多个sshd的正则表达式从…接收断开[preauth]

前端之家收集整理的这篇文章主要介绍了多个sshd的正则表达式从…接收断开[preauth]前端之家小编觉得挺不错的,现在分享给大家,也给大家做个参考。
fail2ban正则表达式会捕获这些日志吗?
  1. Apr 9 08:48:28 server sshd[1856]: Received disconnect from 43.255.190.117: 11: [preauth]
  2. Apr 9 09:06:05 server sshd[1936]: Received disconnect from 43.255.191.159: 11: [preauth]
  3. Apr 9 09:06:10 server sshd[1938]: Received disconnect from 43.255.190.126: 11: [preauth]
  4. Apr 9 09:31:12 server sshd[2005]: Received disconnect from 43.255.190.123: 11: [preauth]
  5. Apr 9 09:37:06 server sshd[2013]: Received disconnect from 43.255.190.149: 11: [preauth]
  6. Apr 9 09:53:55 server sshd[2036]: Received disconnect from 43.255.190.149: 11: [preauth]
  7. Apr 9 10:16:59 server sshd[2368]: Received disconnect from 43.255.190.165: 11: [preauth]
  8. Apr 9 10:47:30 server sshd[3800]: Received disconnect from 43.255.190.150: 11: [preauth]
  9. Apr 9 11:04:01 server sshd[6855]: Received disconnect from 43.255.190.131: 11: [preauth]

和/或与Bye Bye

  1. Apr 9 12:29:59 server sshd[7764]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  2. Apr 9 12:30:00 server sshd[7766]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  3. Apr 9 12:30:01 server sshd[7768]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  4. Apr 9 12:30:03 server sshd[7776]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  5. Apr 9 12:30:04 server sshd[7778]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  6. Apr 9 12:30:05 server sshd[7780]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  7. Apr 9 12:30:06 server sshd[7782]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  8. Apr 9 12:30:07 server sshd[7784]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  9. Apr 9 12:30:08 server sshd[7786]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  10. Apr 9 12:30:10 server sshd[7788]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  11. Apr 9 12:30:11 server sshd[7790]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  12. Apr 9 12:30:12 server sshd[7792]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  13. Apr 9 12:30:13 server sshd[7794]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  14. Apr 9 12:30:14 server sshd[7796]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  15. Apr 9 12:30:15 server sshd[7798]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]
  16. Apr 9 12:30:17 server sshd[7800]: Received disconnect from 180.210.234.87: 11: Bye Bye [preauth]

无论这些人在做什么,我都想要一个fail2ban规则.尽管尝试的频率很高,显然他们没有做任何其他事情来绊倒fail2ban.

您可以使用此规则:
  1. ^%(__prefix_line)sReceived disconnect from <HOST>: 11: (Bye Bye)? \[preauth\]$

要使用fail2ban-regex或egrep对其进行测试,您可以从头开始剥离^%(__ prefix_line).将此行添加到/etc/fail2ban/filter.d/sshd.conf中的failregex变量中.

使用fail2ban-regex的运行给了我这些结果,确认规则匹配:

  1. Running tests
  2. =============
  3.  
  4. Use regex file : sshd.conf
  5. Use log file : /var/log/auth.log
  6.  
  7.  
  8. Results
  9. =======
  10.  
  11. Failregex
  12. |- Regular expressions:
  13. [...]
  14. | [11] ^\s*(?:\S+ )?(?:kernel: \[\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:)?\s*Received disconnect from <HOST>: 11: (Bye Bye)? \[preauth\]$
  15. |
  16. `- Number of matches:
  17. [...]
  18. [11] 545 match(es)
  19. [...]

猜你在找的正则表达式相关文章