From 112bd06c3b68e43c9dfb4f583fa9adde56bf2385 Mon Sep 17 00:00:00 2001 From: Jonas Smedegaard Date: Sat, 4 Jan 2003 00:06:56 +0000 Subject: Misc updates and improvements... --- logcheck/violations.ignore.d/temp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'logcheck/violations.ignore.d/temp') diff --git a/logcheck/violations.ignore.d/temp b/logcheck/violations.ignore.d/temp index d77bfe0..e1f6719 100644 --- a/logcheck/violations.ignore.d/temp +++ b/logcheck/violations.ignore.d/temp @@ -1,3 +1,4 @@ +(imap|samba|netatalk)\(pam_unix\)\[[0-9]+\]: authentication failure; logname= uid=0 euid=0 tty=[^[:space:]]* ruser= rhost=[^[:space:]]* user=[[:alnum:]]+$ afpd\[[0-9]+\]: afp_flushfork: of_find: Permission denied afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied afpd\[[0-9]+\]: bad function 7A @@ -7,13 +8,12 @@ afpd\[[0-9]+\]: error removing /.+/net[\.0-9]+node[0-9]+: Permission denied afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument) IMP\[[0-9]+\]: FAILED .* to .*:143 as .* i(map|pop3)d\[[0-9]+\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\] -imap\(pam_unix\)\[[0-9]+\]: authentication failure; logname= uid=0 euid=0 tty=[^[:space:]]* ruser= rhost=[^[:space:]]* user=[[:alnum:]]+$ kernel: IP_MASQ:reverse ICMP: failed checksum from .*! kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\) PAM_unix\[[0-9]+\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service portsentry\[[0-9]+\]: attackalert: .* smbd\[[0-9]+\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ ! -smbd\[[0-9]+\]: read_socket_data: recv failure for 4. Error = No route to host +smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4. Error = (No route to host|Connection reset by peer) $ smbd\[[0-9]+\]: yield_connection: tdb_delete for name failed with error Record does not exist\. sshd\[[0-9]+\]: Failed password for .* pumpd\[[0-9]+\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument -- cgit v1.2.3