Fail2ban: dovecot ๋กœ๊ทธ์ธ/์ธ์ฆ์— ๋Œ€ํ•ด fail2ban์„ ์„ค์ •ํ•˜๋Š” ๋ฐ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

์— ๋งŒ๋“  2018๋…„ 05์›” 16์ผ  ยท  4์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: fail2ban/fail2ban

  • Fail2Ban ๋ฒ„์ „ fail2ban/bionic, bionic, ํ˜„์žฌ 0.10.2-2 ๋ชจ๋‘ [์„ค์น˜๋จ]
  • Linux divzero.at 4.15.0-20-generic #21-Ubuntu SMP Tue Apr 24 06:16:15 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
  • ์šฐ๋ถ„ํˆฌ 18.04 LTS
  • [x] OS/๋ฐฐํฌ ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ํ†ตํ•ด ์„ค์น˜๋œ Fail2Ban
  • [x] ์ฝ”๋“œ๋ฒ ์ด์Šค์— ์ถ”๊ฐ€ ์™ธ๋ถ€ ํŒจ์น˜๋ฅผ ์ ์šฉํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.
  • [x] ๊ตฌ์„ฑ์— ๋Œ€ํ•ด ์ผ๋ถ€ ์‚ฌ์šฉ์ž ์ง€์ •์ด ์ˆ˜ํ–‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค(์•„๋ž˜์— ์„ธ๋ถ€ ์ •๋ณด ์ œ๊ณต).

๋ฌธ์ œ:

์•ˆ๋…•ํ•˜์„ธ์š”,
์‹คํŒจํ•œ ์ธ์ฆ/๋กœ๊ทธ์ธ ์‹œ๋„๋ฅผ ๊ธˆ์ง€ํ•˜๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ํŠœํ† ๋ฆฌ์–ผ/ํ•˜์šฐํˆฌ๊ฐ€ ์žˆ์ง€๋งŒ ์ผ์ข…์˜ ๊ตฌ์‹ ์ •๊ทœ์‹์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๊นŒ?

/etc/fail2ban # fail2ban-regex /var/log/mail.log /etc/fail2ban/filter.d/dovecot-pop3imap.conf

Running tests
=============
Use   failregex filter file : dovecot-pop3imap, basedir: /etc/fail2ban
ERROR: No failure-id group in '(?: pop3-login|imap-login): (?:Authentication failure|Aborted login \(auth failed|Aborted login \(tried to use disabled|Disconnected \(auth failed).*rip=(?P<host>\S*),.*'

https://wiki.dovecot.org/HowTo/Fail2Ban ๋ฐ https://www.fail2ban.org/wiki/index.php/Dovecot ๋„ ๋ณด๊ณ  ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค

๋‘ ๋ฒˆ์งธ ํŽ˜์ด์ง€์˜ ์˜ˆ์ œ์—์„œ๋Š” ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜์ง€ ์•Š์ง€๋งŒ ์‹ค์ œ๋กœ ์›ํ•˜๋Š” ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๋Š”์ง€ ํ™•์‹คํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์žฌํ˜„ ๋‹จ๊ณ„

dovecot ์œ„ํ‚ค์— ์„ค๋ช…๋œ ๋Œ€๋กœ dovecot-pop3imap.conf๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

์˜ˆ์ƒ๋˜๋Š” ํ–‰๋™

์‹คํŒจํ•œ ๋กœ๊ทธ์ธ/์ธ์ฆ ์‹œ๋„๋ฅผ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.

๊ด€์ฐฐ๋œ ํ–‰๋™

์ •๊ทœ์‹์ด ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ถ”๊ฐ€ ์ •๋ณด

์–ด์ œ ์šฐ๋ถ„ํˆฌ ์„œ๋ฒ„๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œํ–ˆ๊ณ  ์ƒˆ๋กœ์šด ๋ฒ„์ „์˜ fail2ban์„ ์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ ์ดํ›„๋กœ ์‚ฌ์šฉ์ž ์ •์˜ ๊ตฌ์„ฑ์€ ๋” ์ด์ƒ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๊ตฌ์„ฑ, ๋คํ”„ ๋ฐ ๊ธฐํƒ€ ์œ ์šฉํ•œ ๋ฐœ์ทŒ๋ฌธ

/etc/fail2ban/ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ๋ชจ๋“  ์‚ฌ์šฉ์ž ์ •์˜

/var/log/fail2ban.log ํŒŒ์ผ์˜ ๊ด€๋ จ ๋ถ€๋ถ„:

