Skip to content

root-ubuntu: exempt only SSH peers that actually logged in - #109

Merged
ralyodio merged 1 commit into
masterfrom
fix/f2b-authenticated-peers
Sep 25, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/f2b-authenticated-peers

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Follow-up to #107, from rolling it out to dev2.

  • _fail2ban_ssh_peers added every established sshd connection to ignoreip. A brute-forcer in the middle of an attempt holds one too, so it could be exempted permanently. A peer now counts only if sshd logged Accepted … from <ip> for it (auth.log, or the journal on a box without it). On dev2 the peer it picked up was 164.92.111.224 = scan.crawlproof.com logging in by key, so nothing bad got through; the hole was real regardless.
  • The "sshd jail is not loaded" warning fired a split second after the restart while fail2ban was still starting. It now waits up to 10s first.

Tests: new "connected but never logged in is not exempted" case, and the ignoreip test now needs Accepted lines, including keyboard-interactive/pam. 184/184.

🤖 Generated with Claude Code

_fail2ban_ssh_peers took every established connection to sshd, and a
brute-forcer mid-attempt holds one too, so it could be written into
ignoreip for good. A peer now counts only if sshd logged 'Accepted ...
from' it (auth.log, or the journal without one).

Also wait up to 10s for the sshd jail after a restart before warning
it did not load: the first rollout warned while fail2ban was still
starting.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

25 finding(s)

HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9

Severity Rule Location
HIGH sh-remote-script-execution root-ubuntu.sh:3236
HIGH sh-remote-script-execution root-ubuntu.sh:3237
HIGH sh-remote-script-execution root-ubuntu.sh:5071
HIGH sh-remote-script-execution root-ubuntu.sh:5075
MEDIUM sql-template-interpolation dev2/dev2-site:754
MEDIUM sql-template-interpolation dev2/dev2-site:831
MEDIUM sh-remote-script-execution root-ubuntu.sh:5248
MEDIUM redos-nested-quantifier src/domain-free.ts:56
MEDIUM redos-nested-quantifier src/emoji.ts:167
MEDIUM redos-nested-quantifier src/icon.ts:166
MEDIUM redos-nested-quantifier src/mail.ts:1042
MEDIUM sql-template-interpolation src/users-dump.ts:487
MEDIUM sql-string-concatenation src/users-dump.ts:507
MEDIUM sql-template-interpolation src/users-dump.ts:540
MEDIUM sql-string-concatenation src/users-dump.ts:574
MEDIUM redos-nested-quantifier src/wcag.ts:556
LOW secret-generic-credential src/credentials.ts:36
LOW secret-generic-credential src/user-export.ts:632
LOW secret-generic-credential src/user-export.ts:638
LOW secret-generic-api-key test/credentials.test.ts:208
LOW secret-generic-credential test/mail.test.ts:141
LOW secret-generic-credential test/shorten.test.ts:36
LOW secret-database-url test/users-dump.test.ts:108
LOW secret-database-url test/users-dump.test.ts:119
LOW secret-database-url test/users-dump.test.ts:120

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 3728536 into master Sep 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant