filter import Filter, FileFilter, DNSUtils from server.failmanager import FailManager from server.failmanager import FailManagerEmpty +from dummyjail import DummyJail # # Useful helpers @@ -163,7 +164,8 @@ class IgnoreIP(LogCaptureTestCase): def setUp(self): """Call before every test case.""" LogCaptureTestCase.setUp(self) - self.filter = FileFilter(None) + self.jail = DummyJail() + self.filter = FileFilter(self.jail) def testIgnoreIPOK(self): ipList = "127.0.0.1", "192.168.0.1", "255.255.255.255", "99.99.99.99" @@ -202,6 +204,11 @@ class IgnoreIP(LogCaptureTestCase): self.filter.processLineAndAdd('Thu Jul 11 01:21:43 2013 192.168.1.32') self.assertTrue(self._is_logged('Ignore 192.168.1.32')) + def testIgnoreAddBannedIP(self): + self.filter.addIgnoreIP('192.168.1.0/25') + self.filter.addBannedIP('192.168.1.32') + self.assertFalse(self._is_logged('Ignore 192.168.1.32')) + self.assertTrue(self._is_logged('Requested to manually ban an ignored IP 192.168.1.32. User knows best. Proceeding to ban it.')) class LogFile(unittest.TestCase): @@ -347,7 +354,6 @@ class LogFileMonitor(LogCaptureTestCase): from threading import Lock -from dummyjail import DummyJail def get_monitor_failures_testcase(Filter_): """Generator of TestCase's for different filters/backends From c13b91fa709a39e8c402d55453178af35dd20c29 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 12:08:23 +1100 Subject: [PATCH 095/125] TST: separate out DNS based IgnoreIP tests --- fail2ban-testcases | 3 ++- testcases/filtertestcase.py | 25 ++++++++++++++++--------- 2 files changed, 18 insertions(+), 10 deletions(-) diff --git a/fail2ban-testcases b/fail2ban-testcases index 16c92c5f..21b8fda4 100755 --- a/fail2ban-testcases +++ b/fail2ban-testcases @@ -173,7 +173,8 @@ tests.addTest(unittest.makeSuite(misctestcase.CustomDateFormatsTest)) # Filter if not opts.no_network: - tests.addTest(unittest.makeSuite(filtertestcase.IgnoreIP)) + tests.addTest(unittest.makeSuite(filtertestcase.IgnoreIPDNS)) +tests.addTest(unittest.makeSuite(filtertestcase.IgnoreIP)) tests.addTest(unittest.makeSuite(filtertestcase.BasicFilter)) tests.addTest(unittest.makeSuite(filtertestcase.LogFile)) tests.addTest(unittest.makeSuite(filtertestcase.LogFileMonitor)) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 29491ae5..46870d41 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -173,21 +173,12 @@ class IgnoreIP(LogCaptureTestCase): self.filter.addIgnoreIP(ip) self.assertTrue(self.filter.inIgnoreIPList(ip)) - # Test DNS - self.filter.addIgnoreIP("www.epfl.ch") - - self.assertTrue(self.filter.inIgnoreIPList("128.178.50.12")) - self.assertFalse(self.filter.inIgnoreIPList("128.178.50.11")) - self.assertFalse(self.filter.inIgnoreIPList("128.178.50.13")) def testIgnoreIPNOK(self): ipList = "", "999.999.999.999", "abcdef", "192.168.0." for ip in ipList: self.filter.addIgnoreIP(ip) self.assertFalse(self.filter.inIgnoreIPList(ip)) - # Test DNS - self.filter.addIgnoreIP("www.epfl.ch") - self.assertFalse(self.filter.inIgnoreIPList("127.177.50.10")) def testIgnoreIPCIDR(self): self.filter.addIgnoreIP('192.168.1.0/25') @@ -210,6 +201,22 @@ class IgnoreIP(LogCaptureTestCase): self.assertFalse(self._is_logged('Ignore 192.168.1.32')) self.assertTrue(self._is_logged('Requested to manually ban an ignored IP 192.168.1.32. User knows best. Proceeding to ban it.')) + +class IgnoreIPDNS(IgnoreIP): + + def testIgnoreIPDNSOK(self): + self.filter.addIgnoreIP("www.epfl.ch") + self.assertTrue(self.filter.inIgnoreIPList("128.178.50.12")) + + def testIgnoreIPDNSNOK(self): + # Test DNS + self.filter.addIgnoreIP("www.epfl.ch") + print self._log.getvalue() + self.assertFalse(self.filter.inIgnoreIPList("127.177.50.10")) + self.assertFalse(self.filter.inIgnoreIPList("128.178.50.11")) + self.assertFalse(self.filter.inIgnoreIPList("128.178.50.13")) + + class LogFile(unittest.TestCase): FILENAME = "testcases/files/testcase01.log" From 33d96ae4626d0b9d40afef39dfc5a02bafb7aeb1 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 12:10:44 +1100 Subject: [PATCH 096/125] TST: separate out DNS based IgnoreIP tests --- testcases/filtertestcase.py | 1 - 1 file changed, 1 deletion(-) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 46870d41..a4d0230f 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -211,7 +211,6 @@ class IgnoreIPDNS(IgnoreIP): def testIgnoreIPDNSNOK(self): # Test DNS self.filter.addIgnoreIP("www.epfl.ch") - print self._log.getvalue() self.assertFalse(self.filter.inIgnoreIPList("127.177.50.10")) self.assertFalse(self.filter.inIgnoreIPList("128.178.50.11")) self.assertFalse(self.filter.inIgnoreIPList("128.178.50.13")) From 5005719180bb7a344b00740851fc0b133233f0bb Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 12:34:26 +1100 Subject: [PATCH 097/125] TST: permission denied on log file --- testcases/filtertestcase.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index a4d0230f..000ff353 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -269,6 +269,11 @@ class LogFileMonitor(LogCaptureTestCase): # shorter wait time for not modified status return not self.isModified(0.4) + def testNoLogFile(self): + os.chmod(self.name, 0) + self.filter.getFailures(self.name) + self.assertTrue(self._is_logged('Unable to open %s' % self.name)) + def testRemovingFailRegex(self): self.filter.delFailRegex(0) self.assertFalse(self._is_logged('Cannot remove regular expression. Index 0 is not valid')) From a03815facf198472273918b0763d97dd61286ac7 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 11 Dec 2013 13:07:08 +1100 Subject: [PATCH 098/125] TST: FileFilter tail tests --- server/filter.py | 3 +++ testcases/filtertestcase.py | 8 +++++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/server/filter.py b/server/filter.py index 52bb8c4c..b92289ef 100644 --- a/server/filter.py +++ b/server/filter.py @@ -568,6 +568,9 @@ class FileContainer: def getFileName(self): return self.__filename + def getPos(self): + return self.__pos + def open(self): self.__handler = open(self.