_ loglevel = 4 fail2ban์„ ์‹คํ–‰ํ•˜๋Š” ๋™์•ˆ ์–ป๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค _

2018-05-16 14:20:09,136 fail2ban.filter         [31796]: ERROR   No failure-id group in '(?: pop3-login|imap-login): (?:Authentication failure|Aborted login \(auth failed|Aborted login \(tried to use disabled|Disconnected \(auth failed).*rip=(?P<host>\S*),.*'
2018-05-16 14:20:09,136 fail2ban.transmitter    [31796]: WARNING Command ['set', 'dovecot-pop3imap', 'addfailregex', '(?: pop3-login|imap-login): (?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed).*rip=(?P<host>\\S*),.*'] has failed. Received Rege
xException("No failure-id group in '(?: pop3-login|imap-login): (?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed).*rip=(?P<host>\\S*),.*'",)
2018-05-16 14:20:09,137 fail2ban                [31796]: ERROR   NOK: ("No failure-id group in '(?: pop3-login|imap-login): (?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed).*rip=(?P<host>\\S*),.*'",)

๋ฌธ์ œ์˜ ๋ชจ๋‹ˆํ„ฐ๋ง๋œ ๋กœ๊ทธ ํŒŒ์ผ์˜ ๊ด€๋ จ ์ค„:

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

์ง€๊ธˆ '์‹ซ์–ด์š”'๊ฐ€ ๋ณด์ด์‹œ๋‚˜์š”...

๊ทธ๋ฆฌ๊ณ  ๊ฐœ๋ฐœ์ž sebres๋Š” ์ด๊ฒƒ์„ ๋…ผํ‰ํ•ฉ๋‹ˆ๋‹ค ...

์•„๋‹ˆ, "๊ฐœ๋ฐœ์ž sebres๋Š”"์ฃผ์„ - ํ† ํฐ์„ ์‚ฌ์šฉ <HOST> ๋Œ€์‹  (?P<host>\S*) .

์ •๊ทœ์‹ (?P<host>\S*) ๋Š” ์–ด์จŒ๋“  ๋ฌธ์„œํ™”๋˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์ด์—ˆ์Šต๋‹ˆ๋‹ค(๊ทธ๋ฆฌ๊ณ  ๋‹น์‹ ์ด ์•„์ง ํƒœ์–ด๋‚˜์ง€ ์•Š์€ ์‹œ๋Œ€๋ถ€ํ„ฐ)... ๊ทธ๋Ÿผ์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ , ์ผ๋ถ€ ๋ฌธ์„œํ™”๋˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์ด ์ด์ „์— ์ž‘๋™ํ•œ ๊ฒฝ์šฐ์—๋„ ๋™์ผํ•˜๊ฒŒ ์ž‘๋™ํ•œ๋‹ค๋Š” ์˜๋ฏธ๋Š” ์•„๋‹™๋‹ˆ๋‹ค. ์ตœ์‹  ๋ฒ„์ „, ํŠนํžˆ changelog๊ฐ€ ์ƒ๋‹จ์— ๊ตต์€ ๊ตต์€ ๊ธ€์”จ๋กœ ํ‘œ์‹œ๋˜๋Š” ๊ฒฝ์šฐ:
https://github.com/fail2ban/fail2ban/blob/e2a255d104f947f149cc34b17e778c05175e9f78/ChangeLog#L9 -L22

๊ทธ๋ž˜๋„ ๋‹ค์‹œ:

  • (?P<host>\S*) - ์•„๋‹ˆ์š”.
  • <HOST> , <ADDR> , <DNS> - ์˜ˆ.

0.10 ์ดํ›„์˜ fail2ban์ด IPv4์™€ IPv6์„ ๊ตฌ๋ถ„ํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์‹œ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
๋”ฐ๋ผ์„œ (?P<host>\S*) ๋Œ€ํ•œ ์ ์ ˆํ•œ ์ •๊ทœ์‹ ๊ธฐ๋ฐ˜ ๋Œ€์ฒด๋Š” ๋” ๋ณต์žกํ•ฉ๋‹ˆ๋‹ค.

