From 051f090313dc774197d0dcb3f388dc3dc3bdaa35 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 12:44:55 +0100 Subject: [PATCH 1/8] Update debian packaging to dh compat 9 --- debian/compat | 2 +- debian/control | 2 +- debian/pycompat | 1 - debian/rules | 77 ++++++++++--------------------------------------- 4 files changed, 17 insertions(+), 65 deletions(-) delete mode 100644 debian/pycompat diff --git a/debian/compat b/debian/compat index 7ed6ff82..ec635144 100644 --- a/debian/compat +++ b/debian/compat @@ -1 +1 @@ -5 +9 diff --git a/debian/control b/debian/control index 6e9a5682..a3320353 100644 --- a/debian/control +++ b/debian/control @@ -2,7 +2,7 @@ Source: fail2ban Section: net Priority: optional Maintainer: Yaroslav Halchenko -Build-Depends: debhelper (>= 5.0.37.2), python (>= 2.5.4-1~), python-pyinotify +Build-Depends: debhelper (>= 9), python (>= 2.6.6-3~), python-pyinotify Homepage: http://www.fail2ban.org Vcs-Git: git://github.com/fail2ban/fail2ban.git Vcs-Browser: http://github.com/fail2ban/fail2ban diff --git a/debian/pycompat b/debian/pycompat deleted file mode 100644 index 0cfbf088..00000000 --- a/debian/pycompat +++ /dev/null @@ -1 +0,0 @@ -2 diff --git a/debian/rules b/debian/rules index 0249cd55..ffb317e5 100755 --- a/debian/rules +++ b/debian/rules @@ -9,87 +9,40 @@ # Uncomment this to turn on verbose mode. #export DH_VERBOSE=1 +%: + dh $@ --with python2 + DESTDIR=$(CURDIR)/debian/fail2ban -configure: configure-stamp -configure-stamp: - dh_testdir - touch configure-stamp - -build: - -build-arch: - -build-indep: - -clean: clean-inits - dh_testdir - dh_testroot - rm -f build-stamp configure-stamp - rm -rf build - # Does not hurt to ask distutils to do their duty - python setup.py clean - # Enforce removal of *.pyc files. Apparently dh_clean does - # not perform find on provided filename patterns. - find . -name \*.pyc -exec rm -f {} \; +override_dh_clean: + rm -rf fail2ban.egg-info dh_clean -install: build - dh_testdir - dh_testroot - dh_clean -k - dh_installdirs - - # Install the package into debian/fail2ban. - python setup.py install --root=$(DESTDIR) --no-compile --install-layout=deb +override_dh_install: + rm -f $(DESTDIR)/usr/share/doc/fail2ban/README.Solaris # Install Debian shipped jail file in 1 piece (instead of patching # the shipped one since there are too many changes) install -m 644 debian/jail.conf $(DESTDIR)/etc/fail2ban # Remove explicitely created /var/run/fail2ban # just to please lintian since init file will # take care about it anyways - rm -rf $(DESTDIR)/var/run/fail2ban + rm -rf $(DESTDIR)/var/run/ # Install bash completion install -d $(DESTDIR)/etc/bash_completion.d install -m 644 files/bash-completion $(DESTDIR)/etc/bash_completion.d/fail2ban + + dh_install - # Run tests +override_dh_auto_test: ifeq (,$(filter nocheck,$(DEB_BUILD_OPTIONS))) ./fail2ban-testcases-all || : -else - : # Skip unittests due to nocheck endif -# -# Just to comply with policy 4.8 -binary-arch: - -# Build architecture-independent files here. -binary-indep: install - dh_testdir - dh_testroot - dh_installchangelogs ChangeLog - dh_installdocs +override_dh_installexamples: dh_installexamples config/jail.conf files/ipmasq-* - dh_installlogrotate - dh_python2 /usr/share/fail2ban + +override_dh_installinit: dh_installinit -- defaults 99 - # perform swap of order of calls to init and pycentral (or even - # bleedingly new dh_python2) in prerm to close #422655 -- - # python-cleanup section is cut and placed at the end of the file - # since .init script would trigger their compilation again - sed -i -e '/^#.*ed by dh_python2/,/# End auto/{H;d};$$G' \ - debian/fail2ban.prerm.debhelper - +override_dh_installman: dh_installman man/*.