/
usr
/
lib
/
python3
/
dist-packages
/
fail2ban
/
tests
/
files
/
logs
/
/usr/lib/python3/dist-packages/fail2ban/tests/files/logs
mkdir
upload
Name
Size
Mode
Actions
bsd/
-
0755
rm
3proxy
575
0644
edit
dl
rm
apache-auth
12805
0644
edit
dl
rm
apache-badbots
688
0644
edit
dl
rm
apache-botsearch
3750
0644
edit
dl
rm
apache-fakegooglebot
480
0644
edit
dl
rm
apache-modsecurity
2655
0644
edit
dl
rm
apache-nohome
406
0644
edit
dl
rm
apache-noscript
2702
0644
edit
dl
rm
apache-overflows
2476
0644
edit
dl
rm
apache-pass
273
0644
edit
dl
rm
apache-shellshock
499
0644
edit
dl
rm
assp
5209
0644
edit
dl
rm
asterisk
13683
0644
edit
dl
rm
bitwarden
741
0644
edit
dl
rm
centreon
252
0644
edit
dl
rm
counter-strike
399
0644
edit
dl
rm
courier-auth
1070
0644
edit
dl
rm
courier-smtp
1735
0644
edit
dl
rm
cyrus-imap
2455
0644
edit
dl
rm
directadmin
835
0644
edit
dl
rm
domino-smtp
1295
0644
edit
dl
rm
dovecot
11017
0644
edit
dl
rm
dropbear
1329
0644
edit
dl
rm
drupal-auth
788
0644
edit
dl
rm
ejabberd-auth
1490
0644
edit
dl
rm
exim
10145
0644
edit
dl
rm
exim-spam
3462
0644
edit
dl
rm
freeswitch
2390
0644
edit
dl
rm
froxlor-auth
354
0644
edit
dl
rm
gitlab
392
0644
edit
dl
rm
grafana
564
0644
edit
dl
rm
groupoffice
309
0644
edit
dl
rm
gssftpd
176
0644
edit
dl
rm
guacamole
1016
0644
edit
dl
rm
haproxy-http-auth
943
0644
edit
dl
rm
horde
567
0644
edit
dl
rm
kerio
3304
0644
edit
dl
rm
lighttpd-auth
788
0644
edit
dl
rm
mongodb-auth
2053
0644
edit
dl
rm
monit
2411
0644
edit
dl
rm
murmur
702
0644
edit
dl
rm
mysqld-auth
3696
0644
edit
dl
rm
nagios
226
0644
edit
dl
rm
named-refused
2605
0644
edit
dl
rm
nginx-botsearch
2705
0644
edit
dl
rm
nginx-http-auth
1727
0644
edit
dl
rm
nginx-limit-req
1171
0644
edit
dl
rm
nsd
389
0644
edit
dl
rm
openhab
692
0644
edit
dl
rm
openwebmail
615
0644
edit
dl
rm
oracleims
1843
0644
edit
dl
rm
pam-generic
2429
0644
edit
dl
rm
perdition
589
0644
edit
dl
rm
php-url-fopen
314
0644
edit
dl
rm
phpmyadmin-syslog
177
0644
edit
dl
rm
portsentry
341
0644
edit
dl
rm
postfix
13300
0644
edit
dl
rm
proftpd
2946
0644
edit
dl
rm
pure-ftpd
195
0644
edit
dl
rm
qmail
830
0644
edit
dl
rm
recidive
1409
0644
edit
dl
rm
roundcube-auth
5555
0644
edit
dl
rm
scanlogd
854
0644
edit
dl
rm
screensharingd
1118
0644
edit
dl
rm
selinux-ssh
3436
0644
edit
dl
rm
sendmail-auth
2191
0644
edit
dl
rm
sendmail-reject
10485
0644
edit
dl
rm
sieve
535
0644
edit
dl
rm
slapd
1146
0644
edit
dl
rm
softethervpn
648
0644
edit
dl
rm
sogo-auth
3552
0644
edit
dl
rm
solid-pop3d
1626
0644
edit
dl
rm
squid
895
0644
edit
dl
rm
squirrelmail
197
0644
edit
dl
rm
sshd
32903
0644
edit
dl
rm
sshd-journal
24396
0644
edit
dl
rm
stunnel
267
0644
edit
dl
rm
suhosin
1288
0644
edit
dl
rm
tine20
520
0644
edit
dl
rm
traefik-auth
1853
0644
edit
dl
rm
uwimap-auth
1545
0644
edit
dl
rm
vsftpd
1122
0644
edit
dl
rm
webmin-auth
640
0644
edit
dl
rm
wuftpd
631
0644
edit
dl
rm
xinetd-fail
331
0644
edit
dl
rm
znc-adminlog
708
0644
edit
dl
rm
zoneminder
230
0644
edit
dl
rm
zzz-generic-example
4245
0644
edit
dl
rm
zzz-sshd-obsolete-multiline
36
0644
edit
dl
rm
Edit:
/usr/lib/python3/dist-packages/fail2ban/tests/files/logs/postfix
(13300B)
