Ik heb net denyhosts geinstalleerd. Aangezien ik wat wil testen heb ik de purge periode (waarna de hosts die denied worden, worden gepurged) op 1 minuut gezet.
Via:
zouden dan de entries in /etc/hosts.deny moeten worden gepurged. Dit gebeurt echter niet.
Dit vond ik in /var/log/denyhosts
Ik zie echter niks vreemds, dus kan er niet goed de vinger achter krijgen waarom 't niet werkt.
Iemand enig idee waarom de entries niet gepurged worden?
PS /etc/hosts.deny is gewoon netjes aanwezig. Ook heb ik door meermaals verkeerd inloggen via ssh gezien dat mijn ip netjes wordt toegevoegd aan dit bestand.
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
| ######################################################################## # # PURGE_DENY: removed HOSTS_DENY entries that are older than this time # when DenyHosts is invoked with the --purge flag # # format is: i[dhwmy] # Where 'i' is an integer (eg. 7) # 'm' = minutes # 'h' = hours # 'd' = days # 'w' = weeks # 'y' = years # # never purge: #PURGE_DENY = # purge entries older than 1 minute PURGE_DENY = 1m # # purge entries older than 1 week #PURGE_DENY = 1w # # purge entries older than 5 days #PURGE_DENY = 5d ####################################################################### |
Via:
code:
1
2
| sudo service denyhosts stop sudo denyhosts --purge |
zouden dan de entries in /etc/hosts.deny moeten worden gepurged. Dit gebeurt echter niet.
Dit vond ik in /var/log/denyhosts
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
| 2012-07-15 11:31:59,552 - denyhosts : INFO DenyHosts launched with the following args: 2012-07-15 11:31:59,552 - denyhosts : INFO /usr/sbin/denyhosts --daemon --purge --config=/etc/denyhosts.conf 2012-07-15 11:31:59,552 - prefs : INFO DenyHosts configuration settings: 2012-07-15 11:31:59,552 - prefs : INFO ADMIN_EMAIL: [root@localhost] 2012-07-15 11:31:59,552 - prefs : INFO AGE_RESET_INVALID: [864000] 2012-07-15 11:31:59,552 - prefs : INFO AGE_RESET_RESTRICTED: [2160000] 2012-07-15 11:31:59,552 - prefs : INFO AGE_RESET_ROOT: [2160000] 2012-07-15 11:31:59,552 - prefs : INFO AGE_RESET_VALID: [432000] 2012-07-15 11:31:59,552 - prefs : INFO ALLOWED_HOSTS_HOSTNAME_LOOKUP: [no] 2012-07-15 11:31:59,553 - prefs : INFO BLOCK_SERVICE: [sshd] 2012-07-15 11:31:59,553 - prefs : INFO DAEMON_LOG: [/var/log/denyhosts] 2012-07-15 11:31:59,553 - prefs : INFO DAEMON_LOG_MESSAGE_FORMAT: [%(asctime)s - %(name)-12s: %(levelname)-8s %(message)s] 2012-07-15 11:31:59,553 - prefs : INFO DAEMON_LOG_TIME_FORMAT: [None] 2012-07-15 11:31:59,553 - prefs : INFO DAEMON_PURGE: [3600] 2012-07-15 11:31:59,553 - prefs : INFO DAEMON_SLEEP: [30] 2012-07-15 11:31:59,553 - prefs : INFO DENY_THRESHOLD_INVALID: [5] 2012-07-15 11:31:59,553 - prefs : INFO DENY_THRESHOLD_RESTRICTED: [1] 2012-07-15 11:31:59,553 - prefs : INFO DENY_THRESHOLD_ROOT: [1] 2012-07-15 11:31:59,553 - prefs : INFO DENY_THRESHOLD_VALID: [10] 2012-07-15 11:31:59,553 - prefs : INFO FAILED_ENTRY_REGEX: [None] 2012-07-15 11:31:59,553 - prefs : INFO FAILED_ENTRY_REGEX2: [None] 2012-07-15 11:31:59,553 - prefs : INFO FAILED_ENTRY_REGEX3: [None] 2012-07-15 11:31:59,554 - prefs : INFO FAILED_ENTRY_REGEX4: [None] 2012-07-15 11:31:59,554 - prefs : INFO FAILED_ENTRY_REGEX5: [None] 2012-07-15 11:31:59,554 - prefs : INFO FAILED_ENTRY_REGEX6: [None] 2012-07-15 11:31:59,554 - prefs : INFO FAILED_ENTRY_REGEX7: [None] 2012-07-15 11:31:59,554 - prefs : INFO HOSTNAME_LOOKUP: [YES] 2012-07-15 11:31:59,554 - prefs : INFO HOSTS_DENY: [/etc/hosts.deny] 2012-07-15 11:31:59,554 - prefs : INFO LOCK_FILE: [/run/denyhosts.pid] 2012-07-15 11:31:59,554 - prefs : INFO PLUGIN_DENY: [None] 2012-07-15 11:31:59,554 - prefs : INFO PLUGIN_PURGE: [None] 2012-07-15 11:31:59,554 - prefs : INFO PURGE_DENY: [60] 2012-07-15 11:31:59,554 - prefs : INFO PURGE_THRESHOLD: [0] 2012-07-15 11:31:59,554 - prefs : INFO RESET_ON_SUCCESS: [no] 2012-07-15 11:31:59,555 - prefs : INFO SECURE_LOG: [/var/log/auth.log] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_DATE_FORMAT: [%a, %d %b %Y %H:%M:%S %z] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_FROM: [DenyHosts <nobody@localhost>] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_HOST: [localhost] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_PASSWORD: [None] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_PORT: [25] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_SUBJECT: [DenyHosts Report] 2012-07-15 11:31:59,555 - prefs : INFO SMTP_USERNAME: [None] 2012-07-15 11:31:59,555 - prefs : INFO SSHD_FORMAT_REGEX: [None] 2012-07-15 11:31:59,555 - prefs : INFO SUCCESSFUL_ENTRY_REGEX: [None] 2012-07-15 11:31:59,555 - prefs : INFO SUSPICIOUS_LOGIN_REPORT_ALLOWED_HOSTS: [YES] 2012-07-15 11:31:59,555 - prefs : INFO SYNC_DOWNLOAD: [yes] 2012-07-15 11:31:59,556 - prefs : INFO SYNC_DOWNLOAD_RESILIENCY: [18000] 2012-07-15 11:31:59,556 - prefs : INFO SYNC_DOWNLOAD_THRESHOLD: [3] 2012-07-15 11:31:59,556 - prefs : INFO SYNC_INTERVAL: [3600] 2012-07-15 11:31:59,556 - prefs : INFO SYNC_SERVER: [None] 2012-07-15 11:31:59,556 - prefs : INFO SYNC_UPLOAD: [yes] 2012-07-15 11:31:59,556 - prefs : INFO SYSLOG_REPORT: [no] 2012-07-15 11:31:59,556 - prefs : INFO WORK_DIR: [/var/lib/denyhosts] 2012-07-15 11:31:59,556 - denyhosts : INFO restricted: set([]) 2012-07-15 11:31:59,557 - denyhosts : INFO launching DenyHosts daemon (version 2.6)... 2012-07-15 11:31:59,559 - denyhosts : INFO DenyHosts daemon is now running, pid: 21711 2012-07-15 11:31:59,560 - denyhosts : INFO send daemon process a TERM signal to terminate cleanly 2012-07-15 11:31:59,560 - denyhosts : INFO eg. kill -TERM 21711 2012-07-15 11:31:59,560 - denyhosts : INFO monitoring log: /var/log/auth.log 2012-07-15 11:31:59,560 - denyhosts : INFO sync_time: 3600 2012-07-15 11:31:59,560 - denyhosts : INFO daemon_purge: 3600 2012-07-15 11:31:59,560 - denyhosts : INFO daemon_sleep: 30 2012-07-15 11:35:53,082 - denyhosts : INFO DenyHosts daemon is shutting down |
Ik zie echter niks vreemds, dus kan er niet goed de vinger achter krijgen waarom 't niet werkt.
Iemand enig idee waarom de entries niet gepurged worden?
PS /etc/hosts.deny is gewoon netjes aanwezig. Ook heb ik door meermaals verkeerd inloggen via ssh gezien dat mijn ip netjes wordt toegevoegd aan dit bestand.