From 6d72602f6b25aee10a3e0744635d3090a6415518 Mon Sep 17 00:00:00 2001 From: "M. Maraun" Date: Fri, 3 Jul 2015 22:42:22 +0200 Subject: [PATCH 1/7] Set Timeout at urlopen to 3 seconds --- THANKS | 1 + config/action.d/badips.py | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/THANKS b/THANKS index 5ae86a3c..133bd987 100644 --- a/THANKS +++ b/THANKS @@ -71,6 +71,7 @@ kojiro Lars Kneschke Lee Clemens leftyfb (Mike Rushton) +M. Maraun Manuel Arostegui Ramirez Marcel Dopita Mark Edgington diff --git a/config/action.d/badips.py b/config/action.d/badips.py index c2a239f5..58e64990 100644 --- a/config/action.d/badips.py +++ b/config/action.d/badips.py @@ -116,7 +116,7 @@ class BadIPsAction(ActionBase): """ try: response = urlopen( - self._Request("/".join([self._badips, "get", "categories"]))) + self._Request("/".join([self._badips, "get", "categories"])), None, 3) except HTTPError as response: messages = json.loads(response.read().decode('utf-8')) self._logSys.error( From 4744e165394c696144499d95d79ab5b55b556cbd Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Thu, 24 Sep 2015 06:37:01 -0700 Subject: [PATCH 2/7] README :: Some style/grammar tweaks, and init/service script mention. Re: #1193 --- README.md | 29 ++++++++++++++++++++--------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index d9539a32..a64bb943 100644 --- a/README.md +++ b/README.md @@ -6,13 +6,16 @@ ## Fail2Ban: ban hosts that cause multiple authentication errors -Fail2Ban scans log files like /var/log/pwdfail and bans IP that makes too many -password failures. It updates firewall rules to reject the IP address. These -rules can be defined by the user. Fail2Ban can read multiple log files such as -sshd or Apache web server ones. +Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses +having too many failed login attempts. +It does this by updating system firewall rules to reject new connections +from those IP addresses, for a configurable amount of time. +Fail2Ban comes out-of-the-box ready to read many standard log files, such as those +for sshd and Apache, and is easy to configure to read any log file you choose, for +any error you choose. -Fail2Ban is able to reduce the rate of incorrect authentications attempts -however it cannot eliminate the risk that weak authentication presents. +Though Fail2Ban is able to reduce the rate of incorrect authentications attempts, +it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services. @@ -42,7 +45,7 @@ To install, just do: python setup.py install This will install Fail2Ban into the python library directory. The executable -scripts are placed into /usr/bin, and configuration under /etc/fail2ban. +scripts are placed into `/usr/bin`, and configuration under `/etc/fail2ban`. Fail2Ban should be correctly installed now. Just type: @@ -51,11 +54,19 @@ Fail2Ban should be correctly installed now. Just type: to see if everything is alright. You should always use fail2ban-client and never call fail2ban-server directly. +Please note that the system init/service script is not automatically installed. +To enable fail2ban as an automatic service, simply copy the script for your +distro from the `files` directory to `/etc/init.d`. Example: + + cp files/debian-initd /etc/init.d/fail2ban + update-rc.d fail2ban defaults + service fail2ban start + Configuration: -------------- -You can configure Fail2Ban using the files in /etc/fail2ban. It is possible to -configure the server using commands sent to it by fail2ban-client. The +You can configure Fail2Ban using the files in `/etc/fail2ban`. It is possible to +configure the server using commands sent to it by `fail2ban-client`. The available commands are described in the fail2ban-client(1) manpage. Also see fail2ban(1) and jail.conf(5) manpages for further references. From d618ee3d90faeaacea1096ac43af36450527d604 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Thu, 24 Sep 2015 09:53:55 -0400 Subject: [PATCH 3/7] BF: disable testing on python 3.2 until coverage gets a fix --- .travis.