Log message:
fail2ban: updated to 1.1.1
1.1.1
Compatibility
action.d/iptables.conf rewritten due to support of multiple chains (gh-3909), \
therefore user-level derivations (action including iptables-based action) may \
become incompatible, e. g. some tags if used need to be replaced, e. g. \
<chain> with $chain or <_ipt_for_proto-iter> with <_ipt-iter>;
filter.d/exim.conf - several rules of mode normal moved to new mode more, \
because of too risky handling (see gh-3940), to use it as before set mode = more \
for exim jail, but be aware of the consequences.
Fixes
fixes catastrophic backtracking explosion for REs in domino-smtp and dovecot \
filters (GHSA-33wh-ccjc-p397, gh-4221)
fixes systemd bug with missing journal descriptor after rotation by reopening of \
journal if it is recognized as not alive (gh-3929)
improve threaded clean-up of all filters, new thread functions afterStop (to \
force clean-up after stop) and done, invoking afterStop once
ensure journal-reader is always closed (additional prevention against leaks and \
"too many open files"), thereby avoid sporadic segfault in systemd \
module
fixes systemd causing "too many open files" error for a lot of journal \
files and large amount of systemd jails (see new parameter rotated below, \
gh-3391);
passing of arguments from jails to action or filter will affect conditional \
section too (gh-4069), e. g. setting blocktype="DROP" via jail for \
action would now apply for IPv4 and IPv6 chains, to submit different blocktype \
for IPv4 and IPv6 from jail, one can pass them like in this example: banaction = \
iptables-ipset[blocktype="...", \
blocktype?family=inet6="..."]
jail.conf:
default banactions need to be specified in paths-*.conf (maintainer level) now
since stock fail2ban includes paths-debian.conf by default, banactions are \
nftables (can be overwritten in jail.local by user)
paths-common.conf:
changed default mysql_log path (default logpath of mysqld-auth jail without \
maintainer overrides, gh-3932)
paths-debian.conf:
default banactions are nftables
sshd backend switched to systemd (gh-3292)
postfix backend switched to systemd (gh-3527)
action.d/firewallcmd-ipset.conf:
rename ipsettype to ipsetbackend (gh-2620), parameter ipsettype will be used now \
to the real set type (gh-3760)
action.d/nftables.conf:
action fixed for SELinux without execmem permission, rewrite capturing with grep \
-P using grep -E or sed (PCRE-JIT by grep -P may cause SELinux denial for \
execmem, see gh-4137)
action.d/xarf-login-attack.conf - ignore errors or warnings in output of dig \
provided as comment (gh-4068)
filter.d/apache-badbots.conf, filter.d/apache-fakegooglebot.conf:
regexs rewritten more strict (removed catch-alls, etc);
regexs fixed to match lines with vhost in accesslog (gh-1594)
filter.d/apache-noscript.conf - consider new log-format with "AH02811: \
stderr from /..." (gh-3900)
filter.d/apache-overflows.conf - consider AH10244: invalid URI path (gh-3778, \
gh-3900)
filter.d/asterisk.conf - fixed RE for "no matching endpoint" with \
retry info (like after X tries in Y ms) at end, loosening of end anchor (ignore \
any simple text tokens at end if no single quote found), gh-4037
filter.d/exim.conf:
several rules of mode normal moved to new mode more, because of too risky \
handling (gh-3940), thereby mode aggressive is not affected, because it fully \
includes mode more now;
mode aggressive extended to catch dropped by ACL failures, e.g. "ACL: \
Country is banned"
filter.d/freeswitch.conf - bypass some new info in prefix before [WARNING] \
(changed default _pref_line), FreeSWITCH log line prefix has changed in newer \
versions (gh-3143)
filter.d/lighttpd-auth.conf - fixed regex (if failures generated by \
systemd-journal), bypass several prefixes now (gh-3955)
filter.d/postfix.conf:
extended prefregex to capture username in postfix SASL failures (gh-4165)
consider CONNECT and other rejected commands as a valid _pref (gh-3800)
default _daemon in prefix-line is loosened - can match everything starting with \
word postfix, like postfix-example.com/smtpd (gh-3297)
add optional NOQUEUE: prefix to ddos regex (gh-4072)
internal parameter _pref is renamed to _cmd, _pref matches now optional prefix \
like NOQUEUE: etc
modes ddos and aggressive extended to match rate limit exceeded for connection \
or message delivery request rates (gh-3265, gh-4073)
modes aggressive extended to match hostname does not resolve to address \
(gh-4218, gh-4078)
filter.d/dropbear.conf:
recognizes extra pid/timestamp if logged into stdout/journal, added journalmatch \
(gh-3597)
failregex extended to match different format of "Exit before auth" \
message (gh-3791)
filter.d/recidive.conf - restore possibility to set jail name in the filter, \
_jailname is positive now (gh-3769)
filter.d/roundcube-auth.conf - improved RE better matching log format of \
roundcube version 1.4+ (gh-3816)
filter.d/sendmail-reject.conf: (gh-4020)
support <F-MLFID> for BSD-style logfiles
add match for User unknown to default
the relay field may not always have a hostname before the ip address
mode aggressive enables match for lost input channel and Cannot resolve PTR record
filter.d/sshd.conf:
adapted to conform possible new daemon name sshd-session, since OpenSSH 9.8 \
several log messages will be tagged with as originating from a process named \
"sshd-session" rather than "sshd" (gh-3782)
ddos and aggressive modes: regex extended for timeout before authentication \
(optional connection from part, gh-3907)
filter.d/vsftpd.conf - fixed regex (if failures generated by systemd-journal, \
gh-3954)
filter.d/froxlor-auth.conf - updated the regex to the new logging situation for \
froxlor and changed logpath in jail.conf (gh-4075).
|