为了为 xrdp 攻击配置 fail2ban,我需要一些正则表达式的帮助。
在/var/log/xrdp.log
我可以看到:
[20201229-12:24:42] [INFO ] Socket 12: AF_INET6 connection received from ::ffff:82.74.118.114 port 55267
所以在jail.conf
我添加:
[rdp]
enabled = true
filter = rdp
action = iptables-multiport[name=rdp, port="3389,3390,3391", protocol=tcp]
logpath = /var/log/xrdp.log
maxretry = 5
我filter.d/rdp.conf
写道:
[Definition]
failregex = connection received from ::ffff:<HOST> port
ignoreregex =
显然我的正则表达式很糟糕......
有人能帮我吗 ?谢谢