<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>21869</bug_id>
          
          <creation_ts>2009-10-08 02:15:39 +0400</creation_ts>
          <short_desc>несоответствие формату лога</short_desc>
          <delta_ts>2009-10-15 00:52:30 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>sshutout</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="А. Китайкин">cetus</reporter>
          <assigned_to name="Michael Shigorin">mike</assigned_to>
          <cc>mike</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>101034</commentid>
    <comment_count>0</comment_count>
    <who name="А. Китайкин">cetus</who>
    <bug_when>2009-10-08 02:15:39 +0400</bug_when>
    <thetext>В случае атаки на sshd в лог сыплется:
Aug  2 16:42:57 cetium sshd[8294]: Unable to check blacklist for host key 09:76:b7:4a:14:6b:eb:af:4d:16:5d:f7:e0:c6:62:4a
Aug  2 16:42:57 cetium sshd[8294]: Unable to check blacklist for host key 43:14:66:71:9b:1a:69:18:18:99:65:29:43:0c:c8:1e
Aug  2 16:42:57 cetium sshd[8294]: Did not receive identification string from 221.130.128.57
Aug  2 16:47:38 cetium sshd[8322]: Unable to check blacklist for host key 09:76:b7:4a:14:6b:eb:af:4d:16:5d:f7:e0:c6:62:4a
Aug  2 16:47:38 cetium sshd[8322]: Unable to check blacklist for host key 43:14:66:71:9b:1a:69:18:18:99:65:29:43:0c:c8:1e
Aug  2 16:47:44 cetium sshd[8322]: UNKNOWN USER from 221.130.128.57
Aug  2 16:47:44 cetium sshd[8325]: input_userauth_request: UNKNOWN USER

Предусмотренные в sshutout образцы - &quot;Illegal user&quot; or &quot;Invalid user&quot; никак не кореллируют с UNKNOWN USER. Если я правильно понял назначение и приемы работы sshutout, то этот факт прекрасно объясняет отсутствие видимых результатов. 

Проверяю на скорую руку сваяный патчик, если поможет - сообщу. В случае удачи возможно, стоит добавить исправление и в конфиг.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101035</commentid>
    <comment_count>1</comment_count>
      <attachid>3970</attachid>
    <who name="А. Китайкин">cetus</who>
    <bug_when>2009-10-08 02:19:02 +0400</bug_when>
    <thetext>Created attachment 3970
Добавляет проверку наличия слов &quot;UNKNOWN USER&quot; в логе</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101557</commentid>
    <comment_count>2</comment_count>
    <who name="А. Китайкин">cetus</who>
    <bug_when>2009-10-14 23:55:23 +0400</bug_when>
    <thetext>Похоже, что да, заработало наконец. Машинка старенькая, когда ломают, так жалобно винтом скрипит, как под пилой. Теперь по логу видно, что кого-нибудь блокируют периодически, в iptables правила добавляются, и удаляются по истечении.