<HOST> ์ผ๋ฐ˜ ํƒœ๊ทธ ์™ธ์—๋„ <ADDR> , <IP4> , <IP6> ๋ฐ DNS ์™€ ๊ฐ™์ด ํ˜„์žฌ ๊ฐ€๋Šฅํ•œ ๋‹ค๋ฅธ ํƒœ๊ทธ๊ฐ€ ๋งŽ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์‹คํŒจ ID์— ๋Œ€ํ•œ IP๋กœ ๋‹ค๋ฅธ ๊ฒƒ์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด wiki :: ์‚ฌ์šฉ์ž๋‚˜ ๋ฉ”์ผ ๋“ฑ๊ณผ ๊ฐ™์€ ํ˜ธ์ŠคํŠธ(IP ์ฃผ์†Œ)๋กœ ๋‹ค๋ฅธ ๊ฒƒ์„ ๊ธˆ์ง€ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ฐธ์กฐํ•˜์„ธ์š”

sebres๋ฅผ ์ž‘์„ฑํ•˜๋Š” ๋ฐ ์–ผ๋งˆ๋‚˜ ๋งŽ์€ ์‹œ๊ฐ„์ด ๊ฑธ๋ฆด์ง€ ์˜ˆ:

๋„ˆ๋ฌด ๋งŽ์Šต๋‹ˆ๋‹ค(๋ฌด๋ฃŒ์ด๊ธฐ ๋•Œ๋ฌธ์—). ๊ทธ๋Ÿฌ๋‚˜ ๊ทธ(๊ทธ๋ฆฌ๊ณ  ๋‹ค๋ฅธ ๋งŽ์€ ์‚ฌ๋žŒ๋“ค)๋Š” ์ด๋ฏธ ์ถฉ๋ถ„ํ•œ ์˜ˆ์ œ(์œ„์˜ ์œ„ํ‚ค ์ฐธ์กฐ), docu ๋ฐ changelog ํ•ญ๋ชฉ(์•„๋ฌด๋„ ์ฝ์ง€ ์•Š์Œ)์„ ์ž‘์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค.

๋งˆ์ง€๋ง‰์œผ๋กœ ์ค‘์š”ํ•œ ๊ฒƒ์€ - ์˜์–ด๋ฅผ ๋ฐฐ์šฐ๋ ค๊ณ  ํ•˜๋ฉด ์ฒซ ๋ฒˆ์งธ ๋Œ“๊ธ€์˜ ๋‹ต์„ ์ดํ•ดํ•  ์ˆ˜ ์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

  • ๋Œ€์‹  <HOST> (๋ชจ๋“  ์–‘์‹ ๋ˆ„์ ), <ADDR> (ips ์ „์šฉ) ๋˜๋Š” <DNS> (dns-hosts ์ „์šฉ)๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์š”์•ฝ?

๋ชจ๋“  4 ๋Œ“๊ธ€

(?P<host>\S*) ๊ฐ’์€ ๋” ์ด์ƒ ์œ ํšจํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(0.10์˜ IPv6 ์ง€์› ์ดํ›„, ์ตœ์‹  ๋ฒ„์ „์˜ fail2ban์—๋Š” DNS/IPv4/IPv6์— ๋Œ€ํ•œ ๋‹ค๋ฅธ ์ฒ˜๋ฆฌ ๋ฐ ์ •๊ทœ ํ‘œํ˜„์‹์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ผ์น˜ํ•˜๋Š” ๋™์•ˆ ์ด ๊ทธ๋ฃน์„ ๊ตฌ๋ณ„ํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค).
๋”ฐ๋ผ์„œ <HOST> (๋ชจ๋“  ์–‘์‹ ๋ˆ„์ ), <ADDR> (ips ์ „์šฉ) ๋˜๋Š” <DNS> (dns-hosts ์ „์šฉ)๋ฅผ ๋Œ€์‹  ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ใ……ใ…‚. ๋ณด๊ฐ„ <HOST> ๋Š” ๋‹ค์Œ ์ •๊ทœ์‹์— ๋Œ€ํ•œ "๋ณ„์นญ"์ž…๋‹ˆ๋‹ค.