[15] - dh_link - dh_compress - dh_fixperms - dh_installdeb - dh_gencontrol - dh_md5sums - dh_builddeb - -binary: binary-indep -.PHONY: build clean binary-indep binary-arch binary install configure copy-inits clean-inits From ba5a3fdf4a106c9026a07df7f8d90c372b068108 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 12:54:57 +0100 Subject: [PATCH 2/8] remove changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff, applied upstream --- ...6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff | 38 ------------------- debian/patches/series | 1 - 2 files changed, 39 deletions(-) delete mode 100644 debian/patches/changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff diff --git a/debian/patches/changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff b/debian/patches/changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff deleted file mode 100644 index 3b63f12c..00000000 --- a/debian/patches/changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff +++ /dev/null @@ -1,38 +0,0 @@ -From: Yaroslav Halchenko -Subject: ENH: adding custom date format for proftpd when logging in its own log file (default on Debian) -- includes milliseconds - Should resolve Debian #648276 - ---- a/server/datedetector.py -+++ b/server/datedetector.py -@@ -101,6 +101,13 @@ class DateDetector: - template.setRegex("\d{2}/\d{2}/\d{4}:\d{2}:\d{2}:\d{2}") - template.setPattern("%m/%d/%Y:%H:%M:%S") - self._appendTemplate(template) -+ # proftpd 2013-11-16 21:43:03,296 -+ # So like Exim below but with ,subsecond -+ template = DateStrptime() -+ template.setName("Year-Month-Day Hour:Minute:Second[,subsecond]") -+ template.setRegex("\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d+") -+ template.setPattern("%Y-%m-%d %H:%M:%S,%f") -+ self._appendTemplate(template) - # Exim 2006-12-21 06:43:20 - template = DateStrptime() - template.setName("Year-Month-Day Hour:Minute:Second") ---- a/testcases/datedetectortestcase.py -+++ b/testcases/datedetectortestcase.py -@@ -74,6 +74,7 @@ class DateDetectorTest(unittest.TestCase - (False, "23/Jan/2005:21:59:59"), - (False, "01/23/2005:21:59:59"), - (False, "2005-01-23 21:59:59"), -+ (False, "2005-01-23 21:59:59,099"), # proftpd - (False, "23-Jan-2005 21:59:59"), - (False, "23-01-2005 21:59:59"), - (False, "01-23-2005 21:59:59.252"), # reported on f2b, causes Feb29 fix to break ---- a/testcases/files/logs/proftpd -+++ b/testcases/files/logs/proftpd -@@ -14,3 +14,5 @@ Jun 14 00:09:59 platypus.ace-hosting.com - May 31 10:53:25 mail proftpd[15302]: xxxxxxxxxx (::ffff:1.2.3.4[::ffff:1.2.3.4]) - Maximum login attempts (3) exceeded - # failJSON: { "time": "2004-12-05T15:44:32", "match": true , "host": "1.2.3.4" } - Dec 5 15:44:32 serv1 proftpd[70944]: serv1.domain.com (example.com[1.2.3.4]) - USER jtittle@domain.org: no such user found from example.com [1.2.3.4] to 1.2.3.4:21 -+# failJSON: { "time": "2013-11-16T21:59:30", "match": true , "host": "1.2.3.4", "desc": "proftpd-basic 1.3.5~rc3-2.1 on Debian uses date format with milliseconds if logging under /var/log/proftpd/proftpd.log" } -+2013-11-16 21:59:30,121 novo proftpd[25891] localhost (andy[1.2.3.4]): USER kjsad: no such user found from andy [1.2.3.5] to ::ffff:192.168.1.14:21 diff --git a/debian/patches/series b/debian/patches/series index 74695279..b7728eee 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -1,2 +1 @@ -changeset_d4f6ca4f8531f332bcb7ce3a89102f60afaaa08e.diff deb_manpages_reportbug From 05dc81d88082e0c0748b569f0fae5a0434a52075 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 12:55:38 +0100 Subject: [PATCH 3/8] refresh patch deb_manpages_reportbug --- debian/patches/deb_manpages_reportbug | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/debian/patches/deb_manpages_reportbug b/debian/patches/deb_manpages_reportbug index 0d35ac9b..5a41a2e5 100644 --- a/debian/patches/deb_manpages_reportbug +++ b/debian/patches/deb_manpages_reportbug @@ -4,7 +4,7 @@ Subject: tune ups in upstream manpages to direct users to use reportbug --- a/man/fail2ban-client.1 +++ b/man/fail2ban-client.1 -@@ -265,7 +265,7 @@ action for +@@ -369,7 +369,7 @@ Written by Cyril Jaquier . Many contributions by Yaroslav O. Halchenko . .SH "REPORTING BUGS" @@ -15,7 +15,7 @@ Subject: tune ups in