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.travis.yml b/.travis.yml index f65e4896..adb41e7d 100644 --- a/.travis.yml +++ b/.travis.yml @@ -6,7 +6,8 @@ python: - 2.6 - 2.7 - pypy - - 3.2 + # disabled until coverage module fixes up compatibility issue + # - 3.2 - 3.3 - 3.4 - pypy3 From c1b80a5e1bb9d426e87d4eec3285cf20c405438b Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Fri, 25 Sep 2015 02:23:08 -0700 Subject: [PATCH 4/7] README :: fitted paragraph style --- README.md | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index a64bb943..0be4920a 100644 --- a/README.md +++ b/README.md @@ -6,16 +6,15 @@ ## Fail2Ban: ban hosts that cause multiple authentication errors -Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses -having too many failed login attempts. -It does this by updating system firewall rules to reject new connections -from those IP addresses, for a configurable amount of time. -Fail2Ban comes out-of-the-box ready to read many standard log files, such as those -for sshd and Apache, and is easy to configure to read any log file you choose, for -any error you choose. +Fail2Ban scans log files like `/var/log/auth.log` and bans IP addresses having +too many failed login attempts. It does this by updating system firewall rules +to reject new connections from those IP addresses, for a configurable amount +of time. Fail2Ban comes out-of-the-box ready to read many standard log files, +such as those for sshd and Apache, and is easy to configure to read any log +file you choose, for any error you choose. -Though Fail2Ban is able to reduce the rate of incorrect authentications attempts, -it cannot eliminate the risk that weak authentication presents. +Though Fail2Ban is able to reduce the rate of incorrect authentications +attempts, it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services. From 0610791ffecaaade6ed844ad59f99b284e203807 Mon Sep 17 00:00:00 2001 From: Ryan Yoosefi Date: Fri, 25 Sep 2015 02:25:11 -0700 Subject: [PATCH 5/7] README :: init/service example mentions debian based systems as the example --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 0be4920a..cbc075e2 100644 --- a/README.md +++ b/README.md @@ -55,7 +55,8 @@ never call fail2ban-server directly. Please note that the system init/service script is not automatically installed. To enable fail2ban as an automatic service, simply copy the script for your -distro from the `files` directory to `/etc/init.d`. Example: +distro from the `files` directory to `/etc/init.d`. Example (on a Debian-based +system): cp files/debian-initd /etc/init.d/fail2ban update-rc.d fail2ban defaults From 2895d981fa8b91cc6ea2bb74f325453c48dfb31d Mon Sep 17 00:00:00 2001 From: "M. Maraun" Date: Fri, 3 Jul 2015 22:42:22 +0200 Subject: [PATCH 6/7] Set Timeout at urlopen to 3 seconds --- THANKS | 1 + config/action.d/badips.py | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/THANKS b/THANKS index 7bf723c5..68c7af48 100644 --- a/THANKS +++ b/THANKS @@ -71,6 +71,7 @@ kojiro Lars Kneschke Lee Clemens leftyfb (Mike Rushton) +M. Maraun Manuel Arostegui Ramirez Marcel Dopita Mark Edgington diff --git a/config/action.d/badips.py b/config/action.d/badips.py index a1df00a3..99e1866a 100644 --- a/config/action.d/badips.py +++ b/config/action.d/badips.py @@ -117,7 +117,7 @@ class BadIPsAction(ActionBase): """ try: response = urlopen( - self._Request("/".join([self._badips, "get", "categories"]))) + self._Request("/".join([self._badips, "get", "categories"])), None, 3) except HTTPError as response: messages = json.loads(response.read().decode('utf-8')) self._logSys.error( From 6c0f898ec7c5165ca50ee683e8cf371ed9b5a5a4 Mon Sep 17 00:00:00 2001 From: Yaroslav Halchenko Date: Sun, 27 Sep 2015 00:49:57 -0400 Subject: [PATCH 7/7] DOC: changelog for the timeout change --- ChangeLog | 2 ++ 1 file changed, 2 insertions(+) diff --git a/ChangeLog b/ChangeLog index fea070ba..c5fd30aa 100644 --- a/ChangeLog +++ b/ChangeLog @@ -25,6 +25,8 @@ ver. 0.9.4 (2015/XX/XXX) - wanna-be-released * Added new date pattern with year after day (e.g. Sun Jan 23 2005 21:59:59) http://bugs.debian.org/798923 * Added openSUSE path configuration (Thanks Johannes Weberhofer) + * Added a timeout (3 sec) to urlopen within badips.py action + (Thanks M. Maraun) ver. 0.9.3 (2015/08/01) - lets-all-stay-friends ----------