__filename) # Set the file descriptor to be FD_CLOEXEC diff --git a/testcases/filtertestcase.py b/testcases/filtertestcase.py index 000ff353..7b18c4bf 100644 --- a/testcases/filtertestcase.py +++ b/testcases/filtertestcase.py @@ -603,7 +603,13 @@ class GetFailures(unittest.TestCase): def tearDown(self): """Call after every test case.""" - + def testTail(self): + self.filter.addLogPath(LogFile.FILENAME, tail=True) + self.assertEqual(self.filter.getLogPath()[-1].getPos(), 1653) + self.filter.getLogPath()[-1].close() + self.assertEqual(self.filter.getLogPath()[-1].readline(), "") + self.filter.delLogPath(LogFile.FILENAME) + self.assertEqual(self.filter.getLogPath(),[]) def testGetFailures01(self, filename=None, failures=None): filename = filename or GetFailures.FILENAME_01 From f2c58e74c144b91c59b6f3fee9d48098a30f437e Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 08:24:29 +0000 Subject: [PATCH 099/125] TST: check client.JailReader.setName --- testcases/clientreadertestcase.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 773d5072..0e3e6132 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -114,6 +114,8 @@ class JailReaderTest(unittest.TestCase): self.assertTrue(jail.getOptions()) self.assertFalse(jail.isEnabled()) self.assertEqual(jail.getName(), 'ssh-iptables') + jail.setName('ssh-funky-blocker') + self.assertEqual(jail.getName(), 'ssh-funky-blocker') def testSplitAction(self): action = "mail-whois[name=SSH]" From 970fd5d2891f59c7ac3943d8c50715badbd1047c Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 08:52:01 +0000 Subject: [PATCH 100/125] BF: ensure dangling symlink error message is reachable $ ls -la /tmp/f2b-tempq0ipGY/f2 lrwxrwxrwx. 1 dan dan 11 Dec 12 08:42 /tmp/f2b-tempq0ipGY/f2 -> nonexisting In [3]: os.path.exists('/tmp/f2b-tempq0ipGY/f2') Out[3]: False In [4]: os.path.lexists('/tmp/f2b-tempq0ipGY/f2') Out[4]: True --- client/jailreader.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/client/jailreader.py b/client/jailreader.py index 7fbac423..8980431e 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -65,9 +65,10 @@ class JailReader(ConfigReader): pathList = [] for p in glob.glob(path): if not os.path.exists(p): - logSys.warning("File %s doesn't even exist, thus cannot be monitored" % p) - elif not os.path.lexists(p): - logSys.warning("File %s is a dangling link, thus cannot be monitored" % p) + if os.path.lexists(p): + logSys.warning("File %s is a dangling link, thus cannot be monitored" % p) + else: + logSys.warning("File %s doesn't even exist, thus cannot be monitored" % p) else: pathList.append(p) return pathList From f84a03d6b57b9a82fc42cd8e98dd71c11ddceeb8 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 09:08:42 +0000 Subject: [PATCH 101/125] BF: remove nonreachable parts of code Glob ensures the file exists so only a check that a missing dangling symlink needs to be done. $ ls -la /tmp/f2b-tempq0ipGY/f2 lrwxrwxrwx. 1 dan dan 11 Dec 12 08:42 /tmp/f2b-tempq0ipGY/f2 -> xisting In [3]: os.path.exists('/tmp/f2b-tempq0ipGY/f2') Out[3]: False In [4]: os.path.lexists('/tmp/f2b-tempq0ipGY/f2') Out[4]: True --- client/jailreader.py | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/client/jailreader.py b/client/jailreader.py index 8980431e..1c651fe9 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -64,13 +64,10 @@ class JailReader(ConfigReader): """ pathList = [] for p in glob.glob(path): - if not os.path.exists(p): - if os.path.lexists(p): - logSys.warning("File %s is a dangling link, thus cannot be monitored" % p) - else: - logSys.warning("File %s doesn't even exist, thus cannot be monitored" % p) - else: + if os.path.exists(p): pathList.append(p) + else: + logSys.warning("File %s is a dangling link, thus cannot be monitored" % p) return pathList def getOptions(self): From cb4f1e51422bd5976f1598995996ccaa4cf29cc9 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 09:10:12 +0000 Subject: [PATCH 102/125] TST: remove temp files in glob test --- testcases/clientreadertestcase.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 0e3e6132..7f85dbd9 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -135,6 +135,10 @@ class JailReaderTest(unittest.TestCase): self.assertEqual(JailReader._glob(os.path.join(d, '*')), [os.path.join(d, 'f1')]) # since f2 is dangling -- empty list self.assertEqual(JailReader._glob(os.path.join(d, 'f2')), []) + self.assertEqual(JailReader._glob(os.path.join(d, 'nonexisting')), []) + os.remove(os.path.join(d, 'f1')) + os.remove(os.path.join(d, 'f2')) + os.rmdir(d) class JailsReaderTest(unittest.TestCase): From 3036afca9167524e7cd54fb54fb63507f040fb12 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 10:13:57 +0000 Subject: [PATCH 103/125] TST: check dangling link log message --- testcases/clientreadertestcase.py | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 7f85dbd9..0937a5a5 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -27,6 +27,7 @@ from client.configreader import ConfigReader from client.jailreader import JailReader from client.jailsreader import JailsReader from client.configurator import Configurator +from utils import LogCaptureTestCase class ConfigReaderTest(unittest.TestCase): @@ -106,7 +107,7 @@ option = %s self.assertEqual(self._getoption(), 1) -class JailReaderTest(unittest.TestCase): +class JailReaderTest(LogCaptureTestCase): def testStockSSHJail(self): jail = JailReader('ssh-iptables', basedir='config') # we are running tests from root project dir atm @@ -127,17 +128,21 @@ class JailReaderTest(unittest.TestCase): d = tempfile.mkdtemp(prefix="f2b-temp") # Generate few files # regular file - open(os.path.join(d, 'f1'), 'w').close() + f1 = os.path.join(d, 'f1') + open(f1, 'w').close() # dangling link - os.symlink('nonexisting', os.path.join(d, 'f2')) + + f2 = os.path.join(d, 'f2') + os.symlink('nonexisting',f2) # must be only f1 - self.assertEqual(JailReader._glob(os.path.join(d, '*')), [os.path.join(d, 'f1')]) + self.assertEqual(JailReader._glob(os.path.join(d, '*')), [f1]) # since f2 is dangling -- empty list - self.assertEqual(JailReader._glob(os.path.join(d, 