changeset 305:38e35360a390

Blacklist hive, polkitd, cinstall and more as SSH logins
author IBBoard <dev@ibboard.co.uk>
date Thu, 20 Feb 2020 16:57:09 +0000
parents 0e268a4553f8
children 894390fdd6d7
files modules/fail2ban/manifests/init.pp
diffstat 1 files changed, 8 insertions(+), 4 deletions(-) [+]
line wrap: on
line diff
--- a/modules/fail2ban/manifests/init.pp	Tue Feb 18 21:08:35 2020 +0000
+++ b/modules/fail2ban/manifests/init.pp	Thu Feb 20 16:57:09 2020 +0000
@@ -90,7 +90,7 @@
 		'bash',
 		'beagleindex',
 		'bf2',
-		'bitbucket',
+		'.*bitbucket',
 		'bitcoin',
 		'bitnami',
 		'bitrix',
@@ -109,6 +109,7 @@
 		'cgi',
 		'chromeuser',
 		'cinema',
+		'cinstall',
 		'cisco',
 		'clamav',
 		'cliente?[0-9]*',
@@ -189,6 +190,7 @@
 		'hduser',
 		'headmaster',
 		'helpdesk',
+		'hive',
 		'home',
 		'host',
 		'httpd?',
@@ -238,6 +240,7 @@
 		'membership',
 		'messagebus',
 		'minecraft',
+		'mirc',
 		'modem',
 		'mongo(db|user)?',
 		'monitor(ing)?',
@@ -296,6 +299,7 @@
 		'platform',
 		'PlcmSpIp(PlcmSpIp)?',
 		'plex',
+		'polkitd?',
 		'popd?3?',
 		'popuser',
 		'postfix',
@@ -334,9 +338,9 @@
 		'screen',
 		'search',
 		'sekretariat',
-		'setup',
 		'serverpilot',
 		'service',
+		'setup',
 		'(s|u|ams|admin|inss|pro|web)?ftp(d|[_-]?use?r|home|_?test|immo)?[0-9]*',
 		'sftponly',
 		'shell',
@@ -366,11 +370,11 @@
 		'sync[0-9]*',
 		'sysadmin',
 		'system',
-		'teamspeak[23]?(-?use?r)?',
+		'teamspeak[234]?(-?use?r)?',
 		'telkom',
 		'telnetd?',
 		'te?mp(use?r)?[0-9]*',
-		'test((er?|ing|ftp|man|use?r|u)[0-9]*|[0-9]+)?',
+		'test((er?|ing|ftp|man|linux|use?r|u)[0-9]*|[0-9]+)?',
 		'(test)?username',
 		'text',
 		'tomcat',