Commit graph

6286 commits

Author SHA1 Message Date
sebres
7212404e8f amend to 5cbe4b8b01 (systemd RC-fix): lock by closing of journal too (in afterStop, since _closeJournal used in _reopenJournal in lock, and lock is not reentrant)
Some checks failed
Codespell / Check for spelling errors (push) Has been cancelled
CI / build (3.10) (push) Has been cancelled
CI / build (3.11) (push) Has been cancelled
CI / build (3.12) (push) Has been cancelled
CI / build (3.13) (push) Has been cancelled
CI / build (3.14) (push) Has been cancelled
CI / build (3.15.0-rc.2) (push) Has been cancelled
CI / build (3.8) (push) Has been cancelled
CI / build (3.9) (push) Has been cancelled
CI / build (pypy3.11) (push) Has been cancelled
2026-09-11 22:05:03 +02:00
sebres
f51ad5a5fb CI: update Python version to 3.15.0-rc.2 in workflow 2026-09-11 21:44:15 +02:00
sebres
5cbe4b8b01 prevent possible race condition accessing journal from 2 threads in parallel (sporadic "OSError: [Errno 22] Invalid argument" in test_delJournalMatch by addJournalMatch), protect journal handle with lock 2026-09-11 21:26:11 +02:00
sebres
12e94859b8 remove redundant set exclusion (glob for ../system.journal can never contain ../system*@*.journal) 2026-09-11 20:49:22 +02:00
Sergey G. Brester
86e415a76a
Merge pull request #4230 from ChrisJr404/gitlab-json-mode
Some checks failed
Codespell / Check for spelling errors (push) Has been cancelled
CI / build (3.10) (push) Has been cancelled
CI / build (3.11) (push) Has been cancelled
CI / build (3.12) (push) Has been cancelled
CI / build (3.13) (push) Has been cancelled
CI / build (3.14) (push) Has been cancelled
CI / build (3.15.0-rc.1) (push) Has been cancelled
CI / build (3.8) (push) Has been cancelled
CI / build (3.9) (push) Has been cancelled
CI / build (pypy3.11) (push) Has been cancelled
gitlab: add json mode for application_json.log
2026-08-26 16:06:17 +02:00
Sergey G. Brester
0e2ad0360d
update changelog (mode -> logtype, added PR number) 2026-08-26 16:05:01 +02:00
Chris (ChrisJr404)
7924c55682
gitlab: switch mode parameter to standard logtype (file/json) 2026-08-25 23:47:36 -04:00
Chris (ChrisJr404)
050e0b3460
gitlab: add json mode for application_json.log
Gitlab deprecated application.log in 15.10 in favour of the structured
application_json.log. Add a mode option so the filter can read either
format; text stays the default so existing setups keep working.

