| Server IP : 158.247.231.215 / Your IP : 216.73.217.84 Web Server : Apache/2.4.41 (Ubuntu) System : Linux CTMS 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64 User : www-data ( 33) PHP Version : 8.0.30 Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare, MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : ON Directory : /etc/fail2ban/filter.d/ |
Upload File : |
# Fail2Ban filter for ZNC (requires adminlog module) # # to use this module, enable the adminlog module from within ZNC and point # logpath to its logfile (e.g. /var/lib/znc/moddata/adminlog/znc.log). [DEFAULT] logtype = file [Definition] _daemon = znc # Prefix for different logtype (file, journal): # __prefix_file = (?:\[\]\s+)? __prefix_short = (?:\S+\s+%(_daemon)s\[\d+\]:)\s+ __prefix_journal = %(__prefix_short)s __prefix_line = <__prefix_<logtype>> failregex = ^%(__prefix_line)s\[[^]]+\] failed to login from <ADDR> ignoreregex = journalmatch = _SYSTEMD_UNIT=znc.service + _COMM=znc # DEV Notes: # Log format is: [<DATE+TIME>] [<USERNAME>] <ACTION> from <ADDR> # [2018-10-27 01:40:17] [girst] connected to ZNC from 1.2.3.4 # [2018-10-27 01:40:21] [girst] disconnected from ZNC from 1.2.3.4 # [2018-10-27 01:40:55] [girst] failed to login from 1.2.3.4 # # Author: Tobias Girstmair (//gir.st/)