From 4744e165394c696144499d95d79ab5b55b556cbd Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Thu, 24 Sep 2015 06:37:01 -0700 Subject: [PATCH 1/3] README :: Some style/grammar tweaks, and init/service script mention. Re: #1193 --- README.md | 29 ++++++++++++++++++++--------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index d9539a32..a64bb943 100644 --- a/README.md +++ b/README.md @@ -6,13 +6,16 @@ ## Fail2Ban: ban hosts that cause multiple authentication errors -Fail2Ban scans log files like /var/log/pwdfail and bans IP that makes too many -password failures. It updates firewall rules to reject the IP address. These -rules can be defined by the user. Fail2Ban can read multiple log files such as -sshd or Apache web server ones. +Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses +having too many failed login attempts. +It does this by updating system firewall rules to reject new connections +from those IP addresses, for a configurable amount of time. +Fail2Ban comes out-of-the-box ready to read many standard log files, such as those +for sshd and Apache, and is easy to configure to read any log file you choose, for +any error you choose. -Fail2Ban is able to reduce the rate of incorrect authentications attempts -however it cannot eliminate the risk that weak authentication presents. +Though Fail2Ban is able to reduce the rate of incorrect authentications attempts, +it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services. @@ -42,7 +45,7 @@ To install, just do: python setup.py install This will install Fail2Ban into the python library directory. The executable -scripts are placed into /usr/bin, and configuration under /etc/fail2ban. +scripts are placed into `/usr/bin`, and configuration under `/etc/fail2ban`. Fail2Ban should be correctly installed now. Just type: @@ -51,11 +54,19 @@ Fail2Ban should be correctly installed now. Just type: to see if everything is alright. You should always use fail2ban-client and never call fail2ban-server directly. +Please note that the system init/service script is not automatically installed. +To enable fail2ban as an automatic service, simply copy the script for your +distro from the `files` directory to `/etc/init.d`. Example: + + cp files/debian-initd /etc/init.d/fail2ban + update-rc.d fail2ban defaults + service fail2ban start + Configuration: -------------- -You can configure Fail2Ban using the files in /etc/fail2ban. It is possible to -configure the server using commands sent to it by fail2ban-client. The +You can configure Fail2Ban using the files in `/etc/fail2ban`. It is possible to +configure the server using commands sent to it by `fail2ban-client`. The available commands are described in the fail2ban-client(1) manpage. Also see fail2ban(1) and jail.conf(5) manpages for further references. From c1b80a5e1bb9d426e87d4eec3285cf20c405438b Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Fri, 25 Sep 2015 02:23:08 -0700 Subject: [PATCH 2/3] README :: fitted paragraph style --- README.md | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index a64bb943..0be4920a 100644 --- a/README.md +++ b/README.md @@ -6,16 +6,15 @@ ## Fail2Ban: ban hosts that cause multiple authentication errors -Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses -having too many failed login attempts. -It does this by updating system firewall rules to reject new connections -from those IP addresses, for a configurable amount of time. -Fail2Ban comes out-of-the-box ready to read many standard log files, such as those -for sshd and Apache, and is easy to configure to read any log file you choose, for -any error you choose. +Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses having +too many failed login attempts. It does this by updating system firewall rules +to reject new connections from those IP addresses, for a configurable amount +of time. Fail2Ban comes out-of-the-box ready to read many standard log files, +such as those for sshd and Apache, and is easy to configure to read any log +file you choose, for any error you choose. -Though Fail2Ban is able to reduce the rate of incorrect authentications attempts, -it cannot eliminate the risk that weak authentication presents. +Though Fail2Ban is able to reduce the rate of incorrect authentications +attempts, it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services. From 0610791ffecaaade6ed844ad59f99b284e203807 Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Fri, 25 Sep 2015 02:25:11 -0700 Subject: [PATCH 3/3] README :: init/service example mentions debian based systems as the example --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 0be4920a..cbc075e2 100644 --- a/README.md +++ b/README.md @@ -55,7 +55,8 @@ never call fail2ban-server directly. Please note that the system init/service script is not automatically installed. To enable fail2ban as an automatic service, simply copy the script for your -distro from the `files` directory to `/etc/init.d`. Example: +distro from the `files` directory to `/etc/init.d`. Example (on a Debian-based +system): cp files/debian-initd /etc/init.d/fail2ban update-rc.d fail2ban defaults