Advertisement
Guest User

Untitled

a guest
Feb 6th, 2014
379
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.58 KB | None | 0 0
  1. [ssh]
  2.  
  3. enabled = true
  4. port = ssh
  5. filter = sshd
  6. logpath = /var/log/auth.log
  7. maxretry = 3
  8.  
  9. [dropbear]
  10.  
  11. enabled = false
  12. port = ssh
  13. filter = sshd
  14. logpath = /var/log/dropbear
  15. maxretry = 6
  16.  
  17. # Generic filter for pam. Has to be used with action which bans all ports
  18. # such as iptables-allports, shorewall
  19. [pam-generic]
  20.  
  21. enabled = false
  22. # pam-generic filter can be customized to monitor specific subset of 'tty's
  23. filter = pam-generic
  24. # port actually must be irrelevant but lets leave it all for some possible uses
  25. port = all
  26. banaction = iptables-allports
  27. port = anyport
  28. logpath = /var/log/auth.log
  29. maxretry = 6
  30.  
  31.  
  32. [xinetd-fail]
  33.  
  34. enabled = false
  35. filter = xinetd-fail
  36. port = all
  37. banaction = iptables-multiport-log
  38. logpath = /var/log/daemon.log
  39. maxretry = 2
  40.  
  41.  
  42. [ssh-ddos]
  43.  
  44. enabled = false
  45. port = ssh
  46. filter = sshd-ddos
  47. logpath = /var/log/auth.log
  48. maxretry = 6
  49.  
  50.  
  51. [apache]
  52.  
  53. enabled = true
  54. port = http,https
  55. filter = apache-auth
  56. logpath = /var/log/apache*/*error.log
  57. maxretry = 3
  58.  
  59. # default action is now multiport, so apache-multiport jail was left
  60. # for compatibility with previous (<0.7.6-2) releases
  61. [apache-multiport]
  62.  
  63. enabled = true
  64. port = http,https
  65. filter = apache-auth
  66. logpath = /var/log/apache*/*error.log
  67. maxretry = 3
  68.  
  69.  
  70. [apache]
  71.  
  72. enabled = true
  73. port = http,https
  74. filter = apache-auth
  75. logpath = /var/log/apache*/*error.log
  76. maxretry = 3
  77.  
  78. # default action is now multiport, so apache-multiport jail was left
  79. # for compatibility with previous (<0.7.6-2) releases
  80. [apache-multiport]
  81.  
  82. enabled = true
  83. port = http,https
  84. filter = apache-auth
  85. logpath = /var/log/apache*/*error.log
  86. maxretry = 3
  87.  
  88.  
  89. [apache-noscript]
  90.  
  91. enabled = true
  92. port = http,https
  93. filter = apache-noscript
  94. logpath = /var/log/apache*/*error.log
  95. maxretry = 3
  96.  
  97. [apache-overflows]
  98.  
  99. enabled = true
  100. port = http,https
  101. filter = apache-overflows
  102. logpath = /var/log/apache*/*error.log
  103. maxretry = 2
  104.  
  105.  
  106. [vsftpd]
  107.  
  108. enabled = false
  109. port = ftp,ftp-data,ftps,ftps-data
  110. filter = vsftpd
  111. logpath = /var/log/vsftpd.log
  112. # or overwrite it in jails.local to be
  113. # logpath = /var/log/auth.log
  114. # if you want to rely on PAM failed login attempts
  115. # vsftpd's failregex should match both of those formats
  116. maxretry = 6
  117.  
  118.  
  119. [proftpd]
  120.  
  121. enabled = false
  122. port = ftp,ftp-data,ftps,ftps-data
  123. filter = proftpd
  124. logpath = /var/log/proftpd/proftpd.log
  125. maxretry = 6
  126.  
  127.  
  128. [pure-ftpd]
  129.  
  130. enabled = false
  131. port = ftp,ftp-data,ftps,ftps-data
  132. filter = pure-ftpd
  133. logpath = /var/log/auth.log
  134. maxretry = 6
  135.  
  136.  
  137. [wuftpd]
  138.  
  139. enabled = false
  140. port = ftp,ftp-data,ftps,ftps-data
  141. filter = wuftpd
  142. logpath = /var/log/auth.log
  143. maxretry = 6
  144.  
  145.  
  146. [couriersmtp]
  147.  
  148. enabled = false
  149. port = smtp,ssmtp
  150. filter = couriersmtp
  151. logpath = /var/log/mail.log
  152.  
  153.  
  154. #
  155. # Mail servers authenticators: might be used for smtp,ftp,imap servers, so
  156. # all relevant ports get banned
  157. #
  158.  
  159. [courierauth]
  160.  
  161. enabled = false
  162. port = smtp,ssmtp,imap2,imap3,imaps,pop3,pop3s
  163. filter = courierlogin
  164. logpath = /var/log/mail.log
  165.  
  166.  
  167. [sasl]
  168.  
  169. enabled = false
  170. port = smtp,ssmtp,imap2,imap3,imaps,pop3,pop3s
  171. filter = sasl
  172. # You might consider monitoring /var/log/mail.warn instead if you are
  173. # running postfix since it would provide the same log lines at the
  174. # "warn" level but overall at the smaller filesize.
  175. logpath = /var/log/mail.log
  176.  
  177.  
  178. [named-refused-tcp]
  179.  
  180. enabled = false
  181. port = domain,953
  182. protocol = tcp
  183. filter = named-refused
  184. logpath = /var/log/named/security.log
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement