Your message dated Thu, 22 Nov 2007 14:19:51 -0500
with message-id <[EMAIL PROTECTED]>
and subject line [EMAIL PROTECTED]: Re: Bug#452396: fail2ban fails to parse 
/var/log/auth.log]
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: fail2ban
Version: 0.7.5-2
Severity: important
Tags: patch

fail2ban does not parse correctly /var/log/auth.log on my server
An example line is
Failed password for chloe from 12.34.56.78 port 58531 ssh2
(the address has been faked since it's one of my boxen, I was testing the ban 
feature)
A regex adapted to this line could be 
failregex = Failed password for .* from <HOST> port [0-9]+ (ssh2)?

For information, here's my SSH version
Package: ssh
Installed-Size: 32
Maintainer: Matthew Vernon <[EMAIL PROTECTED]>
Architecture: all
Source: openssh
Version: 1:4.3p2-9

Hope this helps
-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.21.1dedibox-r7
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)

Versions of packages fail2ban depends on:
ii  iptables                1.3.6.0debian1-5 administration tools for packet fi
ii  lsb-base                3.1-23.2etch1    Linux Standard Base 3.1 init scrip
ii  python                  2.4.4-2          An interactive high-level object-o
ii  python-central          0.5.12           register and build utility for Pyt
ii  python2.4               2.4.4-3          An interactive high-level object-o

fail2ban recommends no packages.

-- no debconf information



--- End Message ---
--- Begin Message ---
I am closing the bug for now ;-)

----- Forwarded message from ChloƩ Desoutter <[EMAIL PROTECTED]> -----

Date: Thu, 22 Nov 2007 18:52:17 +0100
From: ChloƩ Desoutter <[EMAIL PROTECTED]>
To: Yaroslav Halchenko <[EMAIL PROTECTED]>
Subject: Re: Bug#452396: fail2ban fails to parse /var/log/auth.log
X-CRM114-Status: Good  ( pR: 23.9122 )


   Indeed, it works after reinstalling it. There must have been something
   wrong in either the log format of sshd or my fail2ban conf.
   You may close it, tested and working (using log level 4 I can check).
   Thanks for the help,
   CD
-- 
Yaroslav Halchenko
Research Assistant, Psychology Department, Rutgers-Newark
Student  Ph.D. @ CS Dept. NJIT
Office: (973) 353-5440x263 | FWD: 82823 | Fax: (973) 353-1171
        101 Warren Str, Smith Hall, Rm 4-105, Newark NJ 07102
WWW:     http://www.linkedin.com/in/yarik        


--- End Message ---

Reply via email to