(?:(?:::f{4,6}:)?(?P<ip4>(?:\\d{1,3}\\.){3}\\d{1,3})|\\[?(?P<ip6>(?:[0-9a-fA-F]{1,4}::?|::){1,7}(?:[0-9a-fA-F]{1,4}|(?<=:):))\\]?|(?P<dns>[\\w\\-.^_]*\\w))

DISLIKE ๋ฒ„ํŠผ์€ ์–ด๋””์— ์žˆ์Šต๋‹ˆ๊นŒ? ์šฐ๋ถ„ํˆฌ๋ฅผ ์—…๋ฐ์ดํŠธ ํ•œ ํ›„ ๋™์ผํ•œ ๋ฌธ์ œ๋ฅผ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

fail2ban.filter         [8151]: ERROR   No failure-id group in '(?: pop3-login|imap-login): .*(?:Authentication failure|Aborted login \(auth failed|Aborted login \(tried to use disabled|Disconnected \(auth failed|Aborted login \(\d+ authentication attempts).*rip=(?P<host>\S*),.*'
2018-08-15 14:19:18,200 fail2ban.transmitter    [8151]: WARNING Command ['multi-set', 'dovecot-pop3imap', 'addfailregex', ['(?: pop3-login|imap-login): .*(?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed|Aborted login \\(\\d+ authentication attempts).*rip=(?P<host>\\S*),.*', '.*(?:pop3-login|imap-login):.*(?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed|Aborted login \\(tried to use disallowed plaintext auth).*\\s+rip=(?P<host>\\S*),.*', 'pam.*dovecot.*(?:authentication failure).*\\s+rhost=<HOST>(?:\\s+user=.*)?\\s*$']] has failed. Received RegexException("No failure-id group in '(?: pop3-login|imap-login): .*(?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed|Aborted login \\(\\d+ authentication attempts).*rip=(?P<host>\\S*),.*'",)
2018-08-15 14:19:18,200 fail2ban                [8151]: ERROR   NOK: ("No failure-id group in '(?: pop3-login|imap-login): .*(?:Authentication failure|Aborted login \\(auth failed|Aborted login \\(tried to use disabled|Disconnected \\(auth failed|Aborted login \\(\\d+ authentication attempts).*rip=(?P<host>\\S*),.*'",)

๊ทธ๋ฆฌ๊ณ  ๊ฐœ๋ฐœ์ž sebres๋Š” ์ด๊ฒƒ์„ ๋…ผํ‰ํ•ฉ๋‹ˆ๋‹ค.

(?:(?:::f{4,6}:)?(?P<ip4>(?:\\d{1,3}\\.){3}\\d{1,3})|\\[?(?P<ip6>(?:[0-9a-fA-F]{1,4}::?|::){1,7}(?:[0-9a-fA-F]{1,4}|(?<=:):))\\]?|(?P<dns>[\\w\\-.^_]*\\w))

๊ทธ๋ž˜์„œ ์šฐ๋ฆฌ๋Š” ๊ฐœ๋ฐœ์ž sebres๋ฅผ ์ดํ•ดํ•˜์ง€ ๋ชปํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ทธ๊ฒƒ์„ ๋ณต๊ตฌํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ดํ•ดํ•˜๋Š” ์‚ฌ๋žŒ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚˜์œ ๊ฐœ๋ฐœ์ž๋“ค์ด ์ด๋Ÿฐ ์ผ์„ ๊ทธ๋งŒ๋‘˜ ๋•Œ " (?:(?:::f{4,6}:)?(?P(?:\d{1,3}\.){3}\d{1,3})|\[?(?P(?:[0-9a-fA-F]{1,4}::?|::){1,7}(?:[0-9a-fA-F]{1,4}|(?< =:):))\]?|(?P[\w\-.^_]*\w)) "

