108,7 → 108,8 |
backend = auto |
filter = alcasar_mod-evasive |
action = iptables-allports[name=alcasar_mod-evasive] |
logpath = /var/log/lighttpd/access.log |
logpath = /var/log/httpd/error_log |
/var/log/httpd/ssl_error_log |
maxretry = 2 |
|
# Bannissement sur tout les ports après 3 refus de SSH (tentative d'accès par brute-force) |
129,8 → 130,8 |
backend = auto |
filter = alcasar_acc |
action = iptables-allports[name=alcasar_acc] |
logpath = /var/log/lighttpd/access.log |
maxretry = 6 |
logpath = /var/log/httpd/ssl_error_log |
maxretry = 5 |
|
# Bannissement sur tout les ports après 5 echecs de connexion pour un usager |
[alcasar_intercept] |
140,7 → 141,7 |
backend = auto |
filter = alcasar_intercept |
action = iptables-allports[name=alcasar_intercept] |
logpath = /var/log/lighttpd/access.log |
logpath = /var/log/httpd/ssl_request_log |
maxretry = 5 |
|
# Bannissement sur tout les port après 5 échecs de changement de mot de passe |
152,7 → 153,7 |
backend = auto |
filter = alcasar_change-pwd |
action = iptables-allports[name=alcasar_change-pwd] |
logpath = /var/log/lighttpd/access.log |
logpath = /var/log/httpd/ssl_request_log |
maxretry = 5 |
|
EOF |
183,7 → 184,7 |
# (?:::f{4,6}:)?(?P<host>[\w\-.^_]+) |
# Values: TEXT |
# |
failregex = <HOST> .+\] "[^"]+" 403 |
failregex = \[client <HOST>:[0-9]+\] .*client denied by server configuration |
|
# Option: ignoreregex |
# Notes.: regex to ignore. If this regex matches, the line is ignored. |
210,7 → 211,7 |
# (?:::f{4,6}:)?(?P<host>[\w\-.^_]+) |
# Values: TEXT |
# |
failregex = <HOST> .+\] "[^"]+" 401 |
failregex = \[auth_digest:error\] \[client <HOST>:[0-9]+\] .*ALCASAR Control Center \(ACC\) |
|
#[[]auth_digest:error[]] [[]client <HOST>:[0-9]\{1,5\}[]] |
|
239,7 → 240,7 |
# (?:::f{4,6}:)?(?P<host>[\w\-.^_]+) |
# Values: TEXT |
# |
failregex = <HOST> .* \"GET \/intercept\.php\?res=failed\&reason=reject |
failregex = \[<HOST>\] \"GET \/intercept\.php\?res=failed\&reason=reject |
|
# Option: ignoreregex |
# Notes.: regex to ignore. If this regex matches, the line is ignored. |
267,7 → 268,7 |
# (?:::f{4,6}:)?(?P<host>[\w\-.^_]+) |
# Values: TEXT |
# |
failregex = <HOST> .* \"POST \/password\.php |
failregex = \[<HOST>\] \"POST \/password\.php |
|
|
# Option: ignoreregex |