Bonjour tout le monde!
Je rencontre un “problème” dans les logs de fail2ban. Je précise que je ne suis pas un grand spécialiste, tout au plus un utilisateur avisé.
Mon serveur YunoHost
Matériel: HP Envy All in One
Version de YunoHost: 4.2.5.2 (stable)
Programmes installés: NextCloud 20.0.8~ynh1 + Transmission 1.0~ynh4
J’ai accès à mon serveur: En SSH + webadmin + direct avec un clavier-écran
Êtes-vous dans un contexte particulier ou avez-vous effectué des modifications particulières sur votre instance ?: Oui et non
J’ai suivi les recommandations de sécurité de la documentation Yunohost (changement du port SSH, etc.).
Description du problème
Lors de la visualisation des logs de fail2an, je vois des WARNING Command toutes les minutes. Comme je ne comprends pas bien de quoi il s’agit, je me permets de vous solliciter.
J’ai vu dans une autre discussion que des logs de fail2ban pouvaient être provoqués par Monitorix, que j’ai désinstallé avant de relancer fail2ban. Et j’ai donc ces logs:
2021-06-02 10:14:46,975 fail2ban.server [618]: INFO Exiting Fail2ban
2021-06-02 10:14:47,218 fail2ban.server [28231]: INFO --------------------------------------------------
2021-06-02 10:14:47,218 fail2ban.server [28231]: INFO Starting Fail2ban v0.10.2
2021-06-02 10:14:47,248 fail2ban.database [28231]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2021-06-02 10:14:47,309 fail2ban.jail [28231]: INFO Creating new jail 'sshd'
2021-06-02 10:14:47,359 fail2ban.jail [28231]: INFO Jail 'sshd' uses pyinotify {}
2021-06-02 10:14:47,361 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,362 fail2ban.filter [28231]: INFO maxLines: 1
2021-06-02 10:14:47,379 fail2ban.server [28231]: INFO Jail sshd is not a JournalFilter instance
2021-06-02 10:14:47,380 fail2ban.filter [28231]: INFO Added logfile: '/var/log/auth.log' (pos = 311427, hash = e2eb84d2710961df9bc1799d1ecc436b9d8fec48)
2021-06-02 10:14:47,381 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,381 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,382 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,382 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,383 fail2ban.jail [28231]: INFO Creating new jail 'nginx-http-auth'
2021-06-02 10:14:47,383 fail2ban.jail [28231]: INFO Jail 'nginx-http-auth' uses pyinotify {}
2021-06-02 10:14:47,386 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,388 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/error.log' (pos = 10564, hash = 1c455b35ba5ffbc44078766b22d6ad6e024ec324)
2021-06-02 10:14:47,389 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/funkwhale.commeuneforet.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,390 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/nextcloud.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,390 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,391 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,391 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.funkwhale.commeuneforet.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,392 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.nohost.me-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,392 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.nextcloud.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,393 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.nohost.me-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,394 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/localhost-nginx_status_monitorix.lan-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,395 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,395 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,395 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,395 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,396 fail2ban.jail [28231]: INFO Creating new jail 'postfix'
2021-06-02 10:14:47,397 fail2ban.jail [28231]: INFO Jail 'postfix' uses pyinotify {}
2021-06-02 10:14:47,399 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,407 fail2ban.server [28231]: INFO Jail postfix is not a JournalFilter instance
2021-06-02 10:14:47,407 fail2ban.filter [28231]: INFO Added logfile: '/var/log/mail.log' (pos = 275534, hash = 7ef95f92c0d55e4e0cad1d16878f63d7da9b3ede)
2021-06-02 10:14:47,408 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,408 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,408 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,408 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,409 fail2ban.jail [28231]: INFO Creating new jail 'dovecot'
2021-06-02 10:14:47,409 fail2ban.jail [28231]: INFO Jail 'dovecot' uses pyinotify {}
2021-06-02 10:14:47,412 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,418 fail2ban.datedetector [28231]: INFO date pattern `''`: `{^LN-BEG}TAI64N`
2021-06-02 10:14:47,418 fail2ban.server [28231]: INFO Jail dovecot is not a JournalFilter instance
2021-06-02 10:14:47,418 fail2ban.filter [28231]: INFO Added logfile: '/var/log/mail.log' (pos = 275534, hash = 7ef95f92c0d55e4e0cad1d16878f63d7da9b3ede)
2021-06-02 10:14:47,419 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,419 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,419 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,420 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,420 fail2ban.jail [28231]: INFO Creating new jail 'recidive'
2021-06-02 10:14:47,421 fail2ban.jail [28231]: INFO Jail 'recidive' uses pyinotify {}
2021-06-02 10:14:47,423 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,425 fail2ban.server [28231]: INFO Jail recidive is not a JournalFilter instance
2021-06-02 10:14:47,426 fail2ban.filter [28231]: INFO Added logfile: '/var/log/fail2ban.log' (pos = 3012765, hash = 95ede000ef365b400a8a7a01b080af0e7a5d76af)
2021-06-02 10:14:47,427 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,427 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,428 fail2ban.filter [28231]: INFO findtime: 86400
2021-06-02 10:14:47,428 fail2ban.actions [28231]: INFO banTime: 604800
2021-06-02 10:14:47,429 fail2ban.jail [28231]: INFO Creating new jail 'pam-generic'
2021-06-02 10:14:47,429 fail2ban.jail [28231]: INFO Jail 'pam-generic' uses pyinotify {}
2021-06-02 10:14:47,431 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,436 fail2ban.filter [28231]: INFO Added logfile: '/var/log/auth.log' (pos = 311427, hash = e2eb84d2710961df9bc1799d1ecc436b9d8fec48)
2021-06-02 10:14:47,437 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,437 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,437 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,437 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,438 fail2ban.jail [28231]: INFO Creating new jail 'nextcloud'