๊ทธ๋ฆฌ๊ณ  ์†”๋ฃจ์…˜์„ ์ œ๊ณตํ•˜์‹ญ์‹œ์˜ค. ์ž‘๋™ํ•˜๋Š” 100 % ๊ดœ์ฐฎ์€ ๋งค๋‰ด์–ผ. ๋‚ด์ผ ๊ฒฝ์ฐฐ์— ๊ฐ€์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๋‹น์‹ ์ด ๋งˆ๋ฆฌํ™”๋‚˜๋ฅผ ํ”ผ์šฐ๋Š” ๊ฒƒ์„ ๋ณด๊ณ  ๊ฐ์˜ฅ์— ๊ฐ‘๋‹ˆ๋‹ค. ๋ฌธ์ œ๋Š” sebres๊ฐ€ ๊ฐ์˜ฅ์— ๊ฐ€๋Š” ์ด์œ ์ž…๋‹ˆ๋‹ค. ๋˜‘๊ฐ™๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. 100% ์ ์ ˆํ•œ ์„ค๋ช…์ด ์—†์Šต๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ์ฐจ์ด์ ์€ sebres๋Š” ๊ฒฝ์ฐฐ์— ์‹ ๊ณ ํ•˜๊ณ  PEOPLES๋Š” sebres์™€ ๊ฐ™์€ ๋‚˜์œ ๊ฐœ๋ฐœ์ž๋ฅผ ์‹ ๊ณ ํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‚˜๋Š” ์‚ฌ๋žŒ๋“ค์ด ๋‚˜์œ ๊ฐœ๋ฐœ์ž๋ฅผ ์œ„ํ•œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋ฅผ ๋งŒ๋“ค๋„๋ก ํˆฌํ‘œํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋‘๊ฐ€ ๋งค์ผ ๋‚˜์œ ๊ฐœ๋ฐœ์ด ๋†’๋‹ค๋Š” ๊ฒƒ์„ ๋ณด๊ฒŒ ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ sebres๊ฐ€ ๊ฒฝ์ฐฐ ๊ฐ์˜ฅ์— ๊ฐ€๊ฑฐ๋‚˜ ์‚ฌ๋žŒ๋“ค์ด ๋ถˆํ‰ํ•˜๋Š” ๋ฐ ์ฐจ์ด๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ sebres๋Š” ๋‹ค์Œ์„ ๋„ฃ์„ ์‹œ๊ฐ„์ด ์žˆ์Šต๋‹ˆ๋‹ค.
๊ทธ๋ž˜์„œ ๋‹น์‹ ์€ ์‚ฌ์šฉํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค(๋ชจ๋“  ํ˜•์‹์„ ๋ˆ„์ ),(ip๋งŒ ํ•ด๋‹น) ๋˜๋Š”(dns-hosts๋งŒ ํ•ด๋‹น) ๋Œ€์‹ . ๊ทธ๋ฆฌ๊ณ  ๊ทธ ํ›„ ์ž˜๋ชป๋œ ์•ˆ๋‚ด: BTW. ๋ณด๊ฐ„๋‹ค์Œ ์ •๊ทœ์‹์— ๋Œ€ํ•œ "๋ณ„์นญ"์ž…๋‹ˆ๋‹ค.

์˜ˆ: sebres๋ฅผ ์ž‘์„ฑํ•˜๋Š” ๋ฐ ์‹œ๊ฐ„์ด ์–ผ๋งˆ๋‚˜ ๊ฑธ๋ฆด์ง€ ์˜ˆ:

1 ๋ถ„. sebres์— ๋น„ํ•ด fail2ban ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  dovecot-pop3imap์„ ํ‘ธ๋Š” ๋ฐ ์‹คํŒจํ•˜๋ฉด ์‹œ์Šคํ…œ ๋กœ๊ทธ๊ฐ€ ํ”Œ๋Ÿฌ๋”ฉ๋œ๋‹ค๋Š” ๊ฒƒ์„ ๊ธฐ์–ตํ•˜์‹ญ์‹œ์˜ค.

์ง€๊ธˆ '์‹ซ์–ด์š”'๊ฐ€ ๋ณด์ด์‹œ๋‚˜์š”...

๊ทธ๋ฆฌ๊ณ  ๊ฐœ๋ฐœ์ž sebres๋Š” ์ด๊ฒƒ์„ ๋…ผํ‰ํ•ฉ๋‹ˆ๋‹ค ...

์•„๋‹ˆ, "๊ฐœ๋ฐœ์ž sebres๋Š”"์ฃผ์„ - ํ† ํฐ์„ ์‚ฌ์šฉ <HOST> ๋Œ€์‹  (?P<host>\S*) .

์ •๊ทœ์‹ (?P<host>\S*) ๋Š” ์–ด์จŒ๋“  ๋ฌธ์„œํ™”๋˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์ด์—ˆ์Šต๋‹ˆ๋‹ค(๊ทธ๋ฆฌ๊ณ  ๋‹น์‹ ์ด ์•„์ง ํƒœ์–ด๋‚˜์ง€ ์•Š์€ ์‹œ๋Œ€๋ถ€ํ„ฐ)... ๊ทธ๋Ÿผ์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ , ์ผ๋ถ€ ๋ฌธ์„œํ™”๋˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์ด ์ด์ „์— ์ž‘๋™ํ•œ ๊ฒฝ์šฐ์—๋„ ๋™์ผํ•˜๊ฒŒ ์ž‘๋™ํ•œ๋‹ค๋Š” ์˜๋ฏธ๋Š” ์•„๋‹™๋‹ˆ๋‹ค. ์ตœ์‹  ๋ฒ„์ „, ํŠนํžˆ changelog๊ฐ€ ์ƒ๋‹จ์— ๊ตต์€ ๊ตต์€ ๊ธ€์”จ๋กœ ํ‘œ์‹œ๋˜๋Š” ๊ฒฝ์šฐ:
https://github.com/fail2ban/fail2ban/blob/e2a255d104f947f149cc34b17e778c05175e9f78/ChangeLog#L9 -L22

๊ทธ๋ž˜๋„ ๋‹ค์‹œ:

  • (?P<host>\S*) - ์•„๋‹ˆ์š”.
  • <HOST> , <ADDR> , <DNS> - ์˜ˆ.

