sebres
7212404e8f
amend to 5cbe4b8b01 (systemd RC-fix): lock by closing of journal too (in afterStop, since _closeJournal used in _reopenJournal in lock, and lock is not reentrant)
Codespell / Check for spelling errors (push) Has been cancelled
CI / build (3.10) (push) Has been cancelled
CI / build (3.11) (push) Has been cancelled
CI / build (3.12) (push) Has been cancelled
CI / build (3.13) (push) Has been cancelled
CI / build (3.14) (push) Has been cancelled
CI / build (3.15.0-rc.2) (push) Has been cancelled
CI / build (3.8) (push) Has been cancelled
CI / build (3.9) (push) Has been cancelled
CI / build (pypy3.11) (push) Has been cancelled
2026-09-11 22:05:03 +02:00
sebres
f51ad5a5fb
CI: update Python version to 3.15.0-rc.2 in workflow
2026-09-11 21:44:15 +02:00
sebres
5cbe4b8b01
prevent possible race condition accessing journal from 2 threads in parallel (sporadic "OSError: [Errno 22] Invalid argument" in test_delJournalMatch by addJournalMatch), protect journal handle with lock
2026-09-11 21:26:11 +02:00
sebres
12e94859b8
remove redundant set exclusion (glob for ../system.journal can never contain ../system*@*.journal)
2026-09-11 20:49:22 +02:00
Sergey G. Brester
86e415a76a
Merge pull request #4230 from ChrisJr404/gitlab-json-mode
...
Codespell / Check for spelling errors (push) Has been cancelled
CI / build (3.10) (push) Has been cancelled
CI / build (3.11) (push) Has been cancelled
CI / build (3.12) (push) Has been cancelled
CI / build (3.13) (push) Has been cancelled
CI / build (3.14) (push) Has been cancelled
CI / build (3.15.0-rc.1) (push) Has been cancelled
CI / build (3.8) (push) Has been cancelled
CI / build (3.9) (push) Has been cancelled
CI / build (pypy3.11) (push) Has been cancelled
gitlab: add json mode for application_json.log
2026-08-26 16:06:17 +02:00
Sergey G. Brester
0e2ad0360d
update changelog (mode -> logtype, added PR number)
2026-08-26 16:05:01 +02:00
Chris (ChrisJr404)
7924c55682
gitlab: switch mode parameter to standard logtype (file/json)
2026-08-25 23:47:36 -04:00
Chris (ChrisJr404)
050e0b3460
gitlab: add json mode for application_json.log
...
Gitlab deprecated application.log in 15.10 in favour of the structured
application_json.log. Add a mode option so the filter can read either
format; text stays the default so existing setups keep working.
Closes #3566
2026-08-24 18:00:21 -04:00
sebres
deffcbcd17
add default banactions for several paths-*.conf depending on default net-filter for distribution;
...
closes gh-4224, gh-4229
2026-08-22 13:32:00 +02:00
sebres
46d2acd451
ChangeLog
2026-08-22 13:30:47 +02:00
sebres
63c0a46826
add default banactions for several paths-*.conf depending on default net-filter for distribution;
...
closes gh-4224, gh-4229
2026-08-22 13:26:02 +02:00
Arjen de Korte
c6b20f225c
paths-opensuse.conf: specify default banactions
...
Since 1.1.1 default banactions need to be specified. Take the opportunity to also synchronize the paths with current Factory settings.
2026-08-21 17:53:28 +02:00
Sergey G. Brester
403df4a91c
Merge pull request #4225 from Deric-W/socket-shutdown
...
Fix systemd socket activation being broken
2026-08-20 13:46:36 +02:00
Sergey G. Brester
6185bc3ea2
Update ChangeLog entry (added reference to PR)
2026-08-20 13:45:02 +02:00
Eric Wolf
cbdeee8d81
Fix systemd runtime directory containing persistent socket being removed
...
This resulted in a fail2ban being passed an unreachable socket after being stopped.
2026-08-20 04:03:15 +02:00
Eric Wolf
d574daf22e
Fix sockets passed via socket activation being shut down
...
Doing so results in systemd encountering errors after stopping fail2ban.