'f2')), []) + self.assertEqual(JailReader._glob(f2), []) + self.assertTrue(self._is_logged('File %s is a dangling link, thus cannot be monitored' % f2)) self.assertEqual(JailReader._glob(os.path.join(d, 'nonexisting')), []) - os.remove(os.path.join(d, 'f1')) - os.remove(os.path.join(d, 'f2')) + os.remove(f1) + os.remove(f2) os.rmdir(d) class JailsReaderTest(unittest.TestCase): From b18ce122dd236776d500799475b675d52d7840b8 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 20:07:09 +0000 Subject: [PATCH 104/125] BF/ENH: fix error when action doesn't match regex. Document unreachable code. Simplify regex --- client/jailreader.py | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/client/jailreader.py b/client/jailreader.py index 1c651fe9..2138acee 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -35,7 +35,7 @@ logSys = logging.getLogger("fail2ban.client.config") class JailReader(ConfigReader): - actionCRE = re.compile("^((?:\w|-|_|\.)+)(?:\[(.*)\])?$") + actionCRE = re.compile("^([\w_.-]+)(?:\[(.*)\])?$") def __init__(self, name, force_enable=False, **kwargs): ConfigReader.__init__(self, **kwargs) @@ -173,12 +173,16 @@ class JailReader(ConfigReader): def splitAction(action): m = JailReader.actionCRE.match(action) d = dict() - mgroups = m.groups() + try: + mgroups = m.groups() + except AttributeError: + raise ValueError("While reading action %s we should have got 1 or " + "2 groups. Got: 0" % action) if len(mgroups) == 2: action_name, action_opts = mgroups elif len(mgroups) == 1: action_name, action_opts = mgroups[0], None - else: + else: # pragma: nocover - unreachable - regex only can capture 2 groups raise ValueError("While reading action %s we should have got up to " "2 groups. Got: %r" % (action, mgroups)) if not action_opts is None: From c6d14dcf0eedef9513b3b5fb5b028ff301908734 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Thu, 12 Dec 2013 20:35:30 +0000 Subject: [PATCH 105/125] TST: complete coverage of splitAction --- client/jailreader.py | 2 +- testcases/clientreadertestcase.py | 12 ++++++++++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/client/jailreader.py b/client/jailreader.py index 2138acee..131a4dd5 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -180,7 +180,7 @@ class JailReader(ConfigReader): "2 groups. Got: 0" % action) if len(mgroups) == 2: action_name, action_opts = mgroups - elif len(mgroups) == 1: + elif len(mgroups) == 1: # pragma: nocover - unreachable - .* on second group always matches action_name, action_opts = mgroups[0], None else: # pragma: nocover - unreachable - regex only can capture 2 groups raise ValueError("While reading action %s we should have got up to " diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 0937a5a5..c22f028a 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -123,7 +123,19 @@ class JailReaderTest(LogCaptureTestCase): expected = ['mail-whois', {'name': 'SSH'}] result = JailReader.splitAction(action) self.assertEqual(expected, result) + + self.assertEqual(['mail.who_is', {}], JailReader.splitAction("mail.who_is")) + self.assertEqual(['mail.who_is', {'a':'cat', 'b':'dog'}], JailReader.splitAction("mail.who_is[a=cat,b=dog]")) + self.assertEqual(['mail--ho_is', {}], JailReader.splitAction("mail--ho_is")) + + self.assertEqual(['mail--ho_is', {}], JailReader.splitAction("mail--ho_is['s']")) + self.assertTrue(self._is_logged("Invalid argument ['s'] in ''s''")) + + self.assertEqual(['mail', {'a': ','}], JailReader.splitAction("mail[a=',']")) + self.assertRaises(ValueError, JailReader.splitAction ,'mail-how[') + + def testGlob(self): d = tempfile.mkdtemp(prefix="f2b-temp") # Generate few files From 3ddf8da76e6c69e0f91c9f2fdebba96f9932eff3 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 08:45:10 +0000 Subject: [PATCH 106/125] ENH: ensure filter is defined in jail before its read --- client/jailreader.py | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/client/jailreader.py b/client/jailreader.py index 131a4dd5..1b5bf1ae 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -87,15 +87,18 @@ class JailReader(ConfigReader): if self.isEnabled(): # Read filter - self.__filter = FilterReader(self.__opts["filter"], self.__name, - basedir=self.getBaseDir()) - ret = self.__filter.read() - if ret: - self.__filter.getOptions(self.__opts) + if self.__opts["filter"]: + self.__filter = FilterReader(self.__opts["filter"], self.__name, + basedir=self.getBaseDir()) + ret = self.__filter.read() + if ret: + self.__filter.getOptions(self.__opts) + else: + logSys.error("Unable to read the filter") + return False else: - logSys.error("Unable to read the filter") - return False - + logSys.warn("No filter set for jail %s" % self.__name) + # Read action for act in self.__opts["action"].split('\n'): try: From d74dd31d2301d7e0c5479192405bdc55a70b3c62 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 10:00:34 +0000 Subject: [PATCH 107/125] BF: corrected tests for missing jail Previously tests relied on the missing filter to trigger the conditions required for a missing jail. We now handle this explicitly. --- client/configreader.py | 2 +- client/jailreader.py | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/client/configreader.py b/client/configreader.py index 96aab5f3..470f029f 100644 --- a/client/configreader.py +++ b/client/configreader.py @@ -112,7 +112,7 @@ class ConfigReader(SafeConfigParserWithIncludes): except NoSectionError, e: # No "Definition" section or wrong basedir logSys.error(e) - values[option[1]] = option[2] + return False except NoOptionError: if not option[2] is None: logSys.warn("'%s' not defined in '%s'. Using default one: %r" diff --git a/client/jailreader.py b/client/jailreader.py index 1b5bf1ae..d7c7b84c 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -54,7 +54,7 @@ class JailReader(ConfigReader): return ConfigReader.read(self, "jail") def isEnabled(self): - return self.__force_enable or self.__opts["enabled"] + return self.__force_enable or ( self.__opts and self.