Closes #3566
2026-08-24 18:00:21 -04:00
sebres
deffcbcd17 add default banactions for several paths-*.conf depending on default net-filter for distribution;
closes gh-4224, gh-4229
2026-08-22 13:32:00 +02:00
sebres
46d2acd451 ChangeLog 2026-08-22 13:30:47 +02:00
sebres
63c0a46826 add default banactions for several paths-*.conf depending on default net-filter for distribution;
closes gh-4224, gh-4229
2026-08-22 13:26:02 +02:00
Arjen de Korte
c6b20f225c
paths-opensuse.conf: specify default banactions
Since 1.1.1 default banactions need to be specified. Take the opportunity to also synchronize the paths with current Factory settings.
2026-08-21 17:53:28 +02:00
Sergey G. Brester
403df4a91c
Merge pull request #4225 from Deric-W/socket-shutdown
Fix systemd socket activation being broken
2026-08-20 13:46:36 +02:00
Sergey G. Brester
6185bc3ea2
Update ChangeLog entry (added reference to PR) 2026-08-20 13:45:02 +02:00
Eric Wolf
cbdeee8d81
Fix systemd runtime directory containing persistent socket being removed
This resulted in a fail2ban being passed an unreachable socket after being stopped.
2026-08-20 04:03:15 +02:00
Eric Wolf
d574daf22e
Fix sockets passed via socket activation being shut down
Doing so results in systemd encountering errors after stopping fail2ban.
2026-08-20 02:33:06 +02:00
Sergey G. Brester
1e12c5a7c7
Merge pull request #4216 from jarihu/add-cowrie-filter
Add Cowrie honeypot JSON log filter
2026-08-18 15:28:22 +02:00
sebres
5ecbe89c80 try to optimize RE (skipping tags, no full match and right anchor needed), added datepattern, etc 2026-08-18 15:25:19 +02:00
Jari Huttunen
b552116f4f Renamed filter to cowrie 2026-08-18 14:55:18 +02:00
Jari Huttunen
dfb8a58d17 Fixed the CI failure by adding a stock [cowrie] jail entry to config/jail.conf. 2026-08-18 14:54:35 +02:00
Jari Huttunen
9584c78bb6 Fix cowrie_json filter against real Cowrie log output
The previous regex was written against an assumed field order/spacing
that doesn't match what Cowrie actually emits: no space after ":",
and "eventid" is not the first key (order is session, protocol,
src_ip, ..., eventid, ..., message). Rework the failregex to match
real-world json output, and correct the datepattern to wrap only the
timestamp value (not the "timestamp": key) in the capture group, since
fail2ban excises the whole captured group from the line before
failregex is applied - wrapping the key too left a broken ",," gap in
the JSON that never matched.

Verified against real Cowrie honeypot log samples (session.connect,
client.version, client.kex, login.success, log.closed) and the
existing test-suite (101 filter sample-regex tests pass).
2026-08-18 14:51:33 +02:00
Jari Huttunen
763a1c7f0c Fix cowrie honeypot filter per review (PR #4216)
Replace the custom Python Filter/backend hack with a plain regex
filter, per sebres's review: fail2ban filters shouldn't ship a
custom backend-style parser under config/filter.d, and the previous
prefregex/failregex pair was a no-op catch-all that didn't actually
filter anything.

- Drop cowrie_json.py entirely; parse the JSON log line directly
  with a bounded, anchored failregex (no unbounded .* catch-alls)
  using <ADDR> instead of <HOST> since only an IP is expected.
- Add the required sample log test file
  (fail2ban/tests/files/logs/cowrie_json) covering matched,
  non-matching event, and malformed lines.
2026-08-18 14:51:33 +02:00
Jari Huttunen
ae4be51e16 typo fix 2026-08-18 14:51:32 +02:00
Jari Huttunen
4120682a95 Added cowrie honeypot json log filter 2026-08-18 14:51:32 +02:00
Sergey G. Brester
847abb4b2b
Merge pull request #4217 from VXNCXNX/fix/apache-noscript-cgi-bin-dir
filter.d/apache-noscript: match a cgi-bin directory with no script name
2026-08-18 14:39:22 +02:00
VXNCXNX
17196db9c9 ChangeLog: entry for the apache-noscript cgi-bin fix 2026-08-18 14:35:33 +02:00
VXNCXNX
a511f9e3eb filter.d/apache-noscript: no trailing slash for cgi-bin pattern + word boundary after <script> in 2nd failregex 2026-08-18 14:34:20 +02:00
VXNCXNX
382b904e09 filter.d/apache-noscript: match a cgi-bin directory with no script name
AH02811 lines can name the CGI directory itself rather than a script
inside it:

  stderr from /srv/http/cgi-bin: script not found or unable to stat

The script pattern required 'cgi-bin/', so a path ending in 'cgi-bin:'
never matched. Use a word boundary instead.

Closes gh-4040
2026-08-18 14:33:09 +02:00
Sergey G. Brester
7bfc871bb3
Merge pull request #4223 from VXNCXNX/fix/nginx-botsearch-journal
filter.d/nginx-botsearch: support the journal log format
2026-08-18 10:53:06 +02:00
VXNCXNX
203202cdb4 filter.d/nginx-botsearch: support the journal log format
The error-log regex hardcoded the file-format prefix, so lines carrying a
systemd journal prefix were missed. Use __prefix_line from
nginx-error-common.conf, as the other nginx error-log filters already do.

