# Ansible controlled filename: /etc/fail2ban/filter.d/20_example-blns.filter # Source: ansible bgstack15-fail2ban/files/example-blns.filter # Date: 2016-04-19 # Reference: # NOTE: This file is managed via Ansible: manual changes will be lost [Definition] failregex = ^.*.*(GET|POST).*/etc/passwd.*$ ^.*.*(GET|POST).*/etc/group.*$ ^.*.*(GET|POST).*/etc/hosts.*$ ^.*.*(GET|POST).*/proc/self/environ.*$ ^.*.*(GET|POST).*(?i)admin.*admin.*$ ^.*.*(GET|POST).*(?i)(php|db|pma|web|sql).*admin.*$ ^.*.*(GET|POST).*(?i)admin.*(php|db|pma|web|sql).*$ ^.*.*(GET|POST).*(?i)DELETE_comment.*$ ^.*.*(GET|POST).*(?i)pma/scripts.*setup.*$ ^.*.*(GET|POST).*(?i)pma([0-9]{4})?/? HTTP.*$ ^.*.*(GET|POST).*(?i)(database|myadmin|mysql)/? HTTP.*$ ^.*.*(GET|POST).*(?i)(dbweb|webdb|websql|sqlweb).*$ ^.*.*(GET|POST).*(?i)(my)?sql.*manager.*$ ^.*.*(GET|POST).*(?i)wp-(admin|login|signup|config).*$ ^.*.*(GET|POST).*president/.*wp-cron\.php*$ ^.*.*(GET|POST).*w00t.*blackhats.*$ ^.*.*(GET|POST).*\+\+liker.profile_URL\+\+.*$ ^.*.*(GET|POST).*muieblackcat.*$ ^.*.*(GET|POST).*(?i)ldlogon.*$ ^.*.*(GET|POST).*(?i)\.cobalt$ ^.*.*(GET|POST).*(?i)\.intruvert\/jsp\/admin\/Login\.jsp$ ^.*.*(GET|POST).*(?i)MSWSMTP\/Common\/Authentication\/Logon\.aspx$ ^.*.*(GET|POST).*(?i)php\?password=[0-9]*\&re_password=.*\&login=var.*$ ignoreregex =