__opts["enabled"] ) @staticmethod def _glob(path): @@ -84,6 +84,8 @@ class JailReader(ConfigReader): ["string", "filter", ""], ["string", "action", ""]] self.__opts = ConfigReader.getOptions(self, self.__name, opts) + if not self.__opts: + return False if self.isEnabled(): # Read filter From 1407b955e6673c025c8bd6252f7daca1251ea477 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 10:03:51 +0000 Subject: [PATCH 108/125] TST: more client/jailreader tests --- MANIFEST | 4 ++++ testcases/clientreadertestcase.py | 19 ++++++++++++++++++- testcases/config/action.d/brokenaction.conf | 4 ++++ testcases/config/fail2ban.conf | 5 +++++ testcases/config/filter.d/simple.conf | 4 ++++ testcases/config/jail.conf | 20 ++++++++++++++++++++ 6 files changed, 55 insertions(+), 1 deletion(-) create mode 100644 testcases/config/action.d/brokenaction.conf create mode 100644 testcases/config/fail2ban.conf create mode 100644 testcases/config/filter.d/simple.conf create mode 100644 testcases/config/jail.conf diff --git a/MANIFEST b/MANIFEST index 0e0eb327..a7fefd5c 100644 --- a/MANIFEST +++ b/MANIFEST @@ -242,3 +242,7 @@ files/fail2ban-tmpfiles.conf files/fail2ban.service files/ipmasq-ZZZzzz_fail2ban.rul files/gen_badbots +testcases/config/jail.conf +testcases/config/fail2ban.conf +testcases/config/filter.d/simple.conf +testcases/config/action.d/brokenaction.conf diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index c22f028a..2dec428e 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -109,6 +109,22 @@ option = %s class JailReaderTest(LogCaptureTestCase): + def testJailActionEmpty(self): + jail = JailReader('emptyaction', basedir=os.path.join('testcases','config')) + self.assertTrue(jail.read()) + self.assertTrue(jail.getOptions()) + self.assertTrue(jail.isEnabled()) + self.assertTrue(self._is_logged('No filter set for jail emptyaction')) + self.assertTrue(self._is_logged('No actions were defined for emptyaction')) + + def testJailActionBrokenDef(self): + jail = JailReader('brokenactiondef', basedir=os.path.join('testcases','config')) + self.assertTrue(jail.read()) + self.assertFalse(jail.getOptions()) + self.assertTrue(jail.isEnabled()) + self.assertTrue(self._is_logged('Error in action definition joho[foo')) + self.assertTrue(self._is_logged('Caught exception: While reading action joho[foo we should have got 1 or 2 groups. Got: 0')) + def testStockSSHJail(self): jail = JailReader('ssh-iptables', basedir='config') # we are running tests from root project dir atm self.assertTrue(jail.read()) @@ -157,7 +173,7 @@ class JailReaderTest(LogCaptureTestCase): os.remove(f2) os.rmdir(d) -class JailsReaderTest(unittest.TestCase): +class JailsReaderTest(LogCaptureTestCase): def testProvidingBadBasedir(self): if not os.path.exists('/XXX'): @@ -176,6 +192,7 @@ class JailsReaderTest(unittest.TestCase): # We should not "read" some bogus jail old_comm_commands = comm_commands[:] # make a copy self.assertFalse(jails.getOptions("BOGUS")) + self.assertTrue(self._is_logged("No section: 'BOGUS'")) # and there should be no side-effects self.assertEqual(jails.convert(), old_comm_commands) diff --git a/testcases/config/action.d/brokenaction.conf b/testcases/config/action.d/brokenaction.conf new file mode 100644 index 00000000..d2c8d059 --- /dev/null +++ b/testcases/config/action.d/brokenaction.conf @@ -0,0 +1,4 @@ + +[Definition] + +actioban = hit with big stick diff --git a/testcases/config/fail2ban.conf b/testcases/config/fail2ban.conf new file mode 100644 index 00000000..36984c78 --- /dev/null +++ b/testcases/config/fail2ban.conf @@ -0,0 +1,5 @@ +[Definition] + +# 3 = INFO +loglevel = 3 + diff --git a/testcases/config/filter.d/simple.conf b/testcases/config/filter.d/simple.conf new file mode 100644 index 00000000..4a2c0bb7 --- /dev/null +++ b/testcases/config/filter.d/simple.conf @@ -0,0 +1,4 @@ + +[Definition] + +failregex = diff --git a/testcases/config/jail.conf b/testcases/config/jail.conf new file mode 100644 index 00000000..419e2e2c --- /dev/null +++ b/testcases/config/jail.conf @@ -0,0 +1,20 @@ + +[DEFAULT] +filter = simple + +[emptyaction] +enabled = true +filter = +action = + +[brokenactiondef] +enabled = true +action = joho[foo + +[brokenaction] +enabled = true +action = brokenaction + +[missingaction] +enabled = true +action = thefunkychickendance From e916fcdce4cd5a0b927644c9f79e75375e8141d0 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 10:51:38 +0000 Subject: [PATCH 109/125] TST: test case for actions and filters missing in a jail --- testcases/clientreadertestcase.py | 9 +++++++++ testcases/config/jail.conf | 4 ++-- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 2dec428e..e85ddff8 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -117,6 +117,15 @@ class JailReaderTest(LogCaptureTestCase): self.assertTrue(self._is_logged('No filter set for jail emptyaction')) self.assertTrue(self._is_logged('No actions were defined for emptyaction')) + def testJailActionFilterMissing(self): + jail = JailReader('missingbitsjail', basedir=os.path.join('testcases','config')) + self.assertTrue(jail.read()) + self.assertFalse(jail.getOptions()) + self.assertTrue(jail.isEnabled()) + #print self._log.getvalue() + self.assertTrue(self._is_logged("Found no accessible config files for 'filter.d/catchallthebadies' under testcases/config")) + self.assertTrue(self._is_logged('Unable to read the filter')) + def testJailActionBrokenDef(self): jail = JailReader('brokenactiondef', basedir=os.path.join('testcases','config')) self.assertTrue(jail.read()) diff --git a/testcases/config/jail.conf b/testcases/config/jail.conf index 419e2e2c..4bdd74cf 100644 --- a/testcases/config/jail.conf +++ b/testcases/config/jail.conf @@ -15,6 +15,6 @@ action = joho[foo enabled = true action = brokenaction -[missingaction] -enabled = true +[missingbitsjail] +filter = catchallthebadies action = thefunkychickendance From f6fb737e6cece7d535e64a848fcc0b137519e51c Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 10:55:15 +0000 Subject: [PATCH 110/125] TST: remove commented test print --- testcases/clientreadertestcase.py | 1 - 1 file changed, 1 deletion(-) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index e85ddff8..96f9134f 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -122,7 +122,6 @@ class JailReaderTest(LogCaptureTestCase): self.assertTrue(jail.read()) self.assertFalse(jail.getOptions()) self.assertTrue(jail.isEnabled()) - #print self._log.getvalue() self.assertTrue(self._is_logged("Found no accessible config files for 'filter.d/catchallthebadies' under testcases/config")) self.assertTrue(self._is_logged('Unable to read the filter')) From 2f3648c458e675de99acac6fef0a506c49a0daac Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 11:11:58 +0000 Subject: [PATCH 111/125] DOC: add missing jail directives --- man/jail.conf.5 | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/man/jail.conf.5 b/man/jail.conf.5 index 8ea44316..6c114c56 100644 --- a/man/jail.conf.5 +++ b/man/jail.conf.5 @@ -63,6 +63,12 @@ Comments: use '#' for comment lines and ';' (following a space) for inline comme .SH DEFAULT The following options are applicable to all jails. Their meaning is described in the default \fIjail.conf\fR file. .TP +\fBfilter\fR +.TP +\fBlogpath\fR +.TP +\fBaction\fR +.TP \fBignoreip\fR .TP \fBbantime\fR @@ -74,6 +80,10 @@ The following options are applicable to all jails. Their meaning is described in \fBbackend\fR .TP \fBusedns\fR +.TP +\fBfailregex\fR +.TP +\fBignoreregex\fR .SH "ACTION FILES" From b147270be769ff5b456e29d56d12d27dacd95480 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 11:36:00 +0000 Subject: [PATCH 112/125] BF: allow processing with empty filter --- client/jailreader.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/client/jailreader.py b/client/jailreader.py index d7c7b84c..6f78275b 100644 --- a/client/jailreader.py +++ b/client/jailreader.py @@ -99,6 +99,7 @@ class JailReader(ConfigReader): logSys.error("Unable to read the filter") return False else: + self.__filter = None logSys.warn("No filter set for jail %s" % self.__name) # Read action @@ -168,7 +169,8 @@ class JailReader(ConfigReader): # Do not send a command if the rule is empty. if regex != '': stream.append(["set", self.__name, "addignoreregex", regex]) - stream.extend(self.__filter.convert()) + if self.__filter: + stream.extend(self.__filter.convert()) for action in self.__actions: stream.extend(action.convert()) stream.insert(0, ["add", self.__name, backend]) From 18f0e58caad68212e84f711526e3e1857ae7ae7b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 11:41:40 +0000 Subject: [PATCH 113/125] TST: increase coverage in jailreader --- testcases/clientreadertestcase.py | 32 +++++++++++++++++++++++++++++++ testcases/config/jail.conf | 12 ++++++++++++ 2 files changed, 44 insertions(+) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 96f9134f..f55be051 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -188,6 +188,38 @@ class JailsReaderTest(LogCaptureTestCase): reader = JailsReader(basedir='/XXX') self.assertRaises(ValueError, reader.read) + def testReadTestJailConf(self): + jails = JailsReader(basedir=os.path.join('testcases','config')) + self.assertTrue(jails.read()) # opens fine + self.assertFalse(jails.getOptions()) # reads not sof ine + self.assertRaises(ValueError, jails.convert) + comm_commands = jails.convert(allow_no_files=True) + self.maxDiff = None + self.assertEqual(comm_commands, + [['add', 'emptyaction', 'auto'], + ['set', 'emptyaction', 'usedns', 'warn'], + ['set', 'emptyaction', 'addlogpath', '/var/log/messages'], + ['set', 'emptyaction', 'maxretry', 3], + ['set', 'emptyaction', 'findtime', 600], + ['set', 'emptyaction', 'bantime', 600], + ['add', 'special', 'auto'], + ['set', 'special', 'usedns', 'warn'], + ['set', 'special', 'addlogpath', '/var/log/messages'], + ['set', 'special', 'maxretry', 3], + ['set', 'special', 'addfailregex', ''], + ['set', 'special', 'findtime', 600], + ['set', 'special', 'bantime', 600], + ['add', 'missinglogfiles', 'auto'], + ['set', 'missinglogfiles', 'usedns', 'warn'], + ['set', 'missinglogfiles', 'maxretry', 3], + ['set', 'missinglogfiles', 'findtime', 600], + ['set', 'missinglogfiles', 'bantime', 600], + ['set', 'missinglogfiles', 'addfailregex', ''], + ['start', 'emptyaction'], + ['start', 'special'], + ['start', 'missinglogfiles']]) + + def testReadStockJailConf(self): jails = JailsReader(basedir='config') # we are running tests from root project dir atm self.assertTrue(jails.read()) # opens fine diff --git a/testcases/config/jail.conf b/testcases/config/jail.conf index 4bdd74cf..ab791451 100644 --- a/testcases/config/jail.conf +++ b/testcases/config/jail.conf @@ -7,6 +7,14 @@ enabled = true filter = action = +[special] +failregex = +ignoreregex = +ignoreip = + +[missinglogfiles] +logpath = /weapons/of/mass/destruction + [brokenactiondef] enabled = true action = joho[foo @@ -18,3 +26,7 @@ action = brokenaction [missingbitsjail] filter = catchallthebadies action = thefunkychickendance + +[parse_to_end_of_jail.conf] +enabled = true +action = From 13ccebe78f2c9eafc148382559a79ced32354b50 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Fri, 13 Dec 2013 23:40:51 +0000 Subject: [PATCH 114/125] BF: fix actioncheck in firewallcmd --- ChangeLog | 1 + THANKS | 1 + config/action.d/firewallcmd-new.conf | 2 +- 3 files changed, 3 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index a0624630..0eca4e37 100644 --- a/ChangeLog +++ b/ChangeLog @@ -26,6 +26,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better settings. Closes gh-458, Debian bug #697333, Redhat bug #891798. - complain action - ensure where not matching other IPs in log sample. Closes gh-467 + - Fix firewall-cmd actioncheck - patch from Adam Tkac. Redhat Bug #979622 - Enhancements: - long names on jails documented based on iptables limit of 30 less diff --git a/THANKS b/THANKS index 6d4845bb..e448e09e 100644 --- a/THANKS +++ b/THANKS @@ -6,6 +6,7 @@ the project. If you have been left off, please let us know (preferably send a pull request on github with the "fix") and you will be added +Adam Tkac Adrien Clerc ache ag4ve (Shawn) diff --git a/config/action.d/firewallcmd-new.conf b/config/action.d/firewallcmd-new.conf index 55b6762d..d3443e4e 100644 --- a/config/action.d/firewallcmd-new.conf +++ b/config/action.d/firewallcmd-new.conf @@ -20,7 +20,7 @@ actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state firewall-cmd --direct --remove-rules ipv4 filter fail2ban- firewall-cmd --direct --remove-chain ipv4 filter fail2ban- -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'fail2ban-[ \t]' +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -Eq 'fail2ban-$|fail2ban- ' actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j From b39729a2ab1abea9835fb4f5377c60d56308df9b Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 14 Dec 2013 06:51:36 +0000 Subject: [PATCH 115/125] BF: fix unintential typo --- testcases/config/action.d/brokenaction.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/testcases/config/action.d/brokenaction.conf b/testcases/config/action.d/brokenaction.conf index d2c8d059..59e97b7f 100644 --- a/testcases/config/action.d/brokenaction.conf +++ b/testcases/config/action.d/brokenaction.conf @@ -1,4 +1,4 @@ [Definition] -actioban = hit with big stick +actionban = hit with big stick From 603095bc16ff08798cf16b789bc0360aa62ed112 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 14 Dec 2013 07:00:41 +0000 Subject: [PATCH 116/125] BF: errors in a jail prevents further sections from being parsed. Closes #485 --- client/jailsreader.py | 5 +++-- testcases/clientreadertestcase.py | 30 +++++++++++++++++++++++++++++- 2 files changed, 32 insertions(+), 3 deletions(-) diff --git a/client/jailsreader.py b/client/jailsreader.py index 00c63e3c..d32e6561 100644 --- a/client/jailsreader.py +++ b/client/jailsreader.py @@ -60,6 +60,7 @@ class JailsReader(ConfigReader): sections = [ section ] # Get the options of all jails. + parse_status = True for sec in sections: jail = JailReader(sec, basedir=self.getBaseDir(), force_enable=self.__force_enable) @@ -71,8 +72,8 @@ class JailsReader(ConfigReader): self.__jails.append(jail) else: logSys.error("Errors in jail %r. Skipping..." % sec) - return False - return True + parse_status = False + return parse_status def convert(self, allow_no_files=False): """Convert read before __opts and jails to the commands stream diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index f55be051..91689836 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -215,9 +215,37 @@ class JailsReaderTest(LogCaptureTestCase): ['set', 'missinglogfiles', 'findtime', 600], ['set', 'missinglogfiles', 'bantime', 600], ['set', 'missinglogfiles', 'addfailregex', ''], + ['add', 'brokenaction', 'auto'], + ['set', 'brokenaction', 'usedns', 'warn'], + ['set', 'brokenaction', 'addlogpath', '/var/log/messages'], + ['set', 'brokenaction', 'maxretry', 3], + ['set', 'brokenaction', 'findtime', 600], + ['set', 'brokenaction', 'bantime', 600], + ['set', 'brokenaction', 'addfailregex', ''], + ['set', 'brokenaction', 'addaction', 'brokenaction'], + ['set', + 'brokenaction', + 'actionban', + 'brokenaction', + 'hit with big stick '], + ['set', 'brokenaction', 'actionstop', 'brokenaction', ''], + ['set', 'brokenaction', 'actionstart', 'brokenaction', ''], + ['set', 'brokenaction', 'actionunban', 'brokenaction', ''], + ['set', 'brokenaction', 'actioncheck', 'brokenaction', ''], + ['add', 'parse_to_end_of_jail.conf', 'auto'], + ['set', 'parse_to_end_of_jail.conf', 'usedns', 'warn'], + ['set', 'parse_to_end_of_jail.conf', 'addlogpath', '/var/log/messages'], + ['set', 'parse_to_end_of_jail.conf', 'maxretry', 3], + ['set', 'parse_to_end_of_jail.conf', 'findtime', 600], + ['set', 'parse_to_end_of_jail.conf', 'bantime', 600], + ['set', 'parse_to_end_of_jail.conf', 'addfailregex', ''], ['start', 'emptyaction'], ['start', 'special'], - ['start', 'missinglogfiles']]) + ['start', 'missinglogfiles'], + ['start', 'brokenaction'], + ['start', 'parse_to_end_of_jail.conf'],]) + self.assertTrue(self._is_logged("Errors in jail 'missingbitsjail'. Skipping...")) + self.assertTrue(self._is_logged("No file(s) found for glob /weapons/of/mass/destruction")) def testReadStockJailConf(self): From 4ffc57e14f1254942c88c9d9f94e9ef791af5e5f Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sat, 14 Dec 2013 07:11:29 +0000 Subject: [PATCH 117/125] ENH: simplify firewallcmd-new actioncheck and provide output samples --- config/action.d/firewallcmd-new.conf | 30 +++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/config/action.d/firewallcmd-new.conf b/config/action.d/firewallcmd-new.conf index d3443e4e..7a5c03de 100644 --- a/config/action.d/firewallcmd-new.conf +++ b/config/action.d/firewallcmd-new.conf @@ -1,9 +1,5 @@ # Fail2Ban configuration file # -# Author: Edgar Hoch -# Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. -# It uses "firewall-cmd" instead of "iptables". -# # Because of the --remove-rules in stop this action requires firewalld-0.3.8+ [INCLUDES] @@ -20,7 +16,7 @@ actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state firewall-cmd --direct --remove-rules ipv4 filter fail2ban- firewall-cmd --direct --remove-chain ipv4 filter fail2ban- -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -Eq 'fail2ban-$|fail2ban- ' +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -Eq 'fail2ban-( |$)' actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j @@ -50,3 +46,27 @@ protocol = tcp # Values: [ STRING ] # chain = INPUT_direct + +# DEV NOTES: +# +# Author: Edgar Hoch +# Copied from iptables-new.conf and modified for use with firewalld by Edgar Hoch. +# It uses "firewall-cmd" instead of "iptables". +# +# Output: +# +# $ firewall-cmd --direct --add-chain ipv4 filter fail2ban-name +# success +# $ firewall-cmd --direct --add-rule ipv4 filter fail2ban-name 1000 -j RETURN +# success +# $ sudo firewall-cmd --direct --add-rule ipv4 filter INPUT_direct 0 -m state --state NEW -p tcp --dport 22 -j fail2ban-name +# success +# $ firewall-cmd --direct --get-chains ipv4 filter +# fail2ban-name +# $ firewall-cmd --direct --get-chains ipv4 filter | od -h +# 0000000 6166 6c69 6232 6e61 6e2d 6d61 0a65 +# $ firewall-cmd --direct --get-chains ipv4 filter | grep -Eq 'fail2ban-name( |$)' ; echo $? +# 0 +# $ firewall-cmd -V +# 0.3.8 + From a398c51d6c49ac5de70f9eee68f8c72c1fed10ba Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Sun, 15 Dec 2013 22:36:47 +0000 Subject: [PATCH 118/125] ENH: simplify actioncheck on firewallcmd-new a little more --- config/action.d/firewallcmd-new.