• [^] # Re: Lignes ERROR

    Posté par . En réponse au message fail2ban ne ban pas (enfin pas souvent). Évalué à 2.

    oui, les lignes d'erreur sont bizarres, mais je ne sais pas trop d'où ça vient.
    J'ai essayé avec un ami de voir s'il était banni, et le résultat est oui :

    auth.log :
    Mar 23 21:36:51 valinor sshd[27702]: Invalid user bbob from xx.168.169.xx
    Mar 23 21:36:51 valinor sshd[27702]: Failed none for invalid user bbob from xx.168.169.xx port 53209 ssh2
    Mar 23 21:37:00 valinor sshd[27702]: pam_unix(sshd:auth): check pass; user unknown
    Mar 23 21:37:00 valinor sshd[27702]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=rke29-1-xx-168-169-xx.fbx.proxad.net
    Mar 23 21:37:02 valinor sshd[27702]: Failed password for invalid user bbob from xx.168.169.xx port 53209 ssh2


    fail2ban.log
    2010年03月23日 21:37:04,441 fail2ban.actions: WARNING [ssh] Ban xx.168.169.xx
    2010年03月23日 21:47:04,661 fail2ban.actions: WARNING [ssh] Unban xx.168.169.xx


    iptables -L

    iptables -L
    [sudo] password for gart:
    Chain INPUT (policy ACCEPT)
    target prot opt source destination
    fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
    ACCEPT all -- anywhere anywhere
    ACCEPT icmp -- anywhere anywhere
    ACCEPT igmp -- anywhere anywhere
    ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
    ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
    ACCEPT tcp -- anywhere anywhere tcp dpt:smtp
    ACCEPT tcp -- anywhere anywhere tcp dpt:imap2
    ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
    ACCEPT tcp -- anywhere anywhere tcp dpt:www
    ACCEPT tcp -- anywhere anywhere tcp dpt:https
    ACCEPT udp -- anywhere anywhere udp dpt:1234
    ACCEPT udp -- anywhere 224.0.0.251 udp dpt:mdns
    LOG all -- anywhere anywhere LOG level warning prefix `paquet IPv4 inattendu '
    REJECT all -- anywhere anywhere reject-with icmp-port-unreachable

    Chain FORWARD (policy ACCEPT)
    target prot opt source destination

    Chain OUTPUT (policy ACCEPT)
    target prot opt source destination

    Chain fail2ban-ssh (1 references)
    target prot opt source destination
    DROP all -- rke29-1-xx-168-169-xx.fbx.proxad.net anywhere
    RETURN all -- anywhere anywhere

    mais les vrais méchants, ils ont l'air de toujours passer eux :(