Mercurial > repos > other > Puppet
annotate modules/fail2ban/manifests/init.pp @ 295:90525117ab81
Blacklist more SSH users
Includes Italian admins, local admins, owncloud service,
and others
author | IBBoard <dev@ibboard.co.uk> |
---|---|
date | Sun, 02 Feb 2020 12:02:06 +0000 |
parents | d49def2d04ae |
children | 2f4d0ea4cb55 |
rev | line source |
---|---|
292 | 1 class fail2ban ( |
2 $firewall_cmd, | |
3 ) { | |
4 package { 'fail2ban': | |
5 ensure => installed, | |
6 } | |
7 service { 'fail2ban': | |
8 ensure => running, | |
9 enable => true | |
10 } | |
11 File<| tag == 'fail2ban' |> { | |
12 ensure => present, | |
13 require => Package['fail2ban'], | |
14 notify => Service['fail2ban'], | |
15 } | |
16 file { '/etc/fail2ban/fail2ban.local': | |
17 source => 'puppet:///modules/fail2ban/fail2ban.local', | |
18 } | |
19 file { '/etc/fail2ban/jail.local': | |
20 source => 'puppet:///modules/fail2ban/jail.local', | |
21 } | |
22 file { '/etc/fail2ban/action.d/apf.conf': | |
23 source => 'puppet:///modules/fail2ban/apf.conf', | |
24 } | |
25 | |
26 if $firewall_cmd == 'iptables' { | |
27 $firewall_ban_cmd = 'iptables-multiport' | |
28 } else { | |
29 $firewall_ban_cmd = $firewall_cmd | |
30 } | |
31 | |
32 file { '/etc/fail2ban/action.d/firewall-ban.conf': | |
33 ensure => link, | |
34 target => "/etc/fail2ban/action.d/${firewall_ban_cmd}.conf", | |
35 } | |
36 file { '/etc/fail2ban/filter.d/ibb-apache-exploits-instaban.conf': | |
37 source => 'puppet:///modules/fail2ban/ibb-apache-exploits-instaban.conf', | |
38 } | |
39 file { '/etc/fail2ban/filter.d/ibb-apache-shellshock.conf': | |
40 source => 'puppet:///modules/fail2ban/ibb-apache-shellshock.conf', | |
41 } | |
42 file { '/etc/fail2ban/filter.d/ibb-repeat-offender.conf': | |
43 source => 'puppet:///modules/fail2ban/ibb-repeat-offender.conf', | |
44 } | |
45 file { '/etc/fail2ban/filter.d/ibb-repeat-offender-ssh.conf': | |
46 source => 'puppet:///modules/fail2ban/ibb-repeat-offender-ssh.conf', | |
47 } | |
48 file { '/etc/fail2ban/filter.d/ibb-postfix-spammers.conf': | |
49 source => 'puppet:///modules/fail2ban/ibb-postfix-spammers.conf', | |
50 } | |
51 file { '/etc/fail2ban/filter.d/ibb-postfix-malicious.conf': | |
52 source => 'puppet:///modules/fail2ban/ibb-postfix-malicious.conf', | |
53 } | |
54 file { '/etc/fail2ban/filter.d/ibb-postfix.conf': | |
55 source => 'puppet:///modules/fail2ban/ibb-postfix.conf', | |
56 } | |
57 file { '/etc/fail2ban/filter.d/ibb-sshd.conf': | |
58 source => 'puppet:///modules/fail2ban/ibb-sshd.conf', | |
59 } | |
60 | |
61 $bad_users = [ | |
62 '[0-9]+', | |
63 '[0-9a-z][0-9a-z]?', | |
64 '([0-9a-z])\2{2,}', | |
65 'abc123', | |
66 'abused', | |
67 'adm', | |
68 'Admin', | |
69 'admin[0-9]+', | |
70 'administrateur', | |
71 'administracion', | |
294 | 72 'admissions', |
292 | 73 'altibase', |
74 'alumni', | |
75 'amavisd?', | |
295 | 76 'amministratore', |
292 | 77 'anwenderschnittstelle', |
78 'anonymous', | |
79 'ansible', | |
80 'aptproxy', | |
81 'arkserver', | |
82 'asterisk', | |