Closes gh-3732
2026-08-16 08:40:42 +00:00
Sergey G. Brester
83a66db41d
Readme: version bump - v1.1.2.dev1 2026-08-15 21:58:59 +02:00
sebres
3a7a6ac415 version bump (back to .dev) 2026-08-15 17:48:38 +02:00
sebres
f60978618a release 1.1.1 -- triple-one-win 2026-08-15 14:25:41 +02:00
Sergey G. Brester
f0fe7a57ff
CI: update actions/checkout from v3 to v7
silence deprecation warning (Node.js 20)
2026-08-15 13:33:10 +02:00
Sergey G. Brester
6c7a52e65f
Merge pull request #4221 from sebres/GHSA-33wh-ccjc-p397
fixes GHSA-33wh-ccjc-p397: avoid catastrophic backtracking explosion for REs in domino-smtp and dovecot filter
2026-08-15 13:29:06 +02:00
Sergey G. Brester
a2694a1ec1
update ChangeLog with recent fixes
Fix catastrophic backtracking in REs for domino-smtp and dovecot filters.
2026-08-15 13:25:05 +02:00
Sergey G. Brester
153751d40c
CI: upgrade Python setup action to version 7
try to silence deprecation warning (Node.js 20)
2026-08-15 13:18:30 +02:00
Sergey G. Brester
5684996a94
CI: update checkout action version to v7
try to silence deprecation warning (Node.js 20)
2026-08-15 13:14:33 +02:00
Sergey G. Brester
fbfeecd0b1
CI: update Python version to 3.15.0-rc.1 in workflow 2026-08-15 13:10:02 +02:00
Sergey G. Brester
d5d0f23d48
Merge pull request #4220 from h7x4/systemd-socket-activation
Add support for systemd socket activation
2026-08-15 12:50:05 +02:00
Sergey G. Brester
7f6280dab6
Merge pull request #4218 from VXNCXNX/fix/postfix-resolve-aggressive
filter.d/postfix: catch "hostname ... does not resolve to address" in aggressive mode
2026-08-15 12:35:34 +02:00
Sergey G. Brester
6afc074591
Update ChangeLog with new aggressive mode matching
Extended modes 'aggressive' to match hostname resolution errors.
2026-08-15 12:33:16 +02:00
h7x4
ef15ac46a8
Add fail2ban.socket unit 2026-08-15 19:07:44 +09:00
h7x4
d5d81242cf
Add support for systemd socket activation 2026-08-15 19:06:17 +09:00
VXNCXNX
d97eac50b9 filter.d/postfix: move the new sample into the existing aggressive section
review feedback from sebres, the file already has a filterOptions aggressive section, so the sample belongs there rather than in a second one at the end.
2026-08-15 06:37:47 +00:00
sebres
3a133f8aa4 filter.d/dovecot.conf: amend to GHSA-33wh-ccjc-p397 - improve vulnerable RE part to avoid catastrophic backtracking;
added more (artificial) tests covering that (shall no hang)
2026-08-14 23:38:49 +02:00
VXNCXNX
2b46485c7a filter.d/postfix: catch "hostname ... does not resolve to address" in aggressive mode
Postfix logs this warning when a client's reverse DNS does not resolve
back to its address. Bots trip it constantly, but so does a legitimate
sender with broken rDNS, so it only belongs in aggressive mode.

Regex as given by sebres in gh-4078 and confirmed working by the
reporter.

Closes gh-4078
2026-08-14 16:02:39 +00:00
sebres
189da87824 filter.d/domino-smtp.conf: fixes GHSA-33wh-ccjc-p397 - improve vulnerable RE so it'd not cause hangs 2026-08-14 12:20:27 +02:00
sebres
27552eb190 domino-smtp: added test cases illustrating GHSA-33wh-ccjc-p397 - hang injecting user name 2026-08-14 12:19:42 +02:00
sebres
f127e6e6f0 action.d\nftables.conf: allows protocol all for multi- and allports type;
see https://github.com/fail2ban/fail2ban/discussions/4211#discussioncomment-17863040
2026-08-01 15:51:26 +02:00