⚝
One Hat Cyber Team
⚝
Your IP:
216.73.217.4
Server IP:
41.128.143.86
Server:
Linux host.raqmix.cloud 6.8.0-1025-azure #30~22.04.1-Ubuntu SMP Wed Mar 12 15:28:20 UTC 2025 x86_64
Server Software:
Apache
PHP Version:
8.3.23
Buat File
|
Buat Folder
Eksekusi
Dir :
~
/
usr
/
share
/
doc
/
fail2ban
/
dist-config
/
filter.d
/
View File Name :
sshd.conf
# Fail2Ban filter for openssh # # If you want to protect OpenSSH from being bruteforced by password # authentication then get public key authentication working before disabling # PasswordAuthentication in sshd_config. # # # "Connection from
port \d+" requires LogLevel VERBOSE in sshd_config # [INCLUDES] # Read common prefixes. If any customizations available -- read them from # common.local before = common.conf [DEFAULT] _daemon = sshd # optional prefix (logged from several ssh versions) like "error: ", "error: PAM: " or "fatal: " __pref = (?:(?:error|fatal): (?:PAM: )?)? # optional suffix (logged from several ssh versions) like " [preauth]" #__suff = (?: port \d+)?(?: \[preauth\])?\s* __suff = (?: (?:port \d+|on \S+|\[preauth\])){0,3}\s* __on_port_opt = (?: (?:port \d+|on \S+)){0,2} # close by authenticating user (don't use
after %(__authng_user)s because of catch-all `.*?`): __authng_user = (?: (?:by|from))?(?: (?:invalid|authenticating) user
\S+|.*?
)?(?: from)? # for all possible (also future) forms of "no matching (cipher|mac|MAC|compression method|key exchange method|host key type) found", # see ssherr.c for all possible SSH_ERR_..._ALG_MATCH errors. __alg_match = (?:(?:\w+ (?!found\b)){0,2}\w+) # PAM authentication mechanism, can be overridden, e. g. `filter = sshd[__pam_auth='pam_ldap']`: __pam_auth = pam_[a-z]+ [Definition] prefregex = ^
%(__prefix_line)s
%(__pref)s
.+
$ cmnfailre = ^[aA]uthentication (?:failure|error|failed) for
.*?
(?:from )?
( via \S+)?%(__suff)s$ ^User not known to the underlying authentication module for
.*?
(?:from )?
%(__suff)s$
> ^Failed
for (?P
invalid user )?
(?P
\S+)|(?(cond_inv)(?:(?! from ).)*?|[^:]+)
from
%(__on_port_opt)s(?: ssh\d*)?(?(cond_user): |(?:(?:(?! from ).)*)$) ^
ROOT
LOGIN REFUSED FROM
^[iI](?:llegal|nvalid) user
.*?
(?:from )?
%(__suff)s$ ^User
\S+|.*?
(?:from )?
not allowed because not listed in AllowUsers%(__suff)s$ ^User
\S+|.*?
(?:from )?
not allowed because listed in DenyUsers%(__suff)s$ ^User
\S+|.*?
(?:from )?
not allowed because not in any group%(__suff)s$ ^refused connect from \S+ \(
\) ^Received
disconnect
from
%(__on_port_opt)s:\s*3: .*: Auth fail%(__suff)s$ ^User
\S+|.*?
(?:from )?
not allowed because a group is listed in DenyGroups%(__suff)s$ ^User
\S+|.*?
(?:from )?
not allowed because none of user's groups are listed in AllowGroups%(__suff)s$ ^
%(__pam_auth)s\(sshd:auth\):\s+authentication failure;
(?:\s+(?:(?:logname|e?uid|tty)=\S*)){0,4}\s+ruser=
\S*
\s+rhost=
(?:\s+user=
\S*
)?%(__suff)s$ ^maximum authentication attempts exceeded for (?:invalid user )?
.*?
(?:from )?
%(__on_port_opt)s(?: ssh\d*)?%(__suff)s$ ^User
\S+|.*?
not allowed because account is locked%(__suff)s ^
Disconnecting
(?: from)?(?: (?:invalid|authenticating)) user
\S+
%(__on_port_opt)s:\s*Change of username or service not allowed:\s*.*\[preauth\]\s*$ ^Disconnecting: Too many authentication failures(?: for
\S+|.*?
