/
usr
/
lib
/
python3
/
dist-packages
/
fail2ban
/
tests
/
files
/
logs
/
/usr/lib/python3/dist-packages/fail2ban/tests/files/logs
mkdir
upload
Name
Size
Mode
Actions
bsd/
-
0755
rm
3proxy
575
0644
edit
dl
rm
apache-auth
12805
0644
edit
dl
rm
apache-badbots
688
0644
edit
dl
rm
apache-botsearch
3750
0644
edit
dl
rm
apache-fakegooglebot
480
0644
edit
dl
rm
apache-modsecurity
2655
0644
edit
dl
rm
apache-nohome
406
0644
edit
dl
rm
apache-noscript
2702
0644
edit
dl
rm
apache-overflows
2476
0644
edit
dl
rm
apache-pass
273
0644
edit
dl
rm
apache-shellshock
499
0644
edit
dl
rm
assp
5209
0644
edit
dl
rm
asterisk
13683
0644
edit
dl
rm
bitwarden
741
0644
edit
dl
rm
centreon
252
0644
edit
dl
rm
counter-strike
399
0644
edit
dl
rm
courier-auth
1070
0644
edit
dl
rm
courier-smtp
1735
0644
edit
dl
rm
cyrus-imap
2455
0644
edit
dl
rm
directadmin
835
0644
edit
dl
rm
domino-smtp
1295
0644
edit
dl
rm
dovecot
11017
0644
edit
dl
rm
dropbear
1329
0644
edit
dl
rm
drupal-auth
788
0644
edit
dl
rm
ejabberd-auth
1490
0644
edit
dl
rm
exim
10145
0644
edit
dl
rm
exim-spam
3462
0644
edit
dl
rm
freeswitch
2390
0644
edit
dl
rm
froxlor-auth
354
0644
edit
dl
rm
gitlab
392
0644
edit
dl
rm
grafana
564
0644
edit
dl
rm
groupoffice
309
0644
edit
dl
rm
gssftpd
176
0644
edit
dl
rm
guacamole
1016
0644
edit
dl
rm
haproxy-http-auth
943
0644
edit
dl
rm
horde
567
0644
edit
dl
rm
kerio
3304
0644
edit
dl
rm
lighttpd-auth
788
0644
edit
dl
rm
mongodb-auth
2053
0644
edit
dl
rm
monit
2411
0644
edit
dl
rm
murmur
702
0644
edit
dl
rm
mysqld-auth
3696
0644
edit
dl
rm
nagios
226
0644
edit
dl
rm
named-refused
2605
0644
edit
dl
rm
nginx-botsearch
2705
0644
edit
dl
rm
nginx-http-auth
1727
0644
edit
dl
rm
nginx-limit-req
1171
0644
edit
dl
rm
nsd
389
0644
edit
dl
rm
openhab
692
0644
edit
dl
rm
openwebmail
615
0644
edit
dl
rm
oracleims
1843
0644
edit
dl
rm
pam-generic
2429
0644
edit
dl
rm
perdition
589
0644
edit
dl
rm
php-url-fopen
314
0644
edit
dl
rm
phpmyadmin-syslog
177
0644
edit
dl
rm
portsentry
341
0644
edit
dl
rm
postfix
13300
0644
edit
dl
rm
proftpd
2946
0644
edit
dl
rm
pure-ftpd
195
0644
edit
dl
rm
qmail
830
0644
edit
dl
rm
recidive
1409
0644
edit
dl
rm
roundcube-auth
5555
0644
edit
dl
rm
scanlogd
854
0644
edit
dl
rm
screensharingd
1118
0644
edit
dl
rm
selinux-ssh
3436
0644
edit
dl
rm
sendmail-auth
2191
0644
edit
dl
rm
sendmail-reject
10485
0644
edit
dl
rm
sieve
535
0644
edit
dl
rm
slapd
1146
0644
edit
dl
rm
softethervpn
648
0644
edit
dl
rm
sogo-auth
3552
0644
edit
dl
rm
solid-pop3d
1626
0644
edit
dl
rm
squid
895
0644
edit
dl
rm
squirrelmail
197
0644
edit
dl
rm
sshd
32903
0644
edit
dl
rm
sshd-journal
24396
0644
edit
dl
rm
stunnel
267
0644
edit
dl
rm
suhosin
1288
0644
edit
dl
rm
tine20
520
0644
edit
dl
rm
traefik-auth
1853
0644
edit
dl
rm
uwimap-auth
1545
0644
edit
dl
rm
vsftpd
1122
0644
edit
dl
rm
webmin-auth
640
0644
edit
dl
rm
wuftpd
631
0644
edit
dl
rm
xinetd-fail
331
0644
edit
dl
rm
znc-adminlog
708
0644
edit
dl
rm
zoneminder
230
0644
edit
dl
rm
zzz-generic-example
4245
0644
edit
dl
rm
zzz-sshd-obsolete-multiline
36
0644
edit
dl
rm
Edit:
/usr/lib/python3/dist-packages/fail2ban/tests/files/logs/exim
(10145B)
