⚝
One Hat Cyber Team
⚝
Your IP:
216.73.216.133
Server IP:
185.119.109.197
Server:
Linux managedhosting.chostar.me 5.15.0-160-generic #170-Ubuntu SMP Wed Oct 1 10:06:56 UTC 2025 x86_64
Server Software:
Apache
PHP Version:
8.1.33
Buat File
|
Buat Folder
Eksekusi
Dir :
~
/
proc
/
thread-self
/
root
/
etc
/
fail2ban
/
filter.d
/
View File Name :
sshd.conf
# Fail2Ban filter for openssh # # If you want to protect OpenSSH from being bruteforced by password # authentication then get public key authentication working before disabling # PasswordAuthentication in sshd_config. # # # "Connection from
port \d+" requires LogLevel VERBOSE in sshd_config # [INCLUDES] # Read common prefixes. If any customizations available -- read them from # common.local before = common.conf [DEFAULT] _daemon = sshd # optional prefix (logged from several ssh versions) like "error: ", "error: PAM: " or "fatal: " __pref = (?:(?:error|fatal): (?:PAM: )?)? # optional suffix (logged from several ssh versions) like " [preauth]" #__suff = (?: port \d+)?(?: \[preauth\])?\s* __suff = (?: (?:port \d+|on \S+|\[preauth\])){0,3}\s* __on_port_opt = (?: (?:port \d+|on \S+)){0,2} # close by authenticating user: __authng_user = (?: (?:invalid|authenticating) user
\S+|.*?
)? # for all possible (also future) forms of "no matching (cipher|mac|MAC|compression method|key exchange method|host key type) found", # see ssherr.c for all possible SSH_ERR_..._ALG_MATCH errors. __alg_match = (?:(?:\w+ (?!found\b)){0,2}\w+) # PAM authentication mechanism, can be overridden, e. g. `filter = sshd[__pam_auth='pam_ldap']`: __pam_auth = pam_[a-z]+ [Definition] prefregex = ^
%(__prefix_line)s
%(__pref)s
.+
$ cmnfailre = ^[aA]uthentication (?:failure|error|failed) for
.*
from
( via \S+)?%(__suff)s$ ^User not known to the underlying authentication module for
.*
from
%(__suff)s$
> ^Failed
for (?P
invalid user )?
(?P
\S+)|(?(cond_inv)(?:(?! from ).)*?|[^:]+)
from
%(__on_port_opt)s(?: ssh\d*)?(?(cond_user): |(?:(?:(?! from ).)*)$) ^
ROOT
LOGIN REFUSED FROM
^[iI](?:llegal|nvalid) user
.*?
from
%(__suff)s$ ^User
\S+|.*?
from
not allowed because not listed in AllowUsers%(__suff)s$ ^User
\S+|.*?
from
not allowed because listed in DenyUsers%(__suff)s$ ^User
\S+|.*?
from
not allowed because not in any group%(__suff)s$ ^refused connect from \S+ \(
\) ^Received
disconnect
from
%(__on_port_opt)s:\s*3: .*: Auth fail%(__suff)s$ ^User
\S+|.*?
from
not allowed because a group is listed in DenyGroups%(__suff)s$ ^User
\S+|.*?
from
not allowed because none of user's groups are listed in AllowGroups%(__suff)s$ ^
%(__pam_auth)s\(sshd:auth\):\s+authentication failure;
(?:\s+(?:(?:logname|e?uid|tty)=\S*)){0,4}\s+ruser=
\S*
\s+rhost=
(?:\s+user=
\S*
)?%(__suff)s$ ^maximum authentication attempts exceeded for
.*
from
%(__on_port_opt)s(?: ssh\d*)?%(__suff)s$ ^User
\S+|.*?
not allowed because account is locked%(__suff)s ^
Disconnecting
(?: from)?(?: (?:invalid|authenticating)) user
\S+
%(__on_port_opt)s:\s*Change of username or service not allowed:\s*.*\[preauth\]\s*$ ^Disconnecting: Too many authentication failures(?: for
\S+|.*?