0.10 ์ดํ›„์˜ fail2ban์ด IPv4์™€ IPv6์„ ๊ตฌ๋ถ„ํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์‹œ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
๋”ฐ๋ผ์„œ (?P<host>\S*) ๋Œ€ํ•œ ์ ์ ˆํ•œ ์ •๊ทœ์‹ ๊ธฐ๋ฐ˜ ๋Œ€์ฒด๋Š” ๋” ๋ณต์žกํ•ฉ๋‹ˆ๋‹ค.

<HOST> ์ผ๋ฐ˜ ํƒœ๊ทธ ์™ธ์—๋„ <ADDR> , <IP4> , <IP6> ๋ฐ DNS ์™€ ๊ฐ™์ด ํ˜„์žฌ ๊ฐ€๋Šฅํ•œ ๋‹ค๋ฅธ ํƒœ๊ทธ๊ฐ€ ๋งŽ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์‹คํŒจ ID์— ๋Œ€ํ•œ IP๋กœ ๋‹ค๋ฅธ ๊ฒƒ์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด wiki :: ์‚ฌ์šฉ์ž๋‚˜ ๋ฉ”์ผ ๋“ฑ๊ณผ ๊ฐ™์€ ํ˜ธ์ŠคํŠธ(IP ์ฃผ์†Œ)๋กœ ๋‹ค๋ฅธ ๊ฒƒ์„ ๊ธˆ์ง€ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ฐธ์กฐํ•˜์„ธ์š”

sebres๋ฅผ ์ž‘์„ฑํ•˜๋Š” ๋ฐ ์–ผ๋งˆ๋‚˜ ๋งŽ์€ ์‹œ๊ฐ„์ด ๊ฑธ๋ฆด์ง€ ์˜ˆ:

๋„ˆ๋ฌด ๋งŽ์Šต๋‹ˆ๋‹ค(๋ฌด๋ฃŒ์ด๊ธฐ ๋•Œ๋ฌธ์—). ๊ทธ๋Ÿฌ๋‚˜ ๊ทธ(๊ทธ๋ฆฌ๊ณ  ๋‹ค๋ฅธ ๋งŽ์€ ์‚ฌ๋žŒ๋“ค)๋Š” ์ด๋ฏธ ์ถฉ๋ถ„ํ•œ ์˜ˆ์ œ(์œ„์˜ ์œ„ํ‚ค ์ฐธ์กฐ), docu ๋ฐ changelog ํ•ญ๋ชฉ(์•„๋ฌด๋„ ์ฝ์ง€ ์•Š์Œ)์„ ์ž‘์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค.

๋งˆ์ง€๋ง‰์œผ๋กœ ์ค‘์š”ํ•œ ๊ฒƒ์€ - ์˜์–ด๋ฅผ ๋ฐฐ์šฐ๋ ค๊ณ  ํ•˜๋ฉด ์ฒซ ๋ฒˆ์งธ ๋Œ“๊ธ€์˜ ๋‹ต์„ ์ดํ•ดํ•  ์ˆ˜ ์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

  • ๋Œ€์‹  <HOST> (๋ชจ๋“  ์–‘์‹ ๋ˆ„์ ), <ADDR> (ips ์ „์šฉ) ๋˜๋Š” <DNS> (dns-hosts ์ „์šฉ)๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์š”์•ฝ?

์–ธ์  ๊ฐ€ ์‚ฌ๋žŒ์ด ์™€์„œ ํ”„๋กœ๊ทธ๋žจ์„ ๋‹ค์‹œ ์ž‘์„ฑํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

  1. ๋‚ด ๊ฒƒ์ด ์•„๋‹ˆ๋‹ค
  2. ์ง€๊ธˆ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค ...
  3. ํ† ๋ก  ์ข…๋ฃŒ.
์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