-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New filter for vnc or screensharingd on OS X 10.9 #1008
Comments
Awesome, care to share with a pull request? |
note that .* on both sides of is a bad sign making possible to Yaroslav O. Halchenko, Ph.D. |
I'd be happy to share, but how do I perform a "pull request"? (Please forgive the non-developer newbie..) # Fail2Ban filter for vnc or screensharingd
#
[INCLUDES]
before = common.conf
[Definition]
_daemon = (?:screensharingd|vnc)
failregex = ^%(__prefix_line)sAuthentication: FAILED :: User Name: .*? :: Viewer Address: <HOST> :: Type: (?:DH|.*?)$
ignoreregex =
# Author: Peter Franzén, 2015 I've tested it, using fail2ban-regex, and it still matches the occurrances in my log:
As for the jail, it is configured like this: [vnc]
enabled = true
filter = vnc
port = 5900
action = osx-ipfw[protocol=all,port=5900,localhost=me]
logpath = /var/log/system.log
maxretry = 8 Note the keyword "me".. As for the action I made this change: [Init]
# Option: port
# Notes.: specifies port to block. Can be blank however may require block="ip"
# Values: [ NUM | STRING ]
#
# port = ssh
port =
# Option: dst
# Notes.: the local IP address of the network interface
# Values: IP, any, me or anything support by ipfw as a dst
#
dst = me Kind regards, |
How do I go about adding this to my fail2ban installation? I'm a little confused on this stuff. |
In my case I've got the fail2ban config siituated at /usr/local/etc/fail2ban. There is a subfolder named 'filter'. Look whats in there, and save a file that looks like the others with the contents above. |
Awesome, thank you. |
I created this filter and it seems to work:
The text was updated successfully, but these errors were encountered: