From 20cb29c2f8c5c87bc590896854a20b1473ceb358 Mon Sep 17 00:00:00 2001 From: "info@mode42.com" Date: Sat, 8 Aug 2026 03:54:55 +0000 Subject: #2 --- share/fail2ban/filter.d/hybbx-circuit.conf | 10 ++++++++++ share/fail2ban/filter.d/hybbx-ssh.conf | 11 +++++++++++ share/fail2ban/filter.d/hybbx-telnet.conf | 10 ++++++++++ share/fail2ban/filter.d/hybbx-websocket.conf | 11 +++++++++++ 4 files changed, 42 insertions(+) create mode 100644 share/fail2ban/filter.d/hybbx-circuit.conf create mode 100644 share/fail2ban/filter.d/hybbx-ssh.conf create mode 100644 share/fail2ban/filter.d/hybbx-telnet.conf create mode 100644 share/fail2ban/filter.d/hybbx-websocket.conf (limited to 'share/fail2ban/filter.d') diff --git a/share/fail2ban/filter.d/hybbx-circuit.conf b/share/fail2ban/filter.d/hybbx-circuit.conf new file mode 100644 index 0000000..901e8a2 --- /dev/null +++ b/share/fail2ban/filter.d/hybbx-circuit.conf @@ -0,0 +1,10 @@ +# HyBBX HBX circuit link authentication failures (security.log). +# Matches failed LINK_AUTH on [circuit] port (default 7323). + +[INCLUDES] +before = common.conf + +[Definition] +_daemon = hybbx +failregex = ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2} link_auth_fail ip= .*transport=circuit +ignoreregex = diff --git a/share/fail2ban/filter.d/hybbx-ssh.conf b/share/fail2ban/filter.d/hybbx-ssh.conf new file mode 100644 index 0000000..407be52 --- /dev/null +++ b/share/fail2ban/filter.d/hybbx-ssh.conf @@ -0,0 +1,11 @@ +# HyBBX SSH transport login brute-force (security.log). +# Enable when [transport.ssh] is running and logs login_fail +# with transport=ssh to security.log. + +[INCLUDES] +before = common.conf + +[Definition] +_daemon = hybbx +failregex = ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2} login_fail ip= user=.* transport=ssh +ignoreregex = diff --git a/share/fail2ban/filter.d/hybbx-telnet.conf b/share/fail2ban/filter.d/hybbx-telnet.conf new file mode 100644 index 0000000..f6dfa53 --- /dev/null +++ b/share/fail2ban/filter.d/hybbx-telnet.conf @@ -0,0 +1,10 @@ +# HyBBX telnet login brute-force (security.log). +# Install: copy to /etc/fail2ban/filter.d/ and enable hybbx-telnet in jail.d. + +[INCLUDES] +before = common.conf + +[Definition] +_daemon = hybbx +failregex = ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2} login_fail ip= user=.* transport=telnet +ignoreregex = diff --git a/share/fail2ban/filter.d/hybbx-websocket.conf b/share/fail2ban/filter.d/hybbx-websocket.conf new file mode 100644 index 0000000..2166ee7 --- /dev/null +++ b/share/fail2ban/filter.d/hybbx-websocket.conf @@ -0,0 +1,11 @@ +# HyBBX WebSocket transport login brute-force (security.log). +# Enable when [transport.websocket] is running and logs login_fail +# with transport=websocket to security.log. + +[INCLUDES] +before = common.conf + +[Definition] +_daemon = hybbx +failregex = ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2} login_fail ip= user=.* transport=websocket +ignoreregex = -- cgit v1.3.1