upstream manpages to direct users to use reportbug .br --- a/man/fail2ban-server.1 +++ b/man/fail2ban-server.1 -@@ -38,7 +38,7 @@ print the version +@@ -38,7 +38,7 @@ Written by Cyril Jaquier . Many contributions by Yaroslav O. Halchenko . .SH "REPORTING BUGS" From e2b9cb01f5539ffbf1d3797fdd95a0898509f7c6 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 13:38:58 +0100 Subject: [PATCH 4/8] move renamed conffiles in maintscripts --- debian/postinst | 6 ++++++ debian/postrm | 6 ++++++ debian/preinst | 13 +++++++++++++ 3 files changed, 25 insertions(+) create mode 100755 debian/preinst diff --git a/debian/postinst b/debian/postinst index 885d39aa..7ada14c8 100755 --- a/debian/postinst +++ b/debian/postinst @@ -80,6 +80,12 @@ EOF ;; esac +if dpkg-maintscript-helper supports mv_conffile 2>/dev/null; then + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/couriersmtp.conf /etc/fail2ban/filter.d/courier-smtp.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/courierlogin.conf /etc/fail2ban/filter.d/courier-auth.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/action.d/firewall-cmd-direct-new.conf /etc/fail2ban/action.d/firewallcmd-new.conf 0.8.11-1 -- "$@" +fi + # dh_installdeb will replace this with shell code automatically # generated by other debhelper scripts. diff --git a/debian/postrm b/debian/postrm index 1e6c5ccd..4663d3c3 100755 --- a/debian/postrm +++ b/debian/postrm @@ -34,6 +34,12 @@ case "$1" in ;; esac +if dpkg-maintscript-helper supports mv_conffile 2>/dev/null; then + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/couriersmtp.conf /etc/fail2ban/filter.d/courier-smtp.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/courierlogin.conf /etc/fail2ban/filter.d/courier-auth.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/action.d/firewall-cmd-direct-new.conf /etc/fail2ban/action.d/firewallcmd-new.conf 0.8.11-1 -- "$@" +fi + # dh_installdeb will replace this with shell code automatically # generated by other debhelper scripts. diff --git a/debian/preinst b/debian/preinst new file mode 100755 index 00000000..fb86a5d4 --- /dev/null +++ b/debian/preinst @@ -0,0 +1,13 @@ +#!/bin/sh + +set -e + +if dpkg-maintscript-helper supports mv_conffile 2>/dev/null; then + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/couriersmtp.conf /etc/fail2ban/filter.d/courier-smtp.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/filter.d/courierlogin.conf /etc/fail2ban/filter.d/courier-auth.conf 0.8.11-1 -- "$@" + dpkg-maintscript-helper mv_conffile /etc/fail2ban/action.d/firewall-cmd-direct-new.conf /etc/fail2ban/action.d/firewallcmd-new.conf 0.8.11-1 -- "$@" +fi + +#DEBHELPER# + +exit 0 From af088eefcef8ba70713a15ec9fc75c2637634f92 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 14:12:21 +0100 Subject: [PATCH 5/8] remove /var/lib/fail2ban/fail2ban.sqlite3 when purging --- debian/postrm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/debian/postrm b/debian/postrm index 4663d3c3..ff656c35 100755 --- a/debian/postrm +++ b/debian/postrm @@ -26,6 +26,8 @@ case "$1" in # Remove logs rm -f /var/log/fail2ban* + # Remove sqlite db + rm -f /var/lib/fail2ban/fail2ban.sqlite3 ;; remove|upgrade|failed-upgrade|abort-install|abort-upgrade) # nothing From 82c1ed39794ecafc32b71dc83cf11abbbbb26037 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sun, 16 Mar 2014 06:06:43 +0100 Subject: [PATCH 6/8] enable systemd integration --- debian/control | 4 ++-- .../patches/remove-syslog.target-reference.patch | 14 ++++++++++++++ debian/patches/series | 1 + debian/rules | 7 ++++++- 4 files changed, 23 insertions(+), 3 deletions(-) create mode 100644 debian/patches/remove-syslog.target-reference.patch diff --git a/debian/control b/debian/control index a3320353..0e621e60 100644 --- a/debian/control +++ b/debian/control @@ -2,7 +2,7 @@ Source: fail2ban Section: net Priority: optional Maintainer: Yaroslav Halchenko -Build-Depends: debhelper (>= 9), python (>= 2.6.6-3~), python-pyinotify +Build-Depends: debhelper (>= 9), python (>= 2.6.6-3~), python-pyinotify, dh-systemd Homepage: http://www.fail2ban.org Vcs-Git: git://github.com/fail2ban/fail2ban.git Vcs-Browser: http://github.com/fail2ban/fail2ban @@ -13,7 +13,7 @@ Package: fail2ban Architecture: all Depends: ${python:Depends}, ${misc:Depends}, lsb-base (>=2.0-7) Recommends: iptables, whois, python-pyinotify -Suggests: python-gamin, mailx, system-log-daemon +Suggests: python-gamin, mailx, system-log-daemon, python-systemd Description: ban hosts that cause multiple authentication errors Fail2ban monitors log files (e.g. /var/log/auth.log, /var/log/apache/access.log) and temporarily or persistently bans diff --git a/debian/patches/remove-syslog.target-reference.patch b/debian/patches/remove-syslog.target-reference.patch new file mode 100644 index 00000000..57e73cde --- /dev/null +++ b/debian/patches/remove-syslog.target-reference.patch @@ -0,0 +1,14 @@ +Description: Don't mention obsolete syslog.target in systemd service file +Author: Daniel Schaal +Last-Update: 2014-03-15 + +--- fail2ban-0.9.0.orig/files/fail2ban.service ++++ fail2ban-0.9.0/files/fail2ban.service +@@ -1,6 +1,6 @@ + [Unit] + Description=Fail2ban Service +-After=syslog.target network.target ++After=network.target + + [Service] + Type=forking diff --git a/debian/patches/series b/debian/patches/series index b7728eee..1be59357 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -1 +1,2 @@ deb_manpages_reportbug +remove-syslog.target-reference.patch diff --git a/debian/rules b/debian/rules index ffb317e5..41f04242 100755 --- a/debian/rules +++ b/debian/rules @@ -10,7 +10,7 @@ #export DH_VERBOSE=1 %: - dh $@ --with python2 + dh $@ --with python2,systemd DESTDIR=$(CURDIR)/debian/fail2ban @@ -30,6 +30,11 @@ override_dh_install: # Install bash completion install -d $(DESTDIR)/etc/bash_completion.d install -m 644 files/bash-completion $(DESTDIR)/etc/bash_completion.d/fail2ban + # Install systemd files + install -d $(DESTDIR)/lib/systemd/system + install -d $(DESTDIR)/usr/lib/tmpfiles.d + install -m 644 files/fail2ban.service $(DESTDIR)/lib/systemd/system + install -m 644 files/fail2ban-tmpfiles.conf $(DESTDIR)/usr/lib/tmpfiles.d dh_install From cc4ea850fe190542e9d56a57fd8f2238d26f31f3 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sat, 15 Mar 2014 14:13:06 +0100 Subject: [PATCH 7/8] use upstream jail.conf, paths are now defined in paths-debian.conf --- debian/jail.conf | 483 ----------------------------------------------- debian/rules | 3 - 2 files changed, 486 deletions(-) delete mode 100644 debian/jail.conf diff --git a/debian/jail.conf b/debian/jail.conf deleted file mode 100644 index bffb5cef..00000000 --- a/debian/jail.conf +++ /dev/null @@ -1,483 +0,0 @@ -# Fail2Ban configuration file. -# -# This file was composed for Debian systems from the original one -# provided now under /usr/share/doc/fail2ban/examples/jail.conf -# for additional examples. -# -# Comments: use '#' for comment lines and ';' for inline comments -# -# To avoid merges during upgrades DO NOT MODIFY THIS FILE -# and rather provide your changes in /etc/fail2ban/jail.local -# - -# The DEFAULT allows a global definition of the options. They can be overridden -# in each jail afterwards. - -[DEFAULT] - -# "ignoreip" can be an IP address, a CIDR mask or a DNS host. Fail2ban will not -# ban a host which matches an address in this list. Several addresses can be -# defined using space separator. -ignoreip = 127.0.0.1/8 - -# "bantime" is the number of seconds that a host is banned. -bantime = 600 - -# A host is banned if it has generated "maxretry" during the last "findtime" -# seconds. -findtime = 600 -maxretry = 3 - -# "backend" specifies the backend used to get files modification. -# Available options are "pyinotify", "gamin", "polling" and "auto". -# This option can be overridden in each jail as well. -# -# pyinotify: requires pyinotify (a file alteration monitor) to be installed. -# If pyinotify is not