83 'auser', | |
84 'avahi', | |
85 'avis', | |
86 'backlog', | |
87 'backup(s|er|pc|user)?', | |
88 'bf2', | |
293
55762b436f89
Add more blacklisted SSH usernames
IBBoard <dev@ibboard.co.uk>
parents:
292
diff
changeset
|
89 'bitcoin', |
292 | 90 'bitnami', |
91 'bitrix', | |
92 'boinc', | |
93 'botmaster', | |
94 'build', | |
95 'buscador', | |
96 'cacti(user)?', | |
97 'catchall', | |
98 'cemergen', | |
99 'chef', | |
100 'cinema', | |
101 'clamav', | |
102 'cliente?[0-9]*', | |
103 'clouduser', | |
104 'com', | |
105 'comercial', | |
106 'control', | |
107 'couchdb', | |
108 'cpanel', | |
109 'create', | |
110 'cron', | |
111 '(cs(s|go|cz)|arma|mc|tf2?|sdtd|web|pz)se?rve?r?', | |
112 'cyrus[0-9]*', | |
113 'daemon', | |
114 'danger', | |
115 'debian(-spamd)?', | |
116 'default', | |
117 'dell', | |
118 'deploy(er)?', | |
119 'desktop', | |
120 'developer', | |
121 'devops', | |
122 'devteam', | |
123 'dietpi', | |
124 'django', | |
125 'dotblot', | |
126 'download', | |
127 'dovecot', | |
294 | 128 'duplicity', |
292 | 129 'easy', |
130 'ec2-user', | |
131 'edu(cation)?[0-9]*', | |
132 'e-shop', | |
293
55762b436f89
Add more blacklisted SSH usernames
IBBoard <dev@ibboard.co.uk>
parents:
292
diff
changeset
|
133 'elsearch', |
292 | 134 'engin(eer)?', |
135 'esadmin', | |
136 'events', | |
137 'exports?', | |
138 'facebook', | |
139 'factorio', | |
140 'fax', | |
141 'filter', | |
142 'firebird', | |
143 'fuser', | |
144 'games', | |
145 'gdm', | |
146 'geniuz', | |
147 'ggc_user', | |
148 'ghost', | |
149 'git(olite?|blit|lab(_ci)?)?', | |
150 'gmail', | |
294 | 151 'gmodserver', |
152 'gnuhealth', | |
292 | 153 'gopher', |
154 'guest', | |
155 'hacker', | |
156 'hadoop', | |
157 'harvard', | |
158 'helpdesk', | |
159 'home', | |
160 'host', | |
161 'httpd?', | |
294 | 162 'httpfs', |
292 | 163 'huawei', |
164 'iceuser', | |
165 'imscp', | |
166 'info(rmix)?', | |
167 'java', | |
168 'jboss', | |
169 'jenkins', | |
170 'jira', | |
171 'jsboss', | |
172 'kafka', | |
173 'kodi', | |
295 | 174 'kms', |
292 | 175 'library', |
176 'libsys', | |
177 'libuuid', | |
178 'linode', | |
179 'linux', | |
295 | 180 'localadmin', |
292 | 181 'login', |
182 'logout', | |
295 | 183 'logstash', |
292 | 184 'lynx', |
185 'mailer', | |
186 'mailman', | |
187 'maintain', | |
188 'majordomo', | |
189 'man', | |
190 'mantis', | |
191 'marketing', | |
192 'master', | |
193 'membership', | |
194 'minecraft', | |
195 'modem', | |
196 'mongo(db|user)?', | |
197 'monitor', | |
198 'more', | |
199 'moher', | |
200 'mpiuser', | |
201 'musi[ck]bot', | |
202 '(my?|pg)sq(ue)?l', | |
203 'mythtv', | |
204 'nagios', | |
205 'nasa', | |
206 'netdump', | |
207 'netzplatz', | |
208 'newadmin', | |
295 | 209 'newuser', |
292 | 210 'nexus', |
211 'nfs', | |
212 '(nfs)?nobody', | |
213 'nginx', | |
214 'noc', | |
215 'nothing', | |
216 'NpC', | |
217 'nux', | |
218 'odoo', | |
219 'odroid', | |
220 'onyxeye', | |
221 'openbravo', | |
294 | 222 'openfire', |
292 | 223 'openvpn', |
224 'operador', | |
225 'operator', | |