# From IRC 2013-01-04 # failJSON: { "time": "2013-01-04T17:03:46", "match": true , "host": "24.106.174.74" } 2013-01-04 17:03:46 login authenticator failed for rrcs-24-106-174-74.se.biz.rr.com ([192.168.2.33]) [24.106.174.74]: 535 Incorrect authentication data (set_id=brian) # From IRC 2013-06-13 XATRIX (Georgiy Mernov) # failJSON: { "time": "2013-06-12T03:57:58", "match": true , "host": "120.196.140.45" } 2013-06-12 03:57:58 login authenticator failed for (ylmf-pc) [120.196.140.45]: 535 Incorrect authentication data: 1 Time(s) # failJSON: { "time": "2013-06-12T13:18:11", "match": true , "host": "101.66.165.86" } 2013-06-12 13:18:11 login authenticator failed for (USER-KVI9FGS9KP) [101.66.165.86]: 535 Incorrect authentication data # failJSON: { "time": "2013-06-10T10:10:59", "match": true , "host": "193.169.56.211" } 2013-06-10 10:10:59 H=ufficioestampa.it (srv.ufficioestampa.it) [193.169.56.211] sender verify fail for <user@example.com>: Unrouteable address # http://forum.lissyara.su/viewtopic.php?f=20&t=29857 # 2010-11-24 21:48:41 1PLKOW-00046U-EW F=wvhluo@droolindog.com H=93-143-146-237.adsl.net.t-com.hr (droolindog.com) [93.143.146.237] I=[10.10.10.32]:25 P=esmtp temporarily rejected by local_scan(): Temporary local problem # http://us.generation-nt.com/answer/exim-spamassassin-2010-0-x64-help-204020461.html # 2011-07-07 15:44:16 1QexIu-0006dj-PX F=XXXXXX@XXXXXXXXXXXX H=localhost (saf.bio.caltech.edu) [127.0.0.1] P=esmtp temporarily rejected by local_scan(): Local configuration error - local_scan() library failure/usr/lib/exim/sa-exim.so: cannot open shared object file: No such file or directory # failJSON: { "time": "2013-06-10T18:33:32", "match": true , "host": "202.132.70.178" } 2013-06-10 18:33:32 [10099] H=(yakult.com.tw) [202.132.70.178]:3755 I=[1.2.3.4]:25 F=menacedsj04@listserv.eurasia.org rejected RCPT dir@ml3.ru: relay not permitted # failJSON: { "time": "2013-06-02T06:54:20", "match": true , "host": "211.148.195.192" } 2013-06-02 06:54:20 [13314] SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=[211.148.195.192]:25936 I=[1.2.3.4]:25 input="GET / HTTP/1.1\r\n\r\n" # failJSON: { "time": "2013-06-02T09:05:48", "match": true , "host": "82.96.160.77" } 2013-06-02 09:05:48 [18505] SMTP protocol synchronization error (next input sent too soon: pipelining was not advertised): rejected "RSET" H=ba77.mx83.fr [82.96.160.77]:58302 I=[1.2.3.4]:25 next input="QUIT\r\n" # failJSON: { "time": "2013-06-02T09:22:05", "match": true , "host": "163.14.21.161" } 2013-06-02 09:22:05 [19591] SMTP call from pc012-6201.spo.scu.edu.tw [163.14.21.161]:3767 I=[1.2.3.4]:25 dropped: too many nonmail commands (last was "RSET") # failJSON: { "time": "2013-06-02T09:22:06", "match": true , "host": "192.0.2.109" } 2013-06-02 09:22:06 SMTP call from [192.0.2.109] dropped: too many syntax or protocol errors (last command was "AUTH LOGIN") # failJSON: { "time": "2013-06-02T15:06:18", "match": true , "host": "46.20.35.114" } 2013-06-02 15:06:18 H=(VM-WIN2K3-1562) [46.20.35.114] sender verify fail for <usfh@technological-systems.com>: Unknown user # failJSON: { "time": "2013-06-07T02:02:09", "match": true , "host": "91.232.21.92" } 2013-06-07 02:02:09 H=treeladders.kiev.ua [91.232.21.92] sender verify fail for <mailer@treeladders.kiev.ua>: all relevant MX records point to non-existent hosts # failJSON: { "time": "2013-06-15T16:34:55", "match": true , "host": "182.18.24.93" } 2013-06-15 16:34:55 H=mx.tillions.com [182.18.24.93] F=<buh@caladan.ebay.sun.com> rejected