diff --git a/filters/ssh.preg b/filters/ssh.preg index 7a90a18..e675875 100644 --- a/filters/ssh.preg +++ b/filters/ssh.preg @@ -1,19 +1,17 @@ # set: defscore=15 -Invalid user [[:print:]]+ from -Postponed keyboard-interactive for invalid user [[:print:]]+ from port [0-9]+ -Failed password for invalid user .* from +User [[:print:]]+ from not allowed because listed in DenyUsers +User [[:print:]]+ from not allowed because a group is listed in DenyGroups # set: defscore=10 -[Aa]uthentication failure for .* from ( via [[:print:]]*)? -[Aa]uthentication error for .* from ( via [[:print:]]*)? -User not known to the underlying authentication module for .* from -Failed password for .* from -refused connect from [[:print:]]+ \(\) -Received disconnect from : [0-9]*: [[:print:]]+: Auth fail User [[:print:]]+ from not allowed because not listed in AllowUsers -User [[:print:]]+ from not allowed because listed in DenyUsers User [[:print:]]+ from not allowed because not in any group -User [[:print:]]+ from not allowed because a group is listed in DenyGroups User [[:print:]]+ from not allowed because none of user's groups are listed in AllowGroups +[Aa]uthentication failure for .* from ( via [[:print:]]*)? +[Aa]uthentication error for .* from ( via [[:print:]]*)? +Failed password for .* from # set: defscore=5 +User not known to the underlying authentication module for .* from +Invalid user [[:print:]]+ from +# set: defscore=3 +refused connect from [[:print:]]+ \(\) Did not receive identification string from Connection closed by ( port [0-9]+)? \[preauth\]