summaryrefslogtreecommitdiff
path: root/logcheck/ignore.d.server
diff options
context:
space:
mode:
authorJonas Smedegaard <dr@jones.dk>2005-08-05 09:34:26 +0000
committerJonas Smedegaard <dr@jones.dk>2005-08-05 09:34:26 +0000
commite4f125330b261f4c76770c735482df5ce794a9c6 (patch)
tree9928e729c4c4dc5cc979a76b1d0d2e2792aa948f /logcheck/ignore.d.server
parent16413e543d8a7b7351377f16680fa2e93c67e0a7 (diff)
Ignore illegal ssh users (script-kiddie attacks).
Diffstat (limited to 'logcheck/ignore.d.server')
-rw-r--r--logcheck/ignore.d.server/ssh3
1 files changed, 3 insertions, 0 deletions
diff --git a/logcheck/ignore.d.server/ssh b/logcheck/ignore.d.server/ssh
index d64d593..56e072a 100644
--- a/logcheck/ignore.d.server/ssh
+++ b/logcheck/ignore.d.server/ssh
@@ -9,3 +9,6 @@
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: refused connect from .*
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: Received disconnect from [\.0-9]+: 11: Disconnect requested by Windows SSH Client.$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: subsystem request for sftp$
+
+# Cracking attempts are too common, so clutters more than it helps to warn about them
+^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: (Failed password from illegal|Illegal) user [[:alnum:]]+ from [\.0-9]+ port [0-9]+( ssh2)?$