2021-06-02 10:14:47,438 fail2ban.jail [28231]: INFO Jail 'nextcloud' uses pyinotify {}
2021-06-02 10:14:47,441 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,443 fail2ban.filter [28231]: INFO Added logfile: '/home/yunohost.app/nextcloud/data/nextcloud.log' (pos = 5512504, hash = d31e9c27f76acba9c78f7d98449eca3c5b60143f)
2021-06-02 10:14:47,443 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,443 fail2ban.filter [28231]: INFO maxRetry: 5
2021-06-02 10:14:47,443 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,444 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,444 fail2ban.jail [28231]: INFO Creating new jail 'yunohost'
2021-06-02 10:14:47,445 fail2ban.jail [28231]: INFO Jail 'yunohost' uses pyinotify {}
2021-06-02 10:14:47,447 fail2ban.jail [28231]: INFO Initiated 'pyinotify' backend
2021-06-02 10:14:47,449 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/error.log' (pos = 10564, hash = 1c455b35ba5ffbc44078766b22d6ad6e024ec324)
2021-06-02 10:14:47,450 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/funkwhale.commeuneforet.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,450 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/nextcloud.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,451 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,451 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,452 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.funkwhale.commeuneforet.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,452 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.nohost.me-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,453 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.nextcloud.oinska.internet-box.ch-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,454 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.nohost.me-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,454 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/localhost-nginx_status_monitorix.lan-error.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,455 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/localhost-nginx_status_monitorix.lan-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,456 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/access.log' (pos = 51773, hash = 7ffb4fc1fa269ea7f8c74e379d4ebf0b0cc05b01)
2021-06-02 10:14:47,475 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/funkwhale.commeuneforet.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,476 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.funkwhale.commeuneforet.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,477 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.internet-box.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,478 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.nextcloud.oinska.internet-box.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,479 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/xmpp-upload.oinska.nohost.me-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,480 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.internet-box.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,481 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/nextcloud.oinska.internet-box.ch-access.log' (pos = 0, hash = da39a3ee5e6b4b0d3255bfef95601890afd80709)
2021-06-02 10:14:47,482 fail2ban.filter [28231]: INFO Added logfile: '/var/log/nginx/oinska.nohost.me-access.log' (pos = 430440, hash = 5d25d7e3e558284d965133c4f696a84bc04bc3b5)
2021-06-02 10:14:47,483 fail2ban.filter [28231]: INFO encoding: UTF-8
2021-06-02 10:14:47,483 fail2ban.filter [28231]: INFO maxRetry: 10
2021-06-02 10:14:47,483 fail2ban.filter [28231]: INFO findtime: 600
2021-06-02 10:14:47,483 fail2ban.actions [28231]: INFO banTime: 600
2021-06-02 10:14:47,485 fail2ban.jail [28231]: INFO Jail 'sshd' started
2021-06-02 10:14:47,486 fail2ban.jail [28231]: INFO Jail 'nginx-http-auth' started
2021-06-02 10:14:47,487 fail2ban.jail [28231]: INFO Jail 'postfix' started
2021-06-02 10:14:47,488 fail2ban.jail [28231]: INFO Jail 'dovecot' started
2021-06-02 10:14:47,489 fail2ban.jail [28231]: INFO Jail 'recidive' started
2021-06-02 10:14:47,497 fail2ban.jail [28231]: INFO Jail 'pam-generic' started
2021-06-02 10:14:47,498 fail2ban.jail [28231]: INFO Jail 'nextcloud' started
2021-06-02 10:14:47,499 fail2ban.jail [28231]: INFO Jail 'yunohost' started
Puis immédiatement après, je vois apparaître ces logs:
2021-06-02 10:15:01,482 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:15:01,708 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:16:01,631 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:16:01,855 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:17:00,787 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:17:01,008 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:18:00,922 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:18:01,146 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:19:01,067 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:19:01,288 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:20:01,211 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:20:01,437 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:21:01,352 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:21:01,577 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:22:01,501 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:22:01,726 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:23:01,657 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:23:01,881 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:24:00,817 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:24:01,043 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:25:00,957 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:25:01,184 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:26:01,102 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:26:01,324 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:27:01,245 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:27:01,470 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
2021-06-02 10:28:01,392 fail2ban.transmitter [28231]: WARNING Command ['status', 'postfix-sasl'] has failed. Received UnknownJailException('postfix-sasl')
2021-06-02 10:28:01,620 fail2ban.transmitter [28231]: WARNING Command ['status', 'sshd-ddos'] has failed. Received UnknownJailException('sshd-ddos')
Suis-je en train de me faire pirater?
Merci pour vos avis et votre aide!