Package: fail2ban
Version: 0.7.5-2
Severity: important
Tags: patch

fail2ban does not parse correctly /var/log/auth.log on my server
An example line is
Failed password for chloe from 12.34.56.78 port 58531 ssh2
(the address has been faked since it's one of my boxen, I was testing the ban 
feature)
A regex adapted to this line could be 
failregex = Failed password for .* from <HOST> port [0-9]+ (ssh2)?

For information, here's my SSH version
Package: ssh
Installed-Size: 32
Maintainer: Matthew Vernon <[EMAIL PROTECTED]>
Architecture: all
Source: openssh
Version: 1:4.3p2-9

Hope this helps
-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.21.1dedibox-r7
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)

Versions of packages fail2ban depends on:
ii  iptables                1.3.6.0debian1-5 administration tools for packet fi
ii  lsb-base                3.1-23.2etch1    Linux Standard Base 3.1 init scrip
ii  python                  2.4.4-2          An interactive high-level object-o
ii  python-central          0.5.12           register and build utility for Pyt
ii  python2.4               2.4.4-3          An interactive high-level object-o

fail2ban recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to