RCPT <ruslan@maslovskiy.com.ua>: Sender verify failed # failJSON: { "time": "2013-06-15T16:36:49", "match": true , "host": "111.67.203.116" } 2013-06-15 16:36:49 H=altmx.marsukov.com [111.67.203.116] F=<kadrofutcheti@mail.ru> rejected RCPT <oksana@birzhatm.ua>: Unknown user # 'https://github.com/fail2ban/fail2ban/pull/251#issuecomment-23001227' # failJSON: { "time": "2013-08-20T07:48:02", "match": true , "host": "85.25.92.177" } 2013-08-20 07:48:02 login authenticator failed for static-ip-85-25-92-177.inaddr.ip-pool.com (USER) [85.25.92.177]: 535 Incorrect authentication data: 1 Time(s) # failJSON: { "time": "2013-08-20T23:30:05", "match": true , "host": "91.218.72.71" } 2013-08-20 23:30:05 plain authenticator failed for ([192.168.2.102]) [91.218.72.71]: 535 Incorrect authentication data: 1 Time(s) # failJSON: { "time": "2013-09-02T09:19:07", "match": true , "host": "118.233.20.68" } 2013-09-02 09:19:07 login authenticator failed for (gkzwsoju) [118.233.20.68]: 535 Incorrect authentication data # failJSON: { "time": "2014-01-12T02:07:48", "match": true , "host": "85.214.85.40" } 2014-01-12 02:07:48 dovecot_login authenticator failed for h1832461.stratoserver.net (User) [85.214.85.40]: 535 Incorrect authentication data (set_id=scanner) # failJSON: { "time": "2014-12-02T03:00:23", "match": true , "host": "193.254.202.35" } 2014-12-02 03:00:23 auth_plain authenticator failed for (rom182) [193.254.202.35]:41556 I=[10.0.0.1]:25: 535 Incorrect authentication data (set_id=webmaster) # failJSON: { "time": "2016-03-18T00:34:06", "match": true , "host": "45.32.34.167" } 2016-03-18 00:34:06 [7513] SMTP protocol error in "AUTH LOGIN" H=(ylmf-pc) [45.32.34.167]:60723 I=[172.89.0.6]:587 AUTH command used when not advertised # failJSON: { "time": "2016-03-19T18:40:44", "match": true , "host": "92.45.204.170" } 2016-03-19 18:40:44 [26221] SMTP protocol error in "AUTH LOGIN aW5mb0BtYW5iYXQub3Jn" H=([127.0.0.1]) [92.45.204.170]:14243 I=[172.89.0.6]:587 AUTH command used when not advertised # failJSON: { "time": "2016-05-17T06:25:27", "match": true , "host": "69.10.61.61", "desc": "from gh-1430" } 2016-05-17 06:25:27 SMTP protocol error in "AUTH LOGIN" H=(ylmf-pc) [69.10.61.61] AUTH command used when not advertised # failJSON: { "time": "2016-03-21T06:38:05", "match": true , "host": "49.212.207.15" } 2016-03-21 06:38:05 [5718] no MAIL in SMTP connection from www3005.sakura.ne.jp [49.212.207.15]:28890 I=[172.89.0.6]:25 D=21s C=EHLO,STARTTLS # failJSON: { "time": "2016-03-21T06:57:36", "match": true , "host": "122.165.71.116" } 2016-03-21 06:57:36 [5908] no MAIL in SMTP connection from [122.165.71.116]:2056 I=[172.89.0.6]:25 D=0s # failJSON: { "time": "2016-03-21T06:57:36", "match": true , "host": "122.165.71.116" } 2016-03-21 06:57:36 [5908] no MAIL in SMTP connection from [122.165.71.116] I=[172.89.0.6]:25 D=10s # failJSON: { "time": "2016-03-21T04:07:49", "match": true , "host": "174.137.147.204" } 2016-03-21 04:07:49 [25874] 1ahr79-0006jK-G9 SMTP connection from (voyeur.webair.com) [174.137.147.204]:44884 I=[172.89.0.6]:25 closed by DROP in ACL # failJSON: { "time": "2016-03-21T04:33:13", "match": true , "host": "206.214.71.53" } 2016-03-21 04:33:13 [26074] 1ahrVl-0006mY-79 SMTP connection from riveruse.com [206.214.71.53]:39865 I=[172.89.0.6]:25 