226 'ops(code)?', | |
227 'oprofile', | |
228 'ora(cle|prod)', | |
229 'osmc', | |
295 | 230 'owncloud', |
292 | 231 'papernet', |
232 'password', | |
233 'payments', | |
234 'pay_?pal', | |
294 | 235 'pdfbox', |
292 | 236 'pentaho', |
237 'PlcmSpIp(PlcmSpIp)?', | |
238 'popuser', | |
239 'postfix', | |
240 'postgres', | |
241 'postmaster', | |
242 'print', | |
243 'privoxy', | |
244 'proba', | |
245 'proxy', | |
295 | 246 'public', |
292 | 247 'puppet', |
248 'qhsupport', | |
249 'rabbit(mq)?', | |
250 'radiusd?', | |
251 'redis', | |
252 'redmine', | |
253 'riakcs', | |
254 'root[0-9]+', | |
255 'rpc(user)?', | |
256 'RPM', | |
257 'rtorrent', | |
258 'rustserver', | |
259 'sales[0-9]+', | |
260 's?bin', | |
295 | 261 '(samba|sshd|git|student|tomcat|abc|web|info|(vpn|appl?|my|db)?(use?r|server|manager|mgr)|account)[0-9]*', |
292 | 262 'saslauth', |
263 'scaner', | |
264 'screen', | |
265 'search', | |
266 'setup', | |
294 | 267 'serverpilot', |
292 | 268 'service', |
295 | 269 '(s|u|ams|admin|inss|pro|web)?ftp(d|_?use?r|home|_?test)?[0-9]*', |
292 | 270 'sftponly', |
271 'shell', | |
272 'shop', | |
273 'sinusbot', | |
274 'smmsp', | |
275 'socket', | |
276 'software', | |
277 'solarus', | |
278 'splunk', | |
279 'squid', | |
280 'squirrelmail', | |
281 'sshusr', | |
282 'staffc', | |
283 'steam(cmd)?', | |
284 'store', | |
285 'superuser', | |
286 'support', | |
287 'svnroot', | |
293
55762b436f89
Add more blacklisted SSH usernames
IBBoard <dev@ibboard.co.uk>
parents:
292
diff
changeset
|
288 'sybase', |
292 | 289 'sysadmin', |
290 'system', | |
291 'teamspeak3?', | |
292 'telkom', | |
293 'temp', | |
294 | 294 'test((er?|ing|ftp|man|use?r|u)[0-9]*|[0-9]+)?', |
292 | 295 '(test)?username', |
296 'text', | |
297 'tomcat', | |
298 'tools', | |
299 'toor', | |
300 'ts[23](se?rv(er)?|(musi[ck])?bot)?', | |
301 'tunstall', | |
302 'ubnt', | |
303 'ubuntu', | |
304 'upload', | |
305 'unity', | |
306 'USERID', | |
307 'user[0-9]*', | |
308 'usuario', | |
309 'uucp', | |
310 'vagrant', | |
311 'vbox', | |
312 'ventrilo', | |
313 'vhbackup', | |
314 'virusalter', | |
315 'vmadmin', | |
316 'vmail', | |
317 'vyatta', | |
318 'wanadoo', | |
319 'weblogic', | |
320 'webmaster', | |
321 'WinD3str0y', | |
322 'wine', | |
323 'wp-?user', | |
324 'write', | |
325 'www', | |
326 '(www|web|coin|fax|sys|db2|rsync|tc)-?(adm(in)?|run|user|data)', | |
327 'xbian', | |
328 'xbot', | |
329 'xoadmin', | |
330 'yahoo', | |
331 'yarn', | |
332 'zabbix', | |
333 'zimbra', | |
334 'zookeeper', | |
335 '0fordn1on@#\$%%\^&', | |
336 'P@\$\$w0rd', | |
337 'pass123?4?' | |
338 ] | |
339 | |
340 file { '/etc/fail2ban/filter.d/ibb-sshd-bad-user.conf': | |
341 content => epp('fail2ban/ibb-sshd-bad-user.epp', { 'bad_users' => $bad_users }), | |
342 } | |
343 # Because one of our rules checks fail2ban's log, but the service dies without the file | |
344 file { '/var/log/fail2ban.log': | |
345 ensure => present, | |
346 owner => 'root', | |
347 group => 'root', | |
348 mode => '0600', | |
349 } | |
350 } |