• Apache error_log

    [Sun Sep 06 15:05:08 2015] [error] [client 83.237.214.191] client denied by server configuration: /var/www/vhosts/ittechinfo.ru/httpdocs/wp-content/plugins/easy-responsive-tabs/assets/js/ert_js.php, referer: http://ittechinfo.ru/category/%d0%bd%d0%be%d0%b2%d0%be%d1%81%d1%82%d0%b8/

    Fail2ban blocks users based on rules

    Rules

    [plesk-apache]
    enabled = false
    filter = apache-auth
    action = iptables-multiport[name=apache, port="http,https,7080,7081"]
    logpath = /var/www/vhosts/system/*/logs/error_log
    /var/log/httpd/*error_log
    maxretry = 6

    Filter

    before = apache-common.conf
    
    [Definition]
    
    failregex = ^%(_apache_error_client)s (AH01797: )?client denied by server configuration: (uri )?\S*(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01617: )?user .*? authentication failure for "\S*": Password Mismatch(, referer: \S+)?$
                ^%(_apache_error_client)s (AH01618: )?user .*? not found(: )?\S*(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01614: )?client used wrong authentication scheme: \S*(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH\d+: )?Authorization of user \S+ to access \S* failed, reason: .*$
                ^%(_apache_error_client)s (AH0179[24]: )?(Digest: )?user .*?: password mismatch: \S*(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH0179[01]: |Digest: )user <code>.*?' in realm</code>.+' (not found|denied by provider): \S*(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01631: )?user .*?: authorization failure for "\S*":(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01775: )?(Digest: )?invalid nonce .* received - length is not \S+(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01788: )?(Digest: )?realm mismatch - got <code>.*?' but expected</code>.+'(, referer: \S+)?\s*$
                ^%(_apache_error_client)s (AH01789: )?(Digest: )?unknown algorithm

    .*?’ received: \S*(, referer: \S+)?\s*$
    ^%(_apache_error_client)s (AH01793: )?invalid qop `.*?’ received: \S*(, referer: \S+)?\s*$
    ^%(_apache_error_client)s (AH01777: )?(Digest: )?invalid nonce .*? received – user attempted time travel(, referer: \S+)?\s*$

    ignoreregex = `

    https://ww.wp.xz.cn/plugins/easy-responsive-tabs/

The topic ‘Fail2Ban block plugin’ is closed to new replies.