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/action.d/firewallcmd-new.conf b/config/action.d/firewallcmd-new.conf index 7a5c03de..bae72ca2 100644 --- a/config/action.d/firewallcmd-new.conf +++ b/config/action.d/firewallcmd-new.conf @@ -16,7 +16,7 @@ actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state firewall-cmd --direct --remove-rules ipv4 filter fail2ban- firewall-cmd --direct --remove-chain ipv4 filter fail2ban- -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -Eq 'fail2ban-( |$)' +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q '^fail2ban-$' actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j From 5c26bcbd2b24328a4fc85be0360090ee787bf6d9 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 16 Dec 2013 10:07:41 +0000 Subject: [PATCH 119/125] TST: hopefully normalise config so that consistent test results occur on travis and locally --- testcases/clientreadertestcase.py | 4 ---- testcases/config/jail.conf | 1 + 2 files changed, 1 insertion(+), 4 deletions(-) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 91689836..42c3fa28 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -198,13 +198,11 @@ class JailsReaderTest(LogCaptureTestCase): self.assertEqual(comm_commands, [['add', 'emptyaction', 'auto'], ['set', 'emptyaction', 'usedns', 'warn'], - ['set', 'emptyaction', 'addlogpath', '/var/log/messages'], ['set', 'emptyaction', 'maxretry', 3], ['set', 'emptyaction', 'findtime', 600], ['set', 'emptyaction', 'bantime', 600], ['add', 'special', 'auto'], ['set', 'special', 'usedns', 'warn'], - ['set', 'special', 'addlogpath', '/var/log/messages'], ['set', 'special', 'maxretry', 3], ['set', 'special', 'addfailregex', ''], ['set', 'special', 'findtime', 600], @@ -217,7 +215,6 @@ class JailsReaderTest(LogCaptureTestCase): ['set', 'missinglogfiles', 'addfailregex', ''], ['add', 'brokenaction', 'auto'], ['set', 'brokenaction', 'usedns', 'warn'], - ['set', 'brokenaction', 'addlogpath', '/var/log/messages'], ['set', 'brokenaction', 'maxretry', 3], ['set', 'brokenaction', 'findtime', 600], ['set', 'brokenaction', 'bantime', 600], @@ -234,7 +231,6 @@ class JailsReaderTest(LogCaptureTestCase): ['set', 'brokenaction', 'actioncheck', 'brokenaction', ''], ['add', 'parse_to_end_of_jail.conf', 'auto'], ['set', 'parse_to_end_of_jail.conf', 'usedns', 'warn'], - ['set', 'parse_to_end_of_jail.conf', 'addlogpath', '/var/log/messages'], ['set', 'parse_to_end_of_jail.conf', 'maxretry', 3], ['set', 'parse_to_end_of_jail.conf', 'findtime', 600], ['set', 'parse_to_end_of_jail.conf', 'bantime', 600], diff --git a/testcases/config/jail.conf b/testcases/config/jail.conf index ab791451..525308e3 100644 --- a/testcases/config/jail.conf +++ b/testcases/config/jail.conf @@ -1,6 +1,7 @@ [DEFAULT] filter = simple +logpath = /non/exist [emptyaction] enabled = true From 729929ada98f63558ae8cd61586868173bc234ef Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Mon, 16 Dec 2013 10:21:46 +0000 Subject: [PATCH 120/125] TST: jails can occur in any order once parsed. Sort results to facilitate comparison --- testcases/clientreadertestcase.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/testcases/clientreadertestcase.py b/testcases/clientreadertestcase.py index 42c3fa28..28387703 100644 --- a/testcases/clientreadertestcase.py +++ b/testcases/clientreadertestcase.py @@ -190,13 +190,13 @@ class JailsReaderTest(LogCaptureTestCase): def testReadTestJailConf(self): jails = JailsReader(basedir=os.path.join('testcases','config')) - self.assertTrue(jails.read()) # opens fine - self.assertFalse(jails.getOptions()) # reads not sof ine + self.assertTrue(jails.read()) + self.assertFalse(jails.getOptions()) self.assertRaises(ValueError, jails.convert) comm_commands = jails.convert(allow_no_files=True) self.maxDiff = None - self.assertEqual(comm_commands, - [['add', 'emptyaction', 'auto'], + self.assertEqual(sorted(comm_commands), + sorted([['add', 'emptyaction', 'auto'], ['set', 'emptyaction', 'usedns', 'warn'], ['set', 'emptyaction', 'maxretry', 3], ['set', 'emptyaction', 'findtime', 600], @@ -239,7 +239,7 @@ class JailsReaderTest(LogCaptureTestCase): ['start', 'special'], ['start', 'missinglogfiles'], ['start', 'brokenaction'], - ['start', 'parse_to_end_of_jail.conf'],]) + ['start', 'parse_to_end_of_jail.conf'],])) self.assertTrue(self._is_logged("Errors in jail 'missingbitsjail'. Skipping...")) self.assertTrue(self._is_logged("No file(s) found for glob /weapons/of/mass/destruction")) From 5f623596ee3d96d433458c3106e0f44cd7be04f6 Mon Sep 17 00:00:00 2001 From: alasdairdc Date: Tue, 17 Dec 2013 17:45:50 +0000 Subject: [PATCH 121/125] Updated check_fail2ban to return performance data for all jails Allows perf data from all jails to enable pnp4nagios to display a chart per jail when run with the command: check_fail2ban -p -w 1 -c 5 -P /usr/bin/fail2ban-client sample output: CHECK FAIL2BAN ACTIVITY - CRITICAL - 9 detected jails with 5 current banned IP(s) | apache-noscript.currentBannedIP=0 sendmail.currentBannedIP=0 postfix.currentBannedIP=0 ssh-probe.currentBannedIP=3 ssh-ddos.currentBannedIP=0 apache-multiport.currentBannedIP=0 apache.currentBannedIP=0 ssh.currentBannedIP=2 apache-overflows.currentBannedIP=0 --- files/nagios/check_fail2ban | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/files/nagios/check_fail2ban b/files/nagios/check_fail2ban index 77a63393..afde57d9 100755 --- a/files/nagios/check_fail2ban +++ b/files/nagios/check_fail2ban @@ -165,7 +165,7 @@ if (($critical < 0) or ($warning < 0) or ($critical < $warning)) { # Core script # ----------- -my ($how_many_jail,$how_many_banned,$return_print,$plugstate) = (0,0,"","OK"); +my ($how_many_jail,$how_many_banned,$return_print,$perf_print,$plugstate) = (0,0,"","","OK"); ### Test the connection to the fail2ban server @@ -214,6 +214,7 @@ else { else { print "DEBUG : the jail $jail_name has currently $current_ban_number banned IPs\n" if ($verbose_value); $how_many_banned += int($current_ban_number); + $perf_print .