# filterOptions: [{}, {"mode": "normal"}, {"mode": "aggressive"}] # per https://github.com/fail2ban/fail2ban/issues/125 # and https://github.com/fail2ban/fail2ban/issues/126 # failJSON: { "time": "2005-02-21T09:21:54", "match": true , "host": "192.0.43.10" } Feb 21 09:21:54 xxx postfix/smtpd[14398]: NOQUEUE: reject: RCPT from example.com[192.0.43.10]: 450 4.7.1 : Helo command rejected: Host not found; from=<> to=<> proto=ESMTP helo= # failJSON: { "time": "2005-07-12T07:47:48", "match": true , "host": "1.2.3.4" } Jul 12 07:47:48 saturn postfix/smtpd[8738]: NOQUEUE: reject: RCPT from 1-2-3-4-example.com[1.2.3.4]: 554 5.7.1 <smtp@example.com>: Relay access denied; from=<john@example.com> to=<smtp@example.org> proto=SMTP helo=<198.51.100.17> # failJSON: { "time": "2005-07-18T23:12:56", "match": true , "host": "192.51.100.65" } Jul 18 23:12:56 xxx postfix/smtpd[8738]: NOQUEUE: reject: RCPT from foo[192.51.100.65]: 554 5.7.1 <bad.domain>: Helo command rejected: match bad.domain; from=<foo@good.domain> to=<foo@porcupine.org> proto=SMTP helo=<bad.domain> # failJSON: { "time": "2005-07-18T23:12:56", "match": true , "host": "192.51.100.43" } Jul 18 23:12:56 xxx postfix/smtpd[8738]: NOQUEUE: reject: RCPT from foo[192.51.100.43]: 554 5.7.1 <foo@bad.domain>: Sender address rejected: match bad.domain; from=<foo@bad.domain> to=<foo@porcupine.org> proto=SMTP helo=<192.51.100.43> # failJSON: { "time": "2005-08-10T10:55:38", "match": true , "host": "72.53.132.234" } Aug 10 10:55:38 f-vanier-bourgeois postfix/smtpd[2162]: NOQUEUE: reject: VRFY from 72-53-132-234.cpe.distributel.net[72.53.132.234]: 550 5.1.1 : Recipient address rejected: User unknown in local recipient tab # failJSON: { "time": "2005-08-13T15:45:46", "match": true , "host": "192.0.2.1" } Aug 13 15:45:46 server postfix/smtpd[13844]: 00ADB3C0899: reject: RCPT from example.com[192.0.2.1]: 550 5.1.1 <sales@server.com>: Recipient address rejected: User unknown in local recipient table; from=<xxxxxx@example.com> to=<sales@server.com> proto=ESMTP helo=<mail.example.com> # failJSON: { "time": "2005-01-12T11:07:49", "match": true , "host": "181.21.131.88" } Jan 12 11:07:49 emf1pt2-2-35-70 postfix/smtpd[13767]: improper command pipelining after DATA from unknown[181.21.131.88]: # failJSON: { "time": "2004-12-25T02:35:54", "match": true , "host": "173.10.140.217" } Dec 25 02:35:54 platypus postfix/smtpd[9144]: improper command pipelining after RSET from 173-10-140-217-BusName-washingtonDC.hfc.comcastbusiness.net[173.10.140.217] # failJSON: { "time": "2004-12-18T02:05:46", "match": true , "host": "216.245.198.245" } Dec 18 02:05:46 platypus postfix/smtpd[16349]: improper command pipelining after NOOP from unknown[216.245.198.245] # failJSON: { "time": "2004-12-21T21:17:29", "match": true , "host": "93.184.216.34" } Dec 21 21:17:29 xxx postfix/smtpd[7150]: NOQUEUE: reject: RCPT from badserver.example.com[93.184.216.34]: 450 4.7.1 Client host rejected: cannot find your hostname, [93.184.216.34]; from=<badactor@example.com> to=<goodguy@example.com> proto=ESMTP helo=<badserver.example.com> # failJSON: { "time": "2004-12-21T21:17:30", "match": true , "host": "93.184.216.34", "desc": "variable status code suffix, gh-2442" } Dec 21 21:17:30 xxx postfix/smtpd[7150]: NOQUEUE: reject: RCPT from badserver.example.com[93.184.216.34]: 450 4.7.25 Client host rejected: cannot find your hostname, [93.184.216.34]; from=<badactor@example.com> to=<goodguy@example.com> proto=ESMTP helo=<badserver.example.com> # failJSON: { "time": "2004-11-22T22:33:44", "match": true , "host": "1.2.3.4" } Nov 22 22:33:44 xxx postfix/smtpd[11111]: NOQUEUE: reject: RCPT from 1-2-3-4.example.com[1.2.3.4]: 450 4.1.8 <some@nonexistant.tld>: Sender address rejected: Domain not found; from=<some@nonexistant.tld> to=<goodguy@example.com> proto=ESMTP helo=<1-2-3-4.example.com> # failJSON: { "time": "2005-01-31T13:55:24", "match": true , "host": "78.107.251.238" } Jan 31 13:55:24 xxx postfix/smtpd[3462]: NOQUEUE: reject: EHLO from s271272.static.corbina.ru[78.107.251.238]: 504 5.5.2 <User>: Helo command rejected: need fully-qualified hostname; proto=SMTP helo=<User> # failJSON: { "time": "2005-01-31T13:55:24", "match": true , "host": "78.107.251.238" } Jan 31 13:55:24 xxx postfix-incoming/smtpd[3462]: NOQUEUE: reject: EHLO from s271272.static.corbina.ru[78.107.251.238]: 504 5.5.2 <User>: Helo command rejected: need fully-qualified hostname; proto=SMTP helo=<User> # failJSON: { "time": "2005-04-12T02:24:11", "match": true , "host": "62.138.2.143" } Apr 12 02:24:11 xxx postfix/smtps/smtpd[42]: NOQUEUE: reject: EHLO from astra4139.startdedicated.de[62.138.2.143]: 504 5.5.2 <User>: Helo command rejected: need fully-qualified hostname; proto=SMTP helo=<User> # failJSON: { "time": "2005-06-12T08:58:35", "match": true , "host": "1.2.3.4" } Jun 12 08:58:35 xxx postfix/smtpd[27296]: NOQUEUE: reject: RCPT from unknown[1.2.3.4]: 450 4.7.1 Client host rejected: cannot find your reverse hostname, [2.3.4.5]; from=<meow@kitty.com> to=<kitty@meow.com> proto=ESMTP helo=<kitty.com> # failJSON: { "time": "2005-06-12T08:58:35", "match": true , "host": "1.2.3.4" } Jun 12 08:58:35 xxx postfix/smtpd[2931]: NOQUEUE: reject: RCPT from unknown[1.2.3.4]: 450 4.7.1 <kitty.com>: Helo command rejected: Host not found; from=<meow@kitty.com> to=<kitty@meow.com> proto=SMTP helo=<kitty.com> # failJSON: { "time": "2005-06-12T08:58:35", "match": true , "host": "1.2.3.4" } Jun 12 08:58:35 xxx postfix/smtpd[13533]: improper command pipelining after AUTH from unknown[1.2.3.4]: QUIT # failJSON: { "time": "2005-05-05T15:51:11", "match": true , "host": "216.245.194.173", "desc": "postfix postscreen / gh-1764" } May 5 15:51:11 xxx postfix/postscreen[1148]: NOQUEUE: reject: RCPT from [216.245.194.173]:60591: 550 5.7.1 Service unavailable; client [216.245.194.173] blocked using rbl.example.com; from=<spammer@example.com>, to=<goodguy@example.com>, proto=ESMTP, helo=<badguy.example.com> # failJSON: { "time": "2005-06-03T06:25:43", "match": true , "host": "192.0.2.11", "desc": "too many errors / gh-2439" } Jun 3 06:25:43 srv postfix/smtpd[29306]: too many errors after RCPT from example.com[192.0.2.11] # filterOptions: [{"mode": "errors"}] # failJSON: { "match": false, "desc": "ignore normal messages, jail for too many errors only" } Jun 12 08:58:35 srv postfix/smtpd[29306]: improper command pipelining after AUTH from unknown[192.0.2.11]: QUIT # failJSON: { "time": "2005-06-03T06:25:43", "match": true , "host": "192.0.2.11", "desc": "too many errors / gh-2439" } Jun 3 06:25:43 srv postfix/smtpd[29306]: too many errors after RCPT from example.com[192.0.2.11] # --------------------------------------- # Test-cases of postfix-rbl: # --------------------------------------- # filterOptions: [{}, {"mode": "rbl"}, {"mode": "aggressive"}] # failJSON: { "time": "2004-12-30T18:19:15", "match": true , "host": "93.184.216.34" } Dec 30 18:19:15 xxx postfix/smtpd[1574]: NOQUEUE: reject: RCPT from badguy.example.com[93.184.216.34]: 454 4.7.1 Service unavailable; Client host [93.184.216.34] blocked using rbl.example.com; http://www.example.com/query?ip=93.184.216.34; from=<spammer@example.com> to=<goodguy@example.com> proto=ESMTP helo=<badguy.example.com> # failJSON: { "time": "2004-12-30T18:19:15", "match": true , "host": "93.184.216.34" } Dec 30 18:19:15 xxx postfix-incoming/smtpd[1574]: NOQUEUE: reject: RCPT from badguy.example.com[93.184.216.34]: 454 4.7.1 Service unavailable; Client host [93.184.216.34] blocked using rbl.example.com; http://www.example.com/query?ip=93.184.216.34; from=<spammer@example.com> to=<goodguy@example.com> proto=ESMTP helo=<badguy.example.com> # failJSON: { "time": "2005-02-07T12:25:45", "match": true , "host": "87.236.233.182" } Feb 7 12:25:45 xxx12345 postfix/smtpd[13275]: NOQUEUE: reject: RCPT from unknown[87.236.233.182]: 554 5.7.1 Service unavailable; Client host [87.236.233.182] blocked using rbl.example.com; https://www.example.com/query/ip/87.236.233.182; from=<spammer@example.com> to=<goodguy@example.com> proto=SMTP helo=<WIN-5N8GBBS0R5I> # --------------------------------------- # Test-cases of postfix-sasl: # --------------------------------------- # filterOptions: [{"mode": "auth"}, {"mode": "aggressive"}] #1 Example from postfix from dbts #507990 # failJSON: { "time": "2004-12-02T22:24:22", "match": true , "host": "114.44.142.233" } Dec 2 22:24:22 hel postfix/smtpd[7676]: warning: 114-44-142-233.dynamic.hinet.net[114.44.142.233]: SASL CRAM-MD5 authentication failed: PDc3OTEwNTkyNTEyMzA2NDIuMTIyODI1MzA2MUBoZWw+ #2 Example from postfix from dbts #573314 # failJSON: { "time": "2005-03-10T13:33:30", "match": true , "host": "1.1.1.1" } Mar 10 13:33:30 gandalf postfix/smtpd[3937]: warning: HOSTNAME[1.1.1.1]: SASL LOGIN authentication failed: authentication failure #3 Example from postfix post-debian changes to rename to add "submission" to syslog name # failJSON: { "time": "2004-09-06T00:44:56", "match": true , "host": "82.221.106.233" } Sep 6 00:44:56 trianon postfix/submission/smtpd[11538]: warning: unknown[82.221.106.233]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 #4 Example from postfix post-debian changes to rename to add "submission" to syslog name + downcase # failJSON: { "time": "2004-09-06T00:44:57", "match": true , "host": "82.221.106.233" } Sep 6 00:44:57 trianon postfix/submission/smtpd[11538]: warning: unknown[82.221.106.233]: SASL login authentication failed: UGFzc3dvcmQ6 #5 Example to add : # failJSON: { "time": "2005-01-29T08:11:45", "match": true , "host": "1.1.1.1" } Jan 29 08:11:45 mail postfix/smtpd[10752]: warning: unknown[1.1.1.1]: SASL LOGIN authentication failed: Password: # failJSON: { "time": "2005-01-29T08:11:45", "match": true , "host": "1.1.1.1" } Jan 29 08:11:45 mail postfix-incoming/smtpd[10752]: warning: unknown[1.1.1.1]: SASL LOGIN authentication failed: Password: # failJSON: { "time": "2005-04-12T02:24:11", "match": true , "host": "62.138.2.143" } Apr 12 02:24:11 xxx postfix/smtps/smtpd[42]: warning: