Permalink
Switch branches/tags
upstream/0.8.4 upstream/0.8.3 upstream/0.8.2 upstream/0.8.1 upstream/0.8.0 upstream/0.7.9 upstream/0.7.8 upstream/0.7.7 upstream/0.7.6 upstream/0.7.5 upstream/0.7.4 upstream/0.6.1 upstream/0.6.0 upstream/0.5.4 upstream/0.5.3 upstream/0.5.2 sdist/0.8.5 sdist/0.8.4 sdist/0.8.4+svn20110323 sdist/0.8.3 sdist/0.8.2 sdist/0.8.1 sdist/0.8.0 sdist/0.7.9 sdist/0.7.8 sdist/0.7.7 sdist/0.7.6 sdist/0.7.5 sdist/0.7.4 sdist/0.6.1 sdist/0.6.0 sdist/0.5.4 sdist/0.5.3 sdist/0.5.2 fail2ban_0.9.X debian/0.10.2-2 debian/0.10.2-1 debian/0.9.7-2 debian/0.9.7-1 debian/0.9.6-2 debian/0.9.6-1 debian/0.9.5-1 debian/0.9.4-1 debian/0.9.3-1 debian/0.9.2-1 debian/0.9.1+git44-gd65c4f8-1 debian/0.9.1-1 debian/0.9.0+git252-g47441d1-1 debian/0.9.0+git48-gabcab00-1 debian/0.9.0+git37-gdeb5924-1 debian/0.9.X-python3 debian/0.8.13-1 debian/0.8.11_pre1+git29-gccd2657-1 debian/0.8.11-1 debian/0.8.10-3 debian/0.8.10-1 debian/0.8.9-1 debian/0.8.8-1 debian/0.8.8-1+lucid0 debian/0.8.7-1 debian/0.8.6_+git69-gb4099da-1 debian/0.8.6-3 debian/0.8.6-3wheezy3 debian/0.8.6-3wheezy2 debian/0.8.6-3wheezy1 debian/0.8.6-2 debian/0.8.6-1 debian/0.8.5-2 debian/0.8.5-1 debian/0.8.4+svn20110323-1 debian/0.8.4-3 debian/0.8.4-3+squeeze3 debian/0.8.4-3+squeeze2 debian/0.8.4-3+squeeze1 debian/0.8.4-2 debian/0.8.4-1 debian/0.8.3-6 debian/0.8.3-5 debian/0.8.3-4 debian/0.8.3-3 debian/0.8.3-2 debian/0.8.3-2sid1 debian/0.8.3-1 debian/0.8.2-3 debian/0.8.2-2 debian/0.8.2-1 debian/0.8.1-5 debian/0.8.1-4 debian/0.8.1-3 debian/0.8.1-2 debian/0.8.1-1 debian/0.8.0-2 debian/0.8.0-1 debian/0.7.9-1 debian/0.7.8-1 debian/0.7.7-1 debian/0.7.6-3 debian/0.7.6-1 debian/0.7.5-3+pre6 debian/0.7.5-2
Nothing to show
Find file Copy path
Fetching contributors…
Cannot retrieve contributors at this time
57 lines (49 sloc) 3.17 KB
# Fail2Ban apache-auth filter
#
[INCLUDES]
# Read common prefixes. If any customizations available -- read them from
# apache-common.local
before = apache-common.conf
[Definition]
failregex = ^%(_apache_error_client)s (AH(01797|01630): )?client denied by server configuration: (uri )?\S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01617: )?user .*? authentication failure for "\S*": Password Mismatch(, referer: \S+)?$
^%(_apache_error_client)s (AH01618: )?user .*? not found(: )?\S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01614: )?client used wrong authentication scheme: \S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH\d+: )?Authorization of user \S+ to access \S* failed, reason: .*$
^%(_apache_error_client)s (AH0179[24]: )?(Digest: )?user .*?: password mismatch: \S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH0179[01]: |Digest: )user `.*?' in realm `.+' (not found|denied by provider): \S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01631: )?user .*?: authorization failure for "\S*":(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01775: )?(Digest: )?invalid nonce .* received - length is not \S+(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01788: )?(Digest: )?realm mismatch - got `.*?' but expected `.+'(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01789: )?(Digest: )?unknown algorithm `.*?' received: \S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01793: )?invalid qop `.*?' received: \S*(, referer: \S+)?\s*$
^%(_apache_error_client)s (AH01777: )?(Digest: )?invalid nonce .*? received - user attempted time travel(, referer: \S+)?\s*$
ignoreregex =
# DEV Notes:
#
# This filter matches the authorization failures of Apache. It takes the log messages
# from the modules in aaa that return HTTP_UNAUTHORIZED, HTTP_METHOD_NOT_ALLOWED or
# HTTP_FORBIDDEN and not AUTH_GENERAL_ERROR or HTTP_INTERNAL_SERVER_ERROR.
#
# An unauthorized response 401 is the first step for a browser to instigate authentication
# however apache doesn't log this as an error. Only subsequent errors are logged in the
# error log.
#
# Source:
#
# By searching the code in http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/aaa/*
# for ap_log_rerror(APLOG_MARK, APLOG_ERR and examining resulting return code should get
# all of these expressions. Lots of submodules like mod_authz_* return back to mod_authz_core
# to return the actual failure.
#
# See also: http://wiki.apache.org/httpd/ListOfErrors
# Expressions that don't have tests and aren't common.
# more be added with https://issues.apache.org/bugzilla/show_bug.cgi?id=55284
# ^%(_apache_error_client)s (AH01778: )?user .*: nonce expired \([\d.]+ seconds old - max lifetime [\d.]+\) - sending new nonce\s*$
# ^%(_apache_error_client)s (AH01779: )?user .*: one-time-nonce mismatch - sending new nonce\s*$
# ^%(_apache_error_client)s (AH02486: )?realm mismatch - got `.*' but no realm specified\s*$
#
# referer is always in error log messages if it exists added as per the log_error_core function in server/log.c
#
# Author: Cyril Jaquier
# Major edits by Daniel Black