= "$jail_name.currentBannedIP=$current_ban_number " if ($perfdata_value); } } $return_print = $how_many_jail.' detected jails with '.$how_many_banned.' current banned IP(s)'; @@ -224,7 +225,7 @@ $plugstate = "CRITICAL" if ($how_many_banned >= $critical); $plugstate = "WARNING" if (($how_many_banned >= $warning) && ($how_many_banned < $critical)); $return_print = $display." - ".$plugstate." - ".$return_print; -$return_print .= " | currentBannedIP=$how_many_banned" if ($perfdata_value); +$return_print .= " | $perf_print" if ($perfdata_value); print $return_print; exit $ERRORS{"$plugstate"}; From 2e5a2b26fbd433a82016deae68dabd0d7a051c77 Mon Sep 17 00:00:00 2001 From: alasdairdc Date: Tue, 17 Dec 2013 17:48:19 +0000 Subject: [PATCH 122/125] Updated check_fail2ban to return performance data for all jails and applied to specific jail code --- files/nagios/check_fail2ban | 1 + 1 file changed, 1 insertion(+) diff --git a/files/nagios/check_fail2ban b/files/nagios/check_fail2ban index afde57d9..9bf14305 100755 --- a/files/nagios/check_fail2ban +++ b/files/nagios/check_fail2ban @@ -190,6 +190,7 @@ if ($jail_specific) { else { $how_many_banned = int($current_ban_number); $return_print = $how_many_banned.' current banned IP(s) for the specific jail '.$jail_specific; + $perf_print .= "$jail_name.currentBannedIP=$current_ban_number " if ($perfdata_value); } } ### To analyze all the jail From 4e4f194457c89253c75d5734eb185446129e489b Mon Sep 17 00:00:00 2001 From: alasdairdc Date: Wed, 18 Dec 2013 08:31:54 +0000 Subject: [PATCH 123/125] Updated Thanks. --- THANKS | 1 + 1 file changed, 1 insertion(+) diff --git a/THANKS b/THANKS index e448e09e..84f96b9a 100644 --- a/THANKS +++ b/THANKS @@ -10,6 +10,7 @@ Adam Tkac Adrien Clerc ache ag4ve (Shawn) +Alasdair D. Campbell Amir Caspi Andrey G. Grozin Andy Fragen From 04c267c307c670b17c0f7572a20a104d165d044e Mon Sep 17 00:00:00 2001 From: alasdairdc Date: Wed, 18 Dec 2013 08:36:30 +0000 Subject: [PATCH 124/125] Updated Changelog --- ChangeLog | 1 + 1 file changed, 1 insertion(+) diff --git a/ChangeLog b/ChangeLog index 0eca4e37..77fd6a03 100644 --- a/ChangeLog +++ b/ChangeLog @@ -34,6 +34,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - remove indentation of name and loglevel while logging to SYSLOG to resolve syslog(-ng) parsing problems. Closes Debian bug #730202. - added squid filter. Thanks Roman Gelfand. + - updated check_fail2ban to return performance data for all jails. - New Features: From d22716ab63a6e38c3f2c5c40c15c9fd2e2d3c421 Mon Sep 17 00:00:00 2001 From: Steven Hiscocks Date: Wed, 18 Dec 2013 22:31:54 +0000 Subject: [PATCH 125/125] ENH: Add nsd filter and amend DateEpoch to match date format --- ChangeLog | 2 ++ THANKS | 1 + config/filter.d/nsd.conf | 26 ++++++++++++++++++++++++++ server/datetemplate.py | 2 +- testcases/files/logs/nsd | 4 ++++ 5 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 config/filter.d/nsd.conf create mode 100644 testcases/files/logs/nsd diff --git a/ChangeLog b/ChangeLog index 77fd6a03..e9b3d638 100644 --- a/ChangeLog +++ b/ChangeLog @@ -40,6 +40,8 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better Daniel Black * filter.d/solid-pop3d -- added thanks to Jacques Lav!gnotte on mailinglist. + Bas van den Dikkenberg & Steven Hiscocks + * filter.d/nsd.conf -- also amended Unix date template to match nsd format - Enhancements: - loglines now also report "[PID]" after the name portion diff --git a/THANKS b/THANKS index 84f96b9a..b9b86043 100644 --- a/THANKS +++ b/THANKS @@ -16,6 +16,7 @@ Andrey G. Grozin Andy Fragen Arturo 'Buanzo' Busleiman Axel Thimm +Bas van den Dikkenberg Beau Raines Bill Heaton Carlos Alberto Lopez Perez diff --git a/config/filter.d/nsd.conf b/config/filter.d/nsd.conf new file mode 100644 index 00000000..cd4ce35f --- /dev/null +++ b/config/filter.d/nsd.conf @@ -0,0 +1,26 @@ +# Fail2Ban configuration file +# +# Author: Bas van den Dikkenberg +# +# + +[INCLUDES] + +# Read common prefixes. If any customizations available -- read them from +# common.local +before = common.conf + + +[Definition] + +_daemon = nsd + +# Option: failregex +# Notes.: regex to match the password failures messages in the logfile. The +# host must be matched by a group named "host". The tag "" can +# be used for standard IP/hostname matching and is only an alias for +# (?:::f{4,6}:)?(?P[\w\-.^_]+) +# Values: TEXT + +failregex = ^\[\]%(__prefix_line)sinfo: ratelimit block .* query TYPE255$ + ^\[\]%(__prefix_line)sinfo: .* refused, no acl matches\.$ diff --git a/server/datetemplate.py b/server/datetemplate.py index decaee1c..33c69703 100644 --- a/server/datetemplate.py +++ b/server/datetemplate.py @@ -78,7 +78,7 @@ class DateEpoch(DateTemplate): def __init__(self): DateTemplate.__init__(self) - self.setRegex("(?:^|(?P(?<=audit\()))\d{10}(?:\.\d{3,6})?(?(selinux)(?=:\d+\)))") + self.setRegex("(?:^|(?P(?<=^\[))|(?P(?<=audit\()))\d{10}(?:\.\d{3,6})?(?(selinux)(?=:\d+\))(?(square)(?=\])))") def getDate(self, line): date = None diff --git a/testcases/files/logs/nsd b/testcases/files/logs/nsd new file mode 100644 index 00000000..a33a52a9 --- /dev/null +++ b/testcases/files/logs/nsd @@ -0,0 +1,4 @@ +# failJSON: { "time": "2013-12-17T14:58:14", "match": true , "host": "192.0.2.105" } +[1387288694] nsd[7745]: info: ratelimit block example.com. type any target 192.0.2.0/24 query 192.0.2.105 TYPE255 +# failJSON: { "time": "2013-12-18T07:42:15", "match": true , "host": "192.0.2.115" } +[1387348935] nsd[23600]: info: axfr for zone domain.nl. from client 192.0.2.115 refused, no acl matches.