From 4388ba50d234050f289d109078cf3294bfb5e17e Mon Sep 17 00:00:00 2001 From: Alex 'AdUser' Z Date: Wed, 26 May 2021 11:08:19 +1000 Subject: [PATCH] * tune filters --- filters/ssh.preg | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/filters/ssh.preg b/filters/ssh.preg index ce2d79d..7a90a18 100644 --- a/filters/ssh.preg +++ b/filters/ssh.preg @@ -1,15 +1,19 @@ +# set: defscore=15 +Invalid user [[:print:]]+ from +Postponed keyboard-interactive for invalid user [[:print:]]+ from port [0-9]+ +Failed password for invalid user .* from +# set: defscore=10 [Aa]uthentication failure for .* from ( via [[:print:]]*)? [Aa]uthentication error for .* from ( via [[:print:]]*)? User not known to the underlying authentication module for .* from Failed password for .* from refused connect from [[:print:]]+ \(\) Received disconnect from : [0-9]*: [[:print:]]+: Auth fail -Did not receive identification string from -Invalid user [[:print:]]+ from -Connection closed by ( port [0-9]+)? \[preauth\] -Postponed keyboard-interactive for invalid user [[:print:]]+ from port [0-9]+ User [[:print:]]+ from not allowed because not listed in AllowUsers User [[:print:]]+ from not allowed because listed in DenyUsers User [[:print:]]+ from not allowed because not in any group User [[:print:]]+ from not allowed because a group is listed in DenyGroups User [[:print:]]+ from not allowed because none of user's groups are listed in AllowGroups +# set: defscore=5 +Did not receive identification string from +Connection closed by ( port [0-9]+)? \[preauth\]