installed, Fail2ban will use auto. -# gamin: requires Gamin (a file alteration monitor) to be installed. -# If Gamin is not installed, Fail2ban will use auto. -# polling: uses a polling algorithm which does not require external libraries. -# auto: will try to use the following backends, in order: -# pyinotify, gamin, polling. -backend = auto - -# "usedns" specifies if jails should trust hostnames in logs, -# warn when reverse DNS lookups are performed, or ignore all hostnames in logs -# -# yes: if a hostname is encountered, a reverse DNS lookup will be performed. -# warn: if a hostname is encountered, a reverse DNS lookup will be performed, -# but it will be logged as a warning. -# no: if a hostname is encountered, will not be used for banning, -# but it will be logged as info. -usedns = warn - -# -# Destination email address used solely for the interpolations in -# jail.{conf,local} configuration files. -destemail = root@localhost - -# -# Name of the sender for mta actions -sendername = Fail2Ban - -# -# ACTIONS -# - -# Default banning action (e.g. iptables, iptables-new, -# iptables-multiport, shorewall, etc) It is used to define -# action_* variables. Can be overridden globally or per -# section within jail.local file -banaction = iptables-multiport - -# email action. Since 0.8.1 upstream fail2ban uses sendmail -# MTA for the mailing. Change mta configuration parameter to mail -# if you want to revert to conventional 'mail'. -mta = sendmail - -# Default protocol -protocol = tcp - -# Specify chain where jumps would need to be added in iptables-* actions -chain = INPUT - -# -# Action shortcuts. To be used to define action parameter - -# The simplest action to take: ban only -action_ = %(banaction)s[name=%(__name__)s, port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"] - -# ban & send an e-mail with whois report to the destemail. -action_mw = %(banaction)s[name=%(__name__)s, port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"] - %(mta)s-whois[name=%(__name__)s, dest="%(destemail)s", protocol="%(protocol)s", chain="%(chain)s", sendername="%(sendername)s"] - -# ban & send an e-mail with whois report and relevant log lines -# to the destemail. -action_mwl = %(banaction)s[name=%(__name__)s, port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"] - %(mta)s-whois-lines[name=%(__name__)s, dest="%(destemail)s", logpath=%(logpath)s, chain="%(chain)s", sendername="%(sendername)s"] - -# Choose default action. To change, just override value of 'action' with the -# interpolation to the chosen action shortcut (e.g. action_mw, action_mwl, etc) in jail.local -# globally (section [DEFAULT]) or per specific section -action = %(action_)s - -# -# JAILS -# - -# Next jails corresponds to the standard configuration in Fail2ban 0.6 which -# was shipped in Debian. Enable any defined here jail by including -# -# [SECTION_NAME] -# enabled = true - -# -# in /etc/fail2ban/jail.local. -# -# Optionally you may override any other parameter (e.g. banaction, -# action, port, logpath, etc) in that section within jail.local - -[ssh] - -enabled = true -port = ssh -filter = sshd -logpath = /var/log/auth.log -maxretry = 6 - -[dropbear] - -enabled = false -port = ssh -filter = dropbear -logpath = /var/log/auth.log -maxretry = 6 - -# Generic filter for pam. Has to be used with action which bans all ports -# such as iptables-allports, shorewall -[pam-generic] - -enabled = false -# pam-generic filter can be customized to monitor specific subset of 'tty's -filter = pam-generic -# port actually must be irrelevant but lets leave it all for some possible uses -port = all -banaction = iptables-allports -port = anyport -logpath = /var/log/auth.log -maxretry = 6 - -[xinetd-fail] - -enabled = false -filter = xinetd-fail -port = all -banaction = iptables-multiport-log -logpath = /var/log/daemon.log -maxretry = 2 - - -[ssh-ddos] - -enabled = false -port = ssh -filter = sshd-ddos -logpath = /var/log/auth.log -maxretry = 6 - - -# Here we use