<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comentarios en: Fail2ban filter for PHP Injection attacks</title>
	<atom:link href="http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html</link>
	<description>El blog de Buanzo y sus Secuaces</description>
	<lastBuildDate>Thu, 30 Jun 2011 18:50:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
	<item>
		<title>Por: Bharath</title>
		<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/comment-page-1#comment-2768</link>
		<dc:creator>Bharath</dc:creator>
		<pubDate>Wed, 15 Jun 2011 03:48:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.buanzo.com.ar/?p=5333#comment-2768</guid>
		<description>I love this feature, can some help me with the ignore regex for the following log entries

xxx.xxx.xxx.xxx - - [10/Jun/2011:15:20:39 +0200] &quot;GET /forums/cron.php?rand=1307712039 HTTP/1.1&quot; 200 352 &quot;http://domain.net/forums/externalredirect.php?url=http://foo.com&quot; &quot;Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.1&quot;</description>
		<content:encoded><![CDATA[<p>I love this feature, can some help me with the ignore regex for the following log entries</p>
<p>xxx.xxx.xxx.xxx &#8211; - [10/Jun/2011:15:20:39 +0200] &#8220;GET /forums/cron.php?rand=1307712039 HTTP/1.1&#8243; 200 352 &#8220;http://domain.net/forums/externalredirect.php?url=http://foo.com&#8221; &#8220;Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.1&#8243;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: sagichnich</title>
		<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/comment-page-1#comment-2689</link>
		<dc:creator>sagichnich</dc:creator>
		<pubDate>Sun, 27 Feb 2011 03:59:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.buanzo.com.ar/?p=5333#comment-2689</guid>
		<description>Nice feature, thank you. However, one need to activate the &quot;action&quot; part or fail2ban won&#039;t start.

Apache-logs on red hat based system lay at /var/log/httpd/access_log

[php-url-fopen]

enabled = true
#port    = http,https
filter  = php-url-fopen
logpath = /var/log/httpd/access_log
maxretry = 1
action   = iptables-multiport[name=PHP-fopen, port=&quot;http,https&quot;, protocol=tcp]</description>
		<content:encoded><![CDATA[<p>Nice feature, thank you. However, one need to activate the &#8220;action&#8221; part or fail2ban won&#8217;t start.</p>
<p>Apache-logs on red hat based system lay at /var/log/httpd/access_log</p>
<p>[php-url-fopen]</p>
<p>enabled = true<br />
#port    = http,https<br />
filter  = php-url-fopen<br />
logpath = /var/log/httpd/access_log<br />
maxretry = 1<br />
action   = iptables-multiport[name=PHP-fopen, port="http,https", protocol=tcp]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: watt</title>
		<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/comment-page-1#comment-2418</link>
		<dc:creator>watt</dc:creator>
		<pubDate>Tue, 13 Apr 2010 02:19:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.buanzo.com.ar/?p=5333#comment-2418</guid>
		<description>I&#039;m on ubuntu 8.04 and don&#039;t have any log files in var/www/ folder. What should I replace it with?</description>
		<content:encoded><![CDATA[<p>I&#8217;m on ubuntu 8.04 and don&#8217;t have any log files in var/www/ folder. What should I replace it with?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: Ted Roche&#8217;s weblog &#187; Adding Fail2Ban to the web site</title>
		<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/comment-page-1#comment-1537</link>
		<dc:creator>Ted Roche&#8217;s weblog &#187; Adding Fail2Ban to the web site</dc:creator>
		<pubDate>Mon, 31 Aug 2009 14:00:40 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.buanzo.com.ar/?p=5333#comment-1537</guid>
		<description>[...] came with configurations for Apache 2 and vsftpd. In their wiki, there was a HOWTO for banning PHP-based file upload attacks, something which had begun to fill the logs with [...]</description>
		<content:encoded><![CDATA[<p>[...] came with configurations for Apache 2 and vsftpd. In their wiki, there was a HOWTO for banning PHP-based file upload attacks, something which had begun to fill the logs with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: fasuto</title>
		<link>http://blogs.buanzo.com.ar/2009/04/fail2ban-filter-for-php-injection-attacks.html/comment-page-1#comment-1489</link>
		<dc:creator>fasuto</dc:creator>
		<pubDate>Wed, 22 Jul 2009 08:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.buanzo.com.ar/?p=5333#comment-1489</guid>
		<description>Creo que con tu expresion regular tambien baneas entradas legitimas donde aparezca .php?n=http://****
en el REFERER.
Por ejemplo, las entradas que vienen de google images o de banners:

xxx.xxx.xxx.xxx - - [20/Jul/2009:06:13:02 +0200] &quot;GET /xxx/index.html HTTP/1.1&quot; 200 9398 &quot;http://images.google.es/imgres?imgurl=http://www.xxxx.com/xy/imagenes/img.jpg&amp;imgrefurl=http://www.xxxx.com/xy/index.htnl&amp;usg=__pCH0q6sy06ssIsB4zJu_YYsqNZE=&amp;h=163&amp;w=227&amp;sz=44&amp;hl=es&amp;start=2&amp;um=1&amp;tbnid=hjOK7M4WBtfFHM:&amp;tbnh=78&amp;tbnw=108&amp;prev=/images%3Fq%3Dpunto%2Boro%26hl%3Des%26client%3Dfirefox-a%26rls%3Dorg.mozilla:es-ES:official%26sa%3DG%26um%3D1&quot; &quot;Mozilla/5.0 (Windows; U; Windows NT 6.0; es-ES; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1 (.NET CLR 3.5.30729)&quot;</description>
		<content:encoded><![CDATA[<p>Creo que con tu expresion regular tambien baneas entradas legitimas donde aparezca .php?n=http://****<br />
en el REFERER.<br />
Por ejemplo, las entradas que vienen de google images o de banners:</p>
<p>xxx.xxx.xxx.xxx &#8211; - [20/Jul/2009:06:13:02 +0200] &#8220;GET /xxx/index.html HTTP/1.1&#8243; 200 9398 &#8220;http://images.google.es/imgres?imgurl=http://www.xxxx.com/xy/imagenes/img.jpg&amp;imgrefurl=http://www.xxxx.com/xy/index.htnl&amp;usg=__pCH0q6sy06ssIsB4zJu_YYsqNZE=&amp;h=163&amp;w=227&amp;sz=44&amp;hl=es&amp;start=2&amp;um=1&amp;tbnid=hjOK7M4WBtfFHM:&amp;tbnh=78&amp;tbnw=108&amp;prev=/images%3Fq%3Dpunto%2Boro%26hl%3Des%26client%3Dfirefox-a%26rls%3Dorg.mozilla:es-ES:official%26sa%3DG%26um%3D1&#8243; &#8220;Mozilla/5.0 (Windows; U; Windows NT 6.0; es-ES; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1 (.NET CLR 3.5.30729)&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