)?%(__suff)s$ ^
Received
disconnect
from
%(__on_port_opt)s:\s*11:
-other> ^
Accepted \w+
for
\S+
from
(?:\s|$) cmnfailed-any = \S+ cmnfailed-ignore = \b(?!publickey)\S+ cmnfailed-invalid =
cmnfailed-nofail = (?:
publickey
|\S+) cmnfailed =
> mdre-normal = # used to differentiate "connection closed" with and without `[preauth]` (fail/nofail cases in ddos mode) mdre-normal-other = ^
(?:Connection (?:closed|reset)|Disconnect(?:ed|ing))
%(__authng_user)s
%(__on_port_opt)s(?:: (?!Too many authentication failures)[^\[]+)?(?: \[preauth\])?\s*$ mdre-ddos = ^(?:Did not receive identification string from|Timeout before authentication for)
^kex_exchange_identification: (?:read: )?(?:[Cc]lient sent invalid protocol identifier|[Cc]onnection (?:closed by remote host|reset by peer)) ^Bad protocol version identification '(?:[^']|.*?)' (?:from )?
%(__suff)s$ ^
SSH: Server;Ltype:
(?:Authname|Version|Kex);Remote:
-\d+;[A-Z]\w+: ^Read from socket failed: Connection
reset
by peer ^(?:banner exchange|ssh_dispatch_run_fatal): Connection from
<__on_port_opt>: (?:invalid format|(?:message authentication code incorrect|[Cc]onnection corrupted) \[preauth\]) # same as mdre-normal-other, but as failure (without
with [preauth] and with
on no preauth phase as helper to identify address): mdre-ddos-other = ^
(?:Connection (?:closed|reset)|Disconnect(?:ed|ing))
%(__authng_user)s
%(__on_port_opt)s(?:: (?!Too many authentication failures)[^\[]+)?\s+\[preauth\]\s*$ ^
(?:Connection (?:closed|reset)|Disconnect(?:ed|ing))
%(__authng_user)s
(?:%(__on_port_opt)s(?:: (?!Too many authentication failures)[^\[]+)?|\s*)$ mdre-extra = ^Received
disconnect
from
%(__on_port_opt)s:\s*14: No(?: supported)? authentication methods available ^Unable to negotiate with
%(__on_port_opt)s: no matching <__alg_match> found. ^Unable to negotiate a <__alg_match> ^no matching <__alg_match> found: # part of mdre-ddos-other, but user name is supplied (invalid/authenticating) on [preauth] phase only: mdre-extra-other = ^
Disconnected
(?: from)?(?: (?:invalid|authenticating)) user
\S+|.*?
(?:from )?
%(__on_port_opt)s \[preauth\]\s*$ mdre-aggressive = %(mdre-ddos)s %(mdre-extra)s # mdre-extra-other is fully included within mdre-ddos-other: mdre-aggressive-other = %(mdre-ddos-other)s # Parameter "publickey": nofail (default), invalid, any, ignore publickey = nofail # consider failed publickey for invalid users only: cmnfailre-failed-pub-invalid = ^Failed publickey for invalid user
(?P
\S+)|(?:(?! from ).)*?
from
%(__on_port_opt)s(?: ssh\d*)?(?(cond_user): |(?:(?:(?! from ).)*)$) # consider failed publickey for valid users too (don't need RE, see cmnfailed): cmnfailre-failed-pub-any = # same as invalid, but consider failed publickey for valid users too, just as no failure (helper to get IP and user-name only, see cmnfailed): cmnfailre-failed-pub-nofail =
# don't consider failed publickey as failures (don't need RE, see cmnfailed): cmnfailre-failed-pub-ignore = cfooterre = ^
Connection from
failregex = %(cmnfailre)s
> %(cfooterre)s # Parameter "mode": normal (default), ddos, extra or aggressive (combines all) # Usage example (for jail.local): # [sshd] # mode = extra # # or another jail (rewrite filter parameters of jail): # [sshd-aggressive] # filter = sshd[mode=aggressive] # mode = normal #filter = sshd[mode=aggressive] ignoreregex = maxlines = 1 journalmatch = _SYSTEMD_UNIT=sshd.service + _COMM=sshd # DEV Notes: # # "Failed \S+ for .*? from
..." failregex uses non-greedy catch-all because # it is coming before use of
which is not hard-anchored at the end as well, # and later catch-all's could contain user-provided input, which need to be greedily # matched away first. # # Author: Cyril Jaquier, Yaroslav Halchenko, Petr Voralek, Daniel Black and Sergey Brester aka sebres # Rewritten using prefregex (and introduced "mode" parameter) by Serg G. Brester.