diff options
author | Hendrik Jäger <hendrik@securosys.ch> | 2020-01-05 17:37:23 +0200 |
---|---|---|
committer | Hendrik Jäger <hendrik@securosys.ch> | 2020-01-05 17:37:23 +0200 |
commit | a71c67a64203924a9ca4febc34d343ee05b36607 (patch) | |
tree | 006748a4d09b30510f4178aea21095e206a4d43e /files/etc/logcheck | |
parent | 4b46a74a4435bd5cc6303f60a9afef40d5c6714e (diff) |
Update logcheck rules for nftables
Diffstat (limited to 'files/etc/logcheck')
-rw-r--r-- | files/etc/logcheck/ignore.d.server/local-nftables | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/files/etc/logcheck/ignore.d.server/local-nftables b/files/etc/logcheck/ignore.d.server/local-nftables index 57462a0..ec83f47 100644 --- a/files/etc/logcheck/ignore.d.server/local-nftables +++ b/files/etc/logcheck/ignore.d.server/local-nftables @@ -1,5 +1,6 @@ -^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Bruteforce attack: IN=[[:alnum:].]+ OUT= MAC=[[:xdigit:]:]+ SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP|132) SPT=[[:digit:]]+ DPT=[[:digit:]]+ (WINDOW=[[:digit:]]+ RES=0x[[:digit:]]+ (CWR )?(ECE )?(SYN|ACK|RST) (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)$ +^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Bruteforce attack: IN=[[:alnum:].]+ OUT= MAC=[[:xdigit:]:]+ SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP|132) SPT=[[:digit:]]+ DPT=[[:digit:]]+ (WINDOW=[[:digit:]]+ RES=0x[[:digit:]]+ (CWR )?(ECE )?(SYN|ACK|RST)+ (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)$ ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Blackholing: IN=[[:alnum:].]+ OUT= MAC=[[:xdigit:]:]+ SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP|132) SPT=[[:digit:]]+ DPT=[[:digit:]]+ (WINDOW=[[:digit:]]+ RES=0x[[:digit:]]+ (CWR )?(ECE )?(SYN|ACK|RST) (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)$ ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Illegal incoming traffic: IN=[[:alnum:].]+ OUT= MAC=[[:xdigit:]:]* SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP|132) SPT=[[:digit:]]+ DPT=[[:digit:]]+ (WINDOW=[[:digit:]]+ RES=0x[[:xdigit:]]+ (CWR )?(ECE )?(URG )?(SYN|ACK|RST)+ (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)$ ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Illegal forwarding traffic: IN=[[:alnum:].]+ OUT=[[:alnum:].]+ MACSRC=[[:xdigit:]:]* MACDST=[[:xdigit:]:]* MACPROTO=[[:xdigit:]:]* SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP|132) SPT=[[:digit:]]+ DPT=[[:digit:]]+( SEQ=[[:digit:]]+ ACK=[[:digit:]]+)? (WINDOW=[[:digit:]]+ RES=0x[[:xdigit:]]+ (CWR )?(ECE )?(SYN|ACK|RST) (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)( OPT \([[:xdigit:]]+\))?$ ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Illegal forwarding traffic: IN=[[:alnum:].]+ OUT=[[:alnum:].]+ MACSRC=[[:xdigit:]:]* MACDST=[[:xdigit:]:]* MACPROTO=[[:xdigit:]:]* SRC=[[:xdigit:]:.]+ DST=[[:xdigit:]:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=ICMPv6 TYPE=1 CODE=4 \[SRC=[[:xdigit:]:]+ DST=[[:xdigit:]:]+ LEN=[[:digit:]]+ TC=0 HOPLIMIT=[[:digit:]]+ FLOWLBL=0 PROTO=(TCP|UDP) SPT=[[:digit:]]+ DPT=[[:digit:]]+( SEQ=[[:digit:]]+ ACK=[[:digit:]]+)? (WINDOW=[[:digit:]]+ RES=0x[[:xdigit:]]+ (CWR )?(ECE )?(SYN|ACK|RST) (PSH )?(FIN )?URGP=[[:digit:]]+|LEN=[[:digit:]]+)( OPT \([[:xdigit:]]+\))? \]$ + |