blackhole routes for not requiring any additional kernel support -# to store large volumes of banned IPs - -[ssh-route] - -enabled = false -filter = sshd -action = route -logpath = /var/log/sshd.log -maxretry = 6 - -# Here we use a combination of Netfilter/Iptables and IPsets -# for storing large volumes of banned IPs -# -# IPset comes in two versions. See ipset -V for which one to use -# requires the ipset package and kernel support. -[ssh-iptables-ipset4] - -enabled = false -port = ssh -filter = sshd -banaction = iptables-ipset-proto4 -logpath = /var/log/sshd.log -maxretry = 6 - -[ssh-iptables-ipset6] - -enabled = false -port = ssh -filter = sshd -banaction = iptables-ipset-proto6 -logpath = /var/log/sshd.log -maxretry = 6 - - -# -# HTTP servers -# - -[apache] - -enabled = false -port = http,https -filter = apache-auth -logpath = /var/log/apache*/*error.log -maxretry = 6 - -# default action is now multiport, so apache-multiport jail was left -# for compatibility with previous (<0.7.6-2) releases -[apache-multiport] - -enabled = false -port = http,https -filter = apache-auth -logpath = /var/log/apache*/*error.log -maxretry = 6 - -[apache-noscript] - -enabled = false -port = http,https -filter = apache-noscript -logpath = /var/log/apache*/*error.log -maxretry = 6 - -[apache-overflows] - -enabled = false -port = http,https -filter = apache-overflows -logpath = /var/log/apache*/*error.log -maxretry = 2 - -# Ban attackers that try to use PHP's URL-fopen() functionality -# through GET/POST variables. - Experimental, with more than a year -# of usage in production environments. - -[php-url-fopen] - -enabled = false -port = http,https -filter = php-url-fopen -logpath = /var/www/*/logs/access_log - -# A simple PHP-fastcgi jail which works with lighttpd. -# If you run a lighttpd server, then you probably will -# find these kinds of messages in your error_log: -# ALERT – tried to register forbidden variable ‘GLOBALS’ -# through GET variables (attacker '1.2.3.4', file '/var/www/default/htdocs/index.php') - -[lighttpd-fastcgi] - -enabled = false -port = http,https -filter = lighttpd-fastcgi -logpath = /var/log/lighttpd/error.log - -# Same as above for mod_auth -# It catches wrong authentifications - -[lighttpd-auth] - -enabled = false -port = http,https -filter = suhosin -logpath = /var/log/lighttpd/error.log - -[nginx-http-auth] - -enabled = false -filter = nginx-http-auth -port = http,https -logpath = /var/log/nginx/error.log - -# Monitor roundcube server - -[roundcube-auth] - -enabled = false -filter = roundcube-auth -port = http,https -logpath = /var/log/roundcube/userlogins - - -[sogo-auth] - -enabled = false -filter = sogo-auth -port = http, https -# without proxy this would be: -# port = 20000 -logpath = /var/log/sogo/sogo.log - - -# -# FTP servers -# - -[vsftpd] - -enabled = false -port = ftp,ftp-data,ftps,ftps-data -filter = vsftpd -logpath = /var/log/vsftpd.log -# or overwrite it in jails.local to be -# logpath = /var/log/auth.log -# if you want to rely on PAM failed login attempts -# vsftpd's failregex should match both of those formats -maxretry = 6 - - -[proftpd] - -enabled = false -port = ftp,ftp-data,ftps,ftps-data -filter = proftpd -logpath = /var/log/proftpd/proftpd.log -maxretry = 6 - - -[pure-ftpd] - -enabled = false -port = ftp,ftp-data,ftps,ftps-data -filter = pure-ftpd -logpath = /var/log/syslog -maxretry = 6 - - -[wuftpd] - -enabled = false -port = ftp,ftp-data,ftps,ftps-data -filter = wuftpd -logpath = /var/log/syslog -maxretry = 6 - - -# -# Mail servers -# - -[postfix] - -enabled = false -port = smtp,ssmtp,submission -filter = postfix -logpath = /var/log/mail.log - - -[couriersmtp] - -enabled = false -port = smtp,ssmtp,submission -filter = couriersmtp -logpath = /var/log/mail.log - - -# -# Mail servers authenticators: might be used for smtp,ftp,imap servers, so -# all relevant ports get banned -# - -[courierauth] - -enabled = false -port = smtp,ssmtp,submission,imap2,imap3,imaps,pop3,pop3s -filter = courierlogin -logpath = /var/log/mail.log - - -[sasl] - -enabled = false -port = smtp,ssmtp,submission,imap2,imap3,imaps,pop3,pop3s -filter = postfix-sasl -# You might consider monitoring /var/log/mail.warn instead if you are -# running postfix since it would provide the same log lines at the -# "warn" level but overall at the smaller filesize. -logpath = /var/log/mail.log - -[dovecot] - -enabled = false -port = smtp,ssmtp,submission,imap2,imap3,imaps,pop3,pop3s -filter = dovecot -logpath = /var/log/mail.log - -# To log wrong MySQL access attempts add to /etc/my.cnf: -# log-error=/var/log/mysqld.log -# log-warning = 2 -[mysqld-auth] - -enabled = false -filter = mysqld-auth -port = 3306 -logpath = /var/log/mysqld.log - - -# DNS Servers - - -# These jails block attacks against named (bind9). By default, logging is off -# with bind9 installation. You will need something like this: -# -# logging { -# channel security_file { -# file "/var/log/named/security.log" versions 3 size 30m; -# severity dynamic; -# print-time yes; -# }; -# category security { -# security_file; -# }; -# }; -# -# in your named.conf to provide proper logging - -# !!! WARNING !!! -# Since UDP is connection-less protocol, spoofing of IP and imitation -# of illegal actions is way too simple. Thus enabling of this filter -# might provide an easy way for implementing a DoS against a chosen -# victim. See -# http://nion.modprobe.de/blog/archives/690-fail2ban-+-dns-fail.html -# Please DO NOT USE this jail unless you know what you are doing. -#[named-refused-udp] -# -#enabled = false -#port = domain,953 -#protocol = udp -#filter = named-refused -#logpath = /var/log/named/security.log - -[named-refused-tcp] - -enabled = false -port = domain,953 -protocol = tcp -filter = named-refused -logpath = /var/log/named/security.log - -# Multiple jails, 1 per protocol, are necessary ATM: -# see https://github.com/fail2ban/fail2ban/issues/37 -[asterisk-tcp] - -enabled = false -filter = asterisk -port = 5060,5061 -protocol = tcp -logpath = /var/log/asterisk/messages - -[asterisk-udp] - -enabled = false -filter = asterisk -port = 5060,5061 -protocol = udp -logpath = /var/log/asterisk/messages - - -# Jail for more extended banning of persistent abusers -# !!! WARNING !!! -# Make sure that your loglevel specified in fail2ban.conf/.local -# is not at DEBUG level -- which might then cause fail2ban to fall into -# an infinite loop constantly feeding itself with non-informative lines -[recidive] - -enabled = false -filter = recidive -logpath = /var/log/fail2ban.log -action = iptables-allports[name=recidive] - sendmail-whois-lines[name=recidive, logpath=/var/log/fail2ban.log] -bantime = 604800 ; 1 week -findtime = 86400 ; 1 day -maxretry = 5 diff --git a/debian/rules b/debian/rules index 41f04242..5dc6f587 100755 --- a/debian/rules +++ b/debian/rules @@ -20,9 +20,6 @@ override_dh_clean: override_dh_install: rm -f $(DESTDIR)/usr/share/doc/fail2ban/README.Solaris - # Install Debian shipped jail file in 1 piece (instead of patching - # the shipped one since there are too many changes) - install -m 644 debian/jail.conf $(DESTDIR)/etc/fail2ban # Remove explicitely created /var/run/fail2ban # just to please lintian since init file will # take care about it anyways From c8694d8adf9903a769366fc89a3cd29cc11dbe97 Mon Sep 17 00:00:00 2001 From: Daniel Schaal Date: Sun, 16 Mar 2014 16:52:42 +0100 Subject: [PATCH 8/8] Add news entry for 0.9.0 --- debian/NEWS | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/debian/NEWS b/debian/NEWS index 94eb9b27..b47b9d03 100644 --- a/debian/NEWS +++ b/debian/NEWS @@ -1,3 +1,10 @@ +fail2ban (0.9.0-1) experimental; urgency=low + + From this version on log paths are defined in distro specific files. + for Debian this is in /etc/fail2ban/paths-debian.conf + + -- Daniel Schaal Sun, 16 Mar 2014 16:51:06 +0100 + fail2ban (0.8.11-1) unstable; urgency=low * retroactive for 0.8.9: by default iptables-* actions do not simply