)?%(__suff)s$ ^
Received
disconnect
from
%(__on_port_opt)s:\s*11:
-other> ^
Accepted \w+
for
\S+
from
(?:\s|$) cmnfailed-any = \S+ cmnfailed-ignore = \b(?!publickey)\S+ cmnfailed-invalid =
cmnfailed-nofail = (?:
publickey
|\S+) cmnfailed =
> mdre-normal = # used to differentiate "connection closed" with and without `[preauth]` (fail/nofail cases in ddos mode) mdre-normal-other = ^
(Connection closed|Disconnected)
(?:by|from)%(__authng_user)s
(?:%(__suff)s|\s*)$ mdre-ddos = ^Did not receive identification string from
^kex_exchange_identification: (?:[Cc]lient sent invalid protocol identifier|[Cc]onnection closed by remote host) ^Bad protocol version identification '.*' from
^
SSH: Server;Ltype:
(?:Authname|Version|Kex);Remote:
-\d+;[A-Z]\w+: ^Read from socket failed: Connection
reset
by peer # same as mdre-normal-other, but as failure (without
) and [preauth] only: mdre-ddos-other = ^
(Connection (?:closed|reset)|Disconnected)
(?:by|from)%(__authng_user)s
%(__on_port_opt)s\s+\[preauth\]\s*$ mdre-extra = ^Received
disconnect
from
%(__on_port_opt)s:\s*14: No(?: supported)? authentication methods available ^Unable to negotiate with
%(__on_port_opt)s: no matching <__alg_match> found. ^Unable to negotiate a <__alg_match> ^no matching <__alg_match> found: # part of mdre-ddos-other, but user name is supplied (invalid/authenticating) on [preauth] phase only: mdre-extra-other = ^
Disconnected
(?: from)?(?: (?:invalid|authenticating)) user
\S+|.*?
%(__on_port_opt)s \[preauth\]\s*$ mdre-aggressive = %(mdre-ddos)s %(mdre-extra)s # mdre-extra-other is fully included within mdre-ddos-other: mdre-aggressive-other = %(mdre-ddos-other)s # Parameter "publickey": nofail (default), invalid, any, ignore publickey = nofail # consider failed publickey for invalid users only: cmnfailre-failed-pub-invalid = ^Failed publickey for invalid user
(?P
\S+)|(?:(?! from ).)*?
from
%(__on_port_opt)s(?: ssh\d*)?(?(cond_user): |(?:(?:(?! from ).)*)$) # consider failed publickey for valid users too (don't need RE, see cmnfailed): cmnfailre-failed-pub-any = # same as invalid, but consider failed publickey for valid users too, just as no failure (helper to get IP and user-name only, see cmnfailed): cmnfailre-failed-pub-nofail =
# don't consider failed publickey as failures (don't need RE, see cmnfailed): cmnfailre-failed-pub-ignore = cfooterre = ^
Connection from
failregex = %(cmnfailre)s
> %(cfooterre)s # Parameter "mode": normal (default), ddos, extra or aggressive (combines all) # Usage example (for jail.local): # [sshd] # mode = extra # # or another jail (rewrite filter parameters of jail): # [sshd-aggressive] # filter = sshd[mode=aggressive] # mode = normal #filter = sshd[mode=aggressive] ignoreregex = maxlines = 1 journalmatch = _SYSTEMD_UNIT=sshd.service + _COMM=sshd # DEV Notes: # # "Failed \S+ for .*? from
..." failregex uses non-greedy catch-all because # it is coming before use of
which is not hard-anchored at the end as well, # and later catch-all's could contain user-provided input, which need to be greedily # matched away first. # # Author: Cyril Jaquier, Yaroslav Halchenko, Petr Voralek, Daniel Black and Sergey Brester aka sebres # Rewritten using prefregex (and introduced "mode" parameter) by Serg G. Brester.