2026-08-20 02:33:06 +02:00
Sergey G. Brester
1e12c5a7c7
Merge pull request #4216 from jarihu/add-cowrie-filter
...
Add Cowrie honeypot JSON log filter
2026-08-18 15:28:22 +02:00
sebres
5ecbe89c80
try to optimize RE (skipping tags, no full match and right anchor needed), added datepattern, etc
2026-08-18 15:25:19 +02:00
Jari Huttunen
b552116f4f
Renamed filter to cowrie
2026-08-18 14:55:18 +02:00
Jari Huttunen
dfb8a58d17
Fixed the CI failure by adding a stock [cowrie] jail entry to config/jail.conf.
2026-08-18 14:54:35 +02:00
Jari Huttunen
9584c78bb6
Fix cowrie_json filter against real Cowrie log output
...
The previous regex was written against an assumed field order/spacing
that doesn't match what Cowrie actually emits: no space after ":",
and "eventid" is not the first key (order is session, protocol,
src_ip, ..., eventid, ..., message). Rework the failregex to match
real-world json output, and correct the datepattern to wrap only the
timestamp value (not the "timestamp": key) in the capture group, since
fail2ban excises the whole captured group from the line before
failregex is applied - wrapping the key too left a broken ",," gap in
the JSON that never matched.
Verified against real Cowrie honeypot log samples (session.connect,
client.version, client.kex, login.success, log.closed) and the
existing test-suite (101 filter sample-regex tests pass).
2026-08-18 14:51:33 +02:00
Jari Huttunen
763a1c7f0c
Fix cowrie honeypot filter per review (PR #4216 )
...
Replace the custom Python Filter/backend hack with a plain regex
filter, per sebres's review: fail2ban filters shouldn't ship a
custom backend-style parser under config/filter.d, and the previous
prefregex/failregex pair was a no-op catch-all that didn't actually
filter anything.
- Drop cowrie_json.py entirely; parse the JSON log line directly
with a bounded, anchored failregex (no unbounded .* catch-alls)
using <ADDR> instead of <HOST> since only an IP is expected.
- Add the required sample log test file
(fail2ban/tests/files/logs/cowrie_json) covering matched,
non-matching event, and malformed lines.
2026-08-18 14:51:33 +02:00
Jari Huttunen
ae4be51e16
typo fix
2026-08-18 14:51:32 +02:00
Jari Huttunen
4120682a95
Added cowrie honeypot json log filter
2026-08-18 14:51:32 +02:00
Sergey G. Brester
847abb4b2b
Merge pull request #4217 from VXNCXNX/fix/apache-noscript-cgi-bin-dir
...
filter.d/apache-noscript: match a cgi-bin directory with no script name
2026-08-18 14:39:22 +02:00
VXNCXNX
17196db9c9
ChangeLog: entry for the apache-noscript cgi-bin fix
2026-08-18 14:35:33 +02:00
VXNCXNX
a511f9e3eb
filter.d/apache-noscript: no trailing slash for cgi-bin pattern + word boundary after <script> in 2nd failregex
2026-08-18 14:34:20 +02:00
VXNCXNX
382b904e09
filter.d/apache-noscript: match a cgi-bin directory with no script name
...
AH02811 lines can name the CGI directory itself rather than a script
inside it:
stderr from /srv/http/cgi-bin: script not found or unable to stat
The script pattern required 'cgi-bin/', so a path ending in 'cgi-bin:'
never matched. Use a word boundary instead.
Closes gh-4040
2026-08-18 14:33:09 +02:00
Sergey G. Brester
7bfc871bb3
Merge pull request #4223 from VXNCXNX/fix/nginx-botsearch-journal
...
filter.d/nginx-botsearch: support the journal log format
2026-08-18 10:53:06 +02:00
VXNCXNX
203202cdb4
filter.d/nginx-botsearch: support the journal log format
...
The error-log regex hardcoded the file-format prefix, so lines carrying a
systemd journal prefix were missed. Use __prefix_line from
nginx-error-common.conf, as the other nginx error-log filters already do.
Closes gh-3732
2026-08-16 08:40:42 +00:00
Sergey G. Brester
83a66db41d
Readme: version bump - v1.1.2.dev1
2026-08-15 21:58:59 +02:00
sebres
3a7a6ac415
version bump (back to .dev)
2026-08-15 17:48:38 +02:00
sebres
f60978618a
release 1.1.1 -- triple-one-win
2026-08-15 14:25:41 +02:00
Sergey G. Brester
f0fe7a57ff
CI: update actions/checkout from v3 to v7
...
silence deprecation warning (Node.js 20)
2026-08-15 13:33:10 +02:00
Sergey G. Brester
6c7a52e65f
Merge pull request #4221 from sebres/GHSA-33wh-ccjc-p397
...
fixes GHSA-33wh-ccjc-p397: avoid catastrophic backtracking explosion for REs in domino-smtp and dovecot filter
2026-08-15 13:29:06 +02:00
Sergey G. Brester
a2694a1ec1
update ChangeLog with recent fixes
...
Fix catastrophic backtracking in REs for domino-smtp and dovecot filters.
2026-08-15 13:25:05 +02:00
Sergey G. Brester
153751d40c
CI: upgrade Python setup action to version 7
...
try to silence deprecation warning (Node.js 20)
2026-08-15 13:18:30 +02:00
Sergey G. Brester
5684996a94
CI: update checkout action version to v7
...
try to silence deprecation warning (Node.js 20)
2026-08-15 13:14:33 +02:00
Sergey G. Brester
fbfeecd0b1
CI: update Python version to 3.15.0-rc.1 in workflow
2026-08-15 13:10:02 +02:00
Sergey G. Brester
d5d0f23d48
Merge pull request #4220 from h7x4/systemd-socket-activation
...
Add support for systemd socket activation
2026-08-15 12:50:05 +02:00
Sergey G. Brester
7f6280dab6
Merge pull request #4218 from VXNCXNX/fix/postfix-resolve-aggressive
...
filter.d/postfix: catch "hostname ... does not resolve to address" in aggressive mode
2026-08-15 12:35:34 +02:00
Sergey G. Brester
6afc074591
Update ChangeLog with new aggressive mode matching
...
Extended modes 'aggressive' to match hostname resolution errors.
2026-08-15 12:33:16 +02:00
h7x4
ef15ac46a8
Add fail2ban.socket unit
2026-08-15 19:07:44 +09:00
h7x4
d5d81242cf
Add support for systemd socket activation
2026-08-15 19:06:17 +09:00
VXNCXNX
d97eac50b9
filter.d/postfix: move the new sample into the existing aggressive section
...
review feedback from sebres, the file already has a filterOptions aggressive section, so the sample belongs there rather than in a second one at the end.
2026-08-15 06:37:47 +00:00
sebres
3a133f8aa4
filter.d/dovecot.conf: amend to GHSA-33wh-ccjc-p397 - improve vulnerable RE part to avoid catastrophic backtracking;
...
added more (artificial) tests covering that (shall no hang)
2026-08-14 23:38:49 +02:00
VXNCXNX
2b46485c7a
filter.d/postfix: catch "hostname ... does not resolve to address" in aggressive mode
...
Postfix logs this warning when a client's reverse DNS does not resolve
back to its address. Bots trip it constantly, but so does a legitimate
sender with broken rDNS, so it only belongs in aggressive mode.
Regex as given by sebres in gh-4078 and confirmed working by the
reporter.
Closes gh-4078
2026-08-14 16:02:39 +00:00
sebres
189da87824
filter.d/domino-smtp.conf: fixes GHSA-33wh-ccjc-p397 - improve vulnerable RE so it'd not cause hangs
2026-08-14 12:20:27 +02:00
sebres
27552eb190
domino-smtp: added test cases illustrating GHSA-33wh-ccjc-p397 - hang injecting user name
2026-08-14 12:19:42 +02:00
sebres
f127e6e6f0
action.d\nftables.conf: allows protocol all for multi- and allports type;
...
see https://github.com/fail2ban/fail2ban/discussions/4211#discussioncomment-17863040
2026-08-01 15:51:26 +02:00