From owner-freebsd-questions@FreeBSD.ORG Tue Nov 2 18:49:00 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 70A991065672 for ; Tue, 2 Nov 2010 18:49:00 +0000 (UTC) (envelope-from rfarmer@predatorlabs.net) Received: from mail-iw0-f182.google.com (mail-iw0-f182.google.com [209.85.214.182]) by mx1.freebsd.org (Postfix) with ESMTP id 2FA078FC15 for ; Tue, 2 Nov 2010 18:48:59 +0000 (UTC) Received: by iwn39 with SMTP id 39so8778176iwn.13 for ; Tue, 02 Nov 2010 11:48:59 -0700 (PDT) MIME-Version: 1.0 Received: by 10.231.37.197 with SMTP id y5mr3830760ibd.151.1288723739479; Tue, 02 Nov 2010 11:48:59 -0700 (PDT) Received: by 10.220.187.71 with HTTP; Tue, 2 Nov 2010 11:48:59 -0700 (PDT) X-Originating-IP: [128.95.133.181] In-Reply-To: References: Date: Tue, 2 Nov 2010 11:48:59 -0700 Message-ID: From: Rob Farmer To: "Justin V." Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Cc: freebsd-questions@freebsd.org Subject: Re: SSHgaurd and PF X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Nov 2010 18:49:00 -0000 On Tue, Nov 2, 2010 at 11:42, Justin V. wrote: > So i added this: > > auth.info;authpriv.info;ftp.info =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0/var/log/= auth.log > > > This is existing: > > ftp.info =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 = =A0 =A0 =A0 =A0/var/log/xferlog > > > > > I see my failed attempts going to auth.log and sshguard is still not > blocking or logging.. > > I restarted both syslog and sshguard.. I feel like we are almost there > > > thanks, > > jv Great - then try: ftp.info |exec /usr/local/sbin/sshguard in your /etc/syslog.conf (don't forget to restart syslog) and it should be working - I'm not sure what the threshold for sshguard to block someone is, but you could test it - just make sure you have a way to get back in if it works and your IP is blocked (or wait for the next script kiddie). --=20 Rob Farmer