summaryrefslogtreecommitdiff
path: root/logcheck/ignore.d.server/tmp
blob: 009a3d069b7cc46433ce7388380088f8660a1d32 (plain)
  1. IMP\[.*\]: FAILED .* to .*:143 as .*
  2. PAM_unix\[.*\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service
  3. afpd\[.*\]: uams_dhx_pam\.c :PAM: PAM (Auth OK!|Success -- .*|User entered a null value -- .*)
  4. afpd\[.*\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument)
  5. afpd\[.*\]: uams_dhx_pam\.c :PAM: PAM: User entered a null value -- No such file or directory
  6. afpd\[.*\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied
  7. afpd\[.*\]: bad function 7A
  8. atalkd\[.*\]: as_timer sendto: Netvaerket er ikke tilgaengeligt
  9. FaxGetty\[.*\]: ANSWER: Can not lock modem device
  10. gnome-name-server\[.*\]: server_is_alive: .*
  11. i(map|pop3)d\[.*\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\]
  12. ipppd\[.*\]: Connect\[0\]: /dev/ippp[[:digit:]], fd: 12
  13. kernel: Disorder[[:digit:]] [[:digit:]] [[:digit:]] f[[:digit:]] s[[:digit:]] rr[[:digit:]]
  14. kernel: IP_MASQ:reverse ICMP: failed checksum from .*!
  15. kernel: OPEN: [\.[:digit:]]* -> [\.[:digit:]]* UDP, port: [[:digit:]]* -> [[:digit:]]*
  16. kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\)
  17. kernel: Undo( partial)? (Hoe|loss|retrans)
  18. named\[.*\]: sysquery: findns error \(NXDOMAIN\) on dns\.homebase\.dk\?
  19. named\[.*\]: rcvd NOTIFY\(163.97.195\.in-addr\.arpa, IN, SOA\) from \[195\.97\.163\.2\]\.[[:digit:]]+
  20. named\[.*\]: rcvd NOTIFY for "163\.97\.195\.in-addr\.arpa", name not one of our zones
  21. ntpd\[.*\]: synchronisation lost
  22. ntpd\[.*\]: synchronisation lost
  23. ntpd\[.*\]: time reset [\.[:digit:]-]* .
  24. ntpd\[.*\]: time reset [\.[:digit:]-]+ s
  25. portsentry\[.*\]: attackalert: .*
  26. pumpd\[.*\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument
  27. smbd\[.*\]: read_socket_data: recv failure for 4. Error = No route to host
  28. smbd\[.*\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ !
  29. smbd\[.*\]: yield_connection: tdb_delete for name failed with error Record does not exist\.
  30. smbd\[.*\]: \[.*\] smbd/connection.c:yield_connection\([[:digit:]]+\)
  31. smbd\[.*\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([[:digit:]]+\)
  32. sshd\[.*]: Failed password for .*
  33. sshd\[.*\]: packet_set_maxsize: setting to 4096
  34. dhcpd-2.2.x: BOOTREQUEST from 00:20:6b:18:20:35
  35. dhcpd-2.2.x: No applicable record for BOOTP host 00:20:6b:18:20:35
  36. postfix.*\[.*\]: .* from=<groove@mailomat.grooveattack.com>
  37. snort: FrontPage-
  38. snort: IDS015 - RPC - portmap-request-status:
  39. snort: IDS029 - SCAN-Possible Queso Fingerprint attempt:
  40. snort: IDS115 - MISC-Traceroute-UDP:
  41. snort: IDS212 - MISC - DNS Zone Transfer:
  42. snort: IDS226 - CVE-1999-0172 - CGI-formmail:
  43. snort: IDS246 - MISC - Large ICMP Packet:
  44. snort: IIS-
  45. snort: MISC-Attempted Sun RPC high port access:
  46. snort: NETBIOS-SMB-C:
  47. snort: NETBIOS-SMB-CD...:
  48. snort: NMAP TCP ping!:
  49. snort: RPC Info Query:
  50. snort: SCAN-SYN FIN:
  51. snort: spp_http_decode: IIS Unicode attack detected:
  52. snort: spp_portscan: End of portscan
  53. snort: spp_portscan: PORTSCAN DETECTED
  54. snort: spp_portscan: portscan status from
  55. snort: WEB-../..:
  56. snort: WEB-CGI-upload.pl:
  57. postgres\[.*\]: \[.*\] DEBUG:
  58. postgres\[.*\]: \[[:digit:]-\] ^ITotal CPU .* sec elapsed .* sec\.