<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://forum.ubuntu-fr.org/extern.php?action=feed&amp;tid=1180471&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Forum Ubuntu-fr.org / [résolu] Fail2ban et scanlogd, difficulté au redémarrage]]></title>
		<link>http://forum.ubuntu-fr.org/viewtopic.php?id=1180471</link>
		<description><![CDATA[Les sujets les plus récents dans [résolu] Fail2ban et scanlogd, difficulté au redémarrage.]]></description>
		<lastBuildDate>Sun, 27 Jan 2013 20:23:40 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Réponse à&#160;:  [résolu] Fail2ban et scanlogd, difficulté au redémarrage]]></title>
			<link>http://forum.ubuntu-fr.org/viewtopic.php?pid=12365581#p12365581</link>
			<description><![CDATA[<p>Nickel mon VPS est ban, juste un petit :</p><div class="codebox"><pre><code>service scanlogd restart
Restarting scanlogd: chroot: No such file or directory
# Corriger avec 
cd /var/run/
mkdir scanlogd
chmod 750 scanlogd</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (devphp)]]></author>
			<pubDate>Sun, 27 Jan 2013 20:23:40 +0000</pubDate>
			<guid>http://forum.ubuntu-fr.org/viewtopic.php?pid=12365581#p12365581</guid>
		</item>
		<item>
			<title><![CDATA[Réponse à&#160;:  [résolu] Fail2ban et scanlogd, difficulté au redémarrage]]></title>
			<link>http://forum.ubuntu-fr.org/viewtopic.php?pid=12365371#p12365371</link>
			<description><![CDATA[<p>Super ça fonctionne, maintenant je vais faire ban mon vps xD</p><p>Merci</p>]]></description>
			<author><![CDATA[dummy@example.com (devphp)]]></author>
			<pubDate>Sun, 27 Jan 2013 19:55:59 +0000</pubDate>
			<guid>http://forum.ubuntu-fr.org/viewtopic.php?pid=12365371#p12365371</guid>
		</item>
		<item>
			<title><![CDATA[Réponse à&#160;:  [résolu] Fail2ban et scanlogd, difficulté au redémarrage]]></title>
			<link>http://forum.ubuntu-fr.org/viewtopic.php?pid=12359101#p12359101</link>
			<description><![CDATA[<p>bonjour,</p><p>le filtre matche l&#039;ip mais fail2ban ne sait pas quoi matché comme ports. <br />fais un test avec; </p><div class="codebox"><pre><code>[scanlogd]
enabled = true
filter = scanlogd
logpath = /var/log/syslog
maxretry = 1
action = iptables-allports[name=ALL]</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (Titouan)]]></author>
			<pubDate>Sun, 27 Jan 2013 10:17:40 +0000</pubDate>
			<guid>http://forum.ubuntu-fr.org/viewtopic.php?pid=12359101#p12359101</guid>
		</item>
		<item>
			<title><![CDATA[[résolu] Fail2ban et scanlogd, difficulté au redémarrage]]></title>
			<link>http://forum.ubuntu-fr.org/viewtopic.php?pid=12356121#p12356121</link>
			<description><![CDATA[<p>Bonjour,</p><p>Je configure fail2ban, de façon a pouvoir bannir les personnes qui scan les ports (une de trop)<br />J&#039;ai donc installer scanlogd et j&#039;ai pris mon autre serveur et lance un scan</p><div class="codebox"><pre><code>cat /var/log/syslog | grep scanlogd
Jan 26 22:35:38 stock scanlogd: 88.191.157.29 to 5.39.92.155 ports 22, 443, 995, 21, 80, 143, ..., ?????uxy, TOS 00 @19:53:54</code></pre></div><p>Tout fonctionne jusqu&#039;a présent, je passe donc a fail2ban, je rajout un petit filtre</p><div class="codebox"><pre><code>[Definition]
failregex = scanlogd: &lt;HOST&gt; to .*
ignoreregex =</code></pre></div><p>Petit test avant de lancer le monstre</p><div class="codebox"><pre><code>fail2ban-regex /var/log/syslog /etc/fail2ban/filter.d/scanlogd.conf 
... Bla bla 
Success, the total number of match is 1

However, look at the above section &#039;Running tests&#039; which could contain important
information.</code></pre></div><p>Bon c&#039;est ok, fail2ban a compris</p><div class="codebox"><pre class="vscroll"><code>service fail2ban restart

 * Restarting authentication failure monitor fail2ban                                                                                                                   Traceback (most recent call last):
  File &quot;/usr/bin/fail2ban-client&quot;, line 404, in &lt;module&gt;
    if client.start(sys.argv):
  File &quot;/usr/bin/fail2ban-client&quot;, line 373, in start
    return self.__processCommand(args)
  File &quot;/usr/bin/fail2ban-client&quot;, line 183, in __processCommand
    ret = self.__readConfig()
  File &quot;/usr/bin/fail2ban-client&quot;, line 378, in __readConfig
    ret = self.__configurator.getOptions()
  File &quot;/usr/share/fail2ban/client/configurator.py&quot;, line 68, in getOptions
    return self.__jails.getOptions(jail)
  File &quot;/usr/share/fail2ban/client/jailsreader.py&quot;, line 67, in getOptions
    ret = jail.getOptions()
  File &quot;/usr/share/fail2ban/client/jailreader.py&quot;, line 73, in getOptions
    self.__opts = ConfigReader.getOptions(self, self.__name, opts)
  File &quot;/usr/share/fail2ban/client/configreader.py&quot;, line 87, in getOptions
    v = self.get(sec, option[1])
  File &quot;/usr/lib/python2.7/ConfigParser.py&quot;, line 623, in get
    return self._interpolate(section, option, value, d)
  File &quot;/usr/lib/python2.7/ConfigParser.py&quot;, line 691, in _interpolate
    self._interpolate_some(option, L, rawval, section, vars, 1)
  File &quot;/usr/lib/python2.7/ConfigParser.py&quot;, line 726, in _interpolate_some
    section, map, depth + 1)
  File &quot;/usr/lib/python2.7/ConfigParser.py&quot;, line 723, in _interpolate_some
    option, section, rest, var)
ConfigParser.InterpolationMissingOptionError: Bad value substitution:
	section: [scanlogd]
	option : action
	key    : port
	rawval : &quot;, protocol=&quot;%(protocol)s&quot;, chain=&quot;%(chain)s&quot;]

                                                                                                                                                                 [fail]</code></pre></div><p>Quoi que ....</p><p>Je regarde la jail</p><div class="codebox"><pre><code>[scanlogd]
enabled = true
#filter = scanlogd
logpath = /var/log/syslog
maxretry = 1</code></pre></div><br /><p>Ou est mon erreur ?</p>]]></description>
			<author><![CDATA[dummy@example.com (devphp)]]></author>
			<pubDate>Sat, 26 Jan 2013 22:20:40 +0000</pubDate>
			<guid>http://forum.ubuntu-fr.org/viewtopic.php?pid=12356121#p12356121</guid>
		</item>
	</channel>
</rss>