Oct 14 21:35:24 cetium sshd[12403]: UNKNOWN USER from 61.1.207.29
Oct 14 21:35:24 cetium sshd[12407]: input_userauth_request: UNKNOWN USER
Oct 14 21:35:24 cetium sshd[12396]: UNKNOWN USER from 61.1.207.29
Oct 14 21:35:24 cetium sshd[12399]: input_userauth_request: UNKNOWN USER
Oct 14 21:35:24 cetium sshd[12407]: Received disconnect from 61.1.207.29: 11: Bye Bye
Oct 14 21:35:24 cetium sshd[12399]: Received disconnect from 61.1.207.29: 11: Bye Bye
Oct 14 21:35:24 cetium sshd[12408]: Unable to check blacklist for host key 09:76:b7:4a:14:6b:eb:af:4d:16:5d:f7:e0:c6:62:4a
Oct 14 21:35:24 cetium sshd[12408]: Unable to check blacklist for host key 43:14:66:71:9b:1a:69:18:18:99:65:29:43:0c:c8:1e
Oct 14 21:35:24 cetium sshd[12411]: Unable to check blacklist for host key 09:76:b7:4a:14:6b:eb:af:4d:16:5d:f7:e0:c6:62:4a
Oct 14 21:35:24 cetium sshd[12411]: Unable to check blacklist for host key 43:14:66:71:9b:1a:69:18:18:99:65:29:43:0c:c8:1e
Oct 14 21:35:26 cetium sshutout[5580]: Squelching attack from 61.1.207.29 (30 ssh login attempts) for 36000 seconds.
Oct 14 21:35:26 cetium sshd[12408]: UNKNOWN USER from 61.1.207.29
Oct 14 21:35:26 cetium sshd[12411]: UNKNOWN USER from 61.1.207.29
Oct 14 21:35:26 cetium sshd[12415]: input_userauth_request: UNKNOWN USER
Oct 14 21:35:26 cetium sshd[12414]: input_userauth_request: UNKNOWN USER</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101558</commentid>
    <comment_count>3</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2009-10-15 00:52:30 +0400</bug_when>
    <thetext>sshutout-1.0.5-alt3 -&gt; sisyphus:

* Wed Oct 14 2009 Michael Shigorin &lt;mike@altlinux&gt; 1.0.5-alt3

- applied patch by A.Kitouwaykin &lt;cetus newmail ru&gt; to add
  &quot;UNKNOWN USER&quot; pattern recognition (closes: #21869)
- minor spec cleanup</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3970</attachid>
            <date>2009-10-08 02:19:02 +0400</date>
            <delta_ts>2009-10-08 02:19:02 +0400</delta_ts>
            <desc>Добавляет проверку наличия слов &quot;UNKNOWN USER&quot; в логе</desc>
            <filename>sshutout-1.0.5-alt-UNKNOWN-USER.patch</filename>
            <type>text/plain</type>
            <size>622</size>
            <attacher name="А. Китайкин">cetus</attacher>
            
              <data encoding="base64">LS0tIHNzaHV0b3V0LTEuMC41L3NzaHV0b3V0LmN+CTIwMDktMTAtMDggMDE6Mzk6MzIgKzA0MDAK
KysrIHNzaHV0b3V0LTEuMC41L3NzaHV0b3V0LmMJMjAwOS0xMC0wOCAwMTo0NDoxOSArMDQwMApA
QCAtOTkyLDcgKzk5Miw4IEBACiAgICAgICAgICAgICAgICAgICAgICAgICAvKiBDaGVjayBmb3Ig
bG9naW4gZmFpbHVyZSBvciBpbGxlZ2FsL2ludmFsaWQgdXNlciAqLwogICAgICAgICAgICAgICAg
ICAgICAgICAgaWYgKHN0cm5jbXAobXNnLCAiRmFpbGVkIiwgNikgJiYKICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAhc3Ryc3RyKG1zZywgImVycm9yOiBQQU06IikgJiYKLQkJCSAgICAoIWls
bGVnYWxfdXNlciB8fCAoc3RybmNtcChtc2csICJJbGxlZ2FsIHVzZXIiLCAxMikgJiYgc3RybmNt
cChtc2csICJJbnZhbGlkIHVzZXIiLCAxMikpKSkgeyAKKwkJCSAgICAoIWlsbGVnYWxfdXNlciB8
fCAoc3RybmNtcChtc2csICJsbGVnYWwgdXNlciIsIDEyKSAmJiBzdHJuY21wKG1zZywgIkludmFs
aWQgdXNlciIsIDEyKSAKKwkJCQkJICAgICAgICYmIHN0cm5jbXAobXNnLCAiVU5LTk9XTiBVU0VS
IiwgMTIpKSkpIHsgCiAJCQkJYXR0ZW1wdCA9IDA7CiAJCQkJY29udGludWU7CiAJCQl9Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>