closed by DROP in ACL # failJSON: { "time": "2016-03-21T04:33:14", "match": true , "host": "192.0.2.33", "desc": "short form without optional session-id" } 2016-03-21 04:33:14 SMTP connection from (some.domain) [192.0.2.33] closed by DROP in ACL # failJSON: { "time": "2016-04-01T11:08:39", "match": true , "host": "192.0.2.1" } 2016-04-01 11:08:39 [18643] no MAIL in SMTP connection from host.example.com (SERVER) [192.0.2.1]:1418 I=[172.89.0.6]:25 D=34s C=EHLO,AUTH # failJSON: { "time": "2016-04-01T11:08:40", "match": true , "host": "192.0.2.2" } 2016-04-01 11:08:40 [18643] no MAIL in SMTP connection from host.example.com (SERVER) [192.0.2.2]:1418 I=[172.89.0.6]:25 D=2m42s C=QUIT # failJSON: { "time": "2016-04-01T11:09:21", "match": true , "host": "192.0.2.1" } 2016-04-01 11:09:21 [18648] SMTP protocol error in "AUTH LOGIN" H=host.example.com (SERVER) [192.0.2.1]:4692 I=[172.89.0.6]:25 AUTH command used when not advertised # failJSON: { "time": "2016-03-27T16:48:48", "match": true , "host": "192.0.2.1" } 2016-03-27 16:48:48 [21478] 1akDqs-0005aQ-9b SMTP connection from host.example.com (SERVER) [192.0.2.1]:47714 I=[172.89.0.6]:25 closed by DROP in ACL # failJSON: { "time": "2017-04-23T22:45:59", "match": true , "host": "192.0.2.2", "desc": "optional part (...)" } 2017-04-23 22:45:59 fixed_login authenticator failed for bad.host.example.com [192.0.2.2]:54412 I=[172.89.0.6]:587: 535 Incorrect authentication data (set_id=user@example.com) # failJSON: { "time": "2017-05-01T07:42:42", "match": true , "host": "192.0.2.3", "desc": "rejected RCPT - Unrouteable address" } 2017-05-01 07:42:42 H=some.rev.dns.if.found (the.connector.reports.this.name) [192.0.2.3] F=<some.name@some.domain> rejected RCPT <some.invalid.name@a.domain>: Unrouteable address # failJSON: { "time": "2017-11-28T14:14:30", "match": true , "host": "192.0.2.4", "desc": "lower case AUTH command" } 2017-11-28 14:14:30 SMTP protocol error in "auth login" H=(roxzgj) [192.0.2.4] AUTH command used when not advertised # failJSON: { "time": "2017-11-28T14:14:31", "match": true , "host": "192.0.2.5", "desc": "mixed case AUTH command" } 2017-11-28 14:14:31 SMTP protocol error in "aUtH lOgIn" H=(roxzgj) [192.0.2.5] AUTH command used when not advertised # failJSON: { "time": "2017-11-28T14:14:32", "match": true , "host": "192.0.2.6", "desc": "quoted injecting on AUTH command" } 2017-11-28 14:14:32 SMTP protocol error in "aUtH lOgIn" H=(test) [8.8.8.8]" H=(roxzgj) [192.0.2.6] AUTH command used when not advertised ## no matches with `mode = normal`: # failJSON: { "match": false , "desc": "aggressive mode only" } 2017-12-03 08:32:00 no host name found for IP address 192.0.2.8 # failJSON: { "match": false , "desc": "aggressive mode only" } 2017-12-03 08:51:35 no IP address found for host test.example.com (during SMTP connection from [192.0.2.9]) # filterOptions: [{"mode": "aggressive"}] # failJSON: { "time": "2017-12-03T08:32:00", "match": true , "host": "192.0.2.8", "desc": "no host found for IP" } 2017-12-03 08:32:00 no host name found for IP address 192.0.2.8 # failJSON: { "time": "2017-12-03T08:51:35", "match": true , "host": "192.0.2.9", "desc": "no IP found for host" } 2017-12-03 08:51:35 no IP address found for host test.example.com (during SMTP connection from [192.0.2.9])
Save
cmd:
run