astra4139.startdedicated.de[62.138.2.143]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 # failJSON: { "time": "2005-08-03T15:30:49", "match": true , "host": "98.191.84.74" } Aug 3 15:30:49 ksusha postfix/smtpd[17041]: warning: mail.foldsandwalker.com[98.191.84.74]: SASL Plain authentication failed: # failJSON: { "time": "2005-08-04T16:47:52", "match": true , "host": "192.0.2.237", "desc": "cover optional port after host" } Aug 4 16:47:52 mail3 postfix/smtpd[31152]: warning: unknown[192.0.2.237]:55729: SASL LOGIN authentication failed: authentication failure # failJSON: { "time": "2004-11-04T09:11:01", "match": true , "host": "192.0.2.150", "desc": "without reason for fail, see gh-1245" } Nov 4 09:11:01 mail postfix/submission/smtpd[27133]: warning: unknown[192.0.2.150]: SASL PLAIN authentication failed: #6 Example to ignore because due to a failed attempt to connect to authentication service - no malicious activities whatsoever # failJSON: { "match": false } Feb 3 08:29:28 mail postfix/smtpd[21022]: warning: unknown[1.1.1.1]: SASL LOGIN authentication failed: Connection lost to authentication server # filterOptions: [{"mode": "auth"}] # failJSON: { "match": false, "desc": "not aggressive" } Jan 14 16:18:16 xxx postfix/smtpd[14933]: warning: host[192.0.2.5]: SASL CRAM-MD5 authentication failed: Invalid authentication mechanism # filterOptions: [{"mode": "aggressive"}] # failJSON: { "time": "2005-01-14T16:18:16", "match": true , "host": "192.0.2.5", "desc": "aggressive only" } Jan 14 16:18:16 xxx postfix/smtpd[14933]: warning: host[192.0.2.5]: SASL CRAM-MD5 authentication failed: Invalid authentication mechanism # --------------------------------------- # Test-cases of postfix DDOS mode: # --------------------------------------- # filterOptions: [{"mode": "ddos"}, {"mode": "aggressive"}] # failJSON: { "time": "2005-02-10T13:26:34", "match": true , "host": "192.0.2.1" } Feb 10 13:26:34 srv postfix/smtpd[123]: disconnect from unknown[192.0.2.1] helo=1 auth=0/1 quit=1 commands=2/3 # failJSON: { "time": "2005-02-10T13:26:34", "match": true , "host": "192.0.2.2" } Feb 10 13:26:34 srv postfix/smtpd[123]: disconnect from unknown[192.0.2.2] ehlo=1 auth=0/1 rset=1 quit=1 commands=3/4 # failJSON: { "time": "2005-02-18T09:45:10", "match": true , "host": "192.0.2.10" } Feb 18 09:45:10 xxx postfix/smtpd[42]: lost connection after CONNECT from spammer.example.com[192.0.2.10] # failJSON: { "time": "2005-02-18T09:45:12", "match": true , "host": "192.0.2.42" } Feb 18 09:45:12 xxx postfix/smtpd[42]: lost connection after STARTTLS from spammer.example.com[192.0.2.42] # failJSON: { "time": "2005-02-18T09:48:04", "match": true , "host": "192.0.2.23" } Feb 18 09:48:04 xxx postfix/smtpd[23]: lost connection after AUTH from unknown[192.0.2.23] # failJSON: { "time": "2005-02-18T09:48:04", "match": true , "host": "192.0.2.23" } Feb 18 09:48:04 xxx postfix/smtpd[23]: lost connection after AUTH from unknown[192.0.2.23] # filterOptions: [{}, {"mode": "ddos"}, {"mode": "aggressive"}] # failJSON: { "match": false, "desc": "don't affect lawful data (sporadical connection aborts within DATA-phase, see gh-1813 for discussion)" } Feb 18 09:50:05 xxx postfix/smtpd[42]: lost connection after DATA from good-host.example.com[192.0.2.10]
Save
cmd:
run