diff --git a/libipm/scp.c b/libipm/scp.c index e218ee3e..4e1426a3 100644 --- a/libipm/scp.c +++ b/libipm/scp.c @@ -159,16 +159,18 @@ scp_msg_in_start(struct trans *trans) int scp_send_gateway_request(struct trans *trans, const char *username, - const char *password) + const char *password, + const char *connection_description) { int rv; rv = libipm_msg_out_simple_send( trans, (int)E_SCP_GATEWAY_REQUEST, - "ss", + "sss", username, - password); + password, + connection_description); /* Wipe the output buffer to remove the password */ libipm_msg_out_erase(trans); @@ -181,12 +183,14 @@ scp_send_gateway_request(struct trans *trans, int scp_get_gateway_request(struct trans *trans, const char **username, - const char **password) + const char **password, + const char **connection_description) { /* Make sure the buffer is cleared after processing this message */ libipm_set_flags(trans, LIBIPM_E_MSG_IN_ERASE_AFTER_USE); - return libipm_msg_in_parse(trans, "ss", username, password); + return libipm_msg_in_parse(trans, "sss", username, password, + connection_description); } /*****************************************************************************/ diff --git a/libipm/scp.h b/libipm/scp.h index 33a5d986..7984a7b6 100644 --- a/libipm/scp.h +++ b/libipm/scp.h @@ -150,6 +150,7 @@ scp_msg_in_reset(struct trans *trans); * @param trans SCP transport * @param username Username * @param password Password + * @param connection_description Description of the connection * @return != 0 for error * * Server replies with E_SCP_GATEWAY_RESPONSE @@ -157,7 +158,8 @@ scp_msg_in_reset(struct trans *trans); int scp_send_gateway_request(struct trans *trans, const char *username, - const char *password); + const char *password, + const char *connection_description); /** * Parse an incoming E_SCP_GATEWAY_REQUEST message (SCP server) @@ -165,12 +167,14 @@ scp_send_gateway_request(struct trans *trans, * @param trans SCP transport * @param[out] username Username * @param[out] password Password + * @param[out] connection_description Description of the connection * @return != 0 for error */ int scp_get_gateway_request(struct trans *trans, const char **username, - const char **password); + const char **password, + const char **connection_description); /** * Send an E_SCP_GATEWAY_RESPONSE (SCP server) diff --git a/sesman/scp_process.c b/sesman/scp_process.c index a15dbc9e..f4850a3b 100644 --- a/sesman/scp_process.c +++ b/sesman/scp_process.c @@ -37,6 +37,33 @@ #include "auth.h" #include "session.h" +/**************************************************************************//** + * Logs an authentication failure message + * + * @param username Username + * @param connection_description Connection details + * + * The message is intended for use by fail2ban. Make changes with care. + */ +static void +log_authfail_message(const char *username, const char *connection_description) +{ + char ip[64]; + const char *ipp; + if (connection_description != NULL && + connection_description[0] != '\0') + { + g_get_ip_from_description(connection_description, ip, sizeof(ip)); + ipp = ip; + } + else + { + ipp = "unknown"; + } + LOG(LOG_LEVEL_INFO, "AUTHFAIL: user=%s ip=%s time=%d", + username, ipp, g_time1()); +} + /******************************************************************************/ static int @@ -45,8 +72,11 @@ process_gateway_request(struct trans *trans) int rv; const char *username; const char *password; + const char *connection_description; - if ((rv = scp_get_gateway_request(trans, &username, &password)) == 0) + rv = scp_get_gateway_request(trans, &username, &password, + &connection_description); + if (rv == 0) { int errorcode = 0; tbus data; @@ -73,9 +103,7 @@ process_gateway_request(struct trans *trans) } else { - /* g_writeln("username or password error"); */ - LOG(LOG_LEVEL_INFO, "Username or password error for user: %s", - username); + log_authfail_message(username, connection_description); } rv = scp_send_gateway_response(trans, errorcode); auth_end(data); @@ -168,16 +196,7 @@ process_create_session_request(struct trans *trans) } else { - char ip[64]; - g_get_ip_from_description(sp.connection_description, - ip, sizeof(ip)); - /* - * The message is intended for use by fail2ban, so for - * future-proofing we only log the IP address rather than the - * connection description */ - LOG(LOG_LEVEL_INFO, - "AUTHFAIL: user=%s ip=%s time=%d", - sp.username, ip, g_time1()); + log_authfail_message(sp.username, sp.connection_description); } if (do_auth_end) diff --git a/xrdp/xrdp_mm.c b/xrdp/xrdp_mm.c index a149a447..b48e9f3b 100644 --- a/xrdp/xrdp_mm.c +++ b/xrdp/xrdp_mm.c @@ -228,7 +228,9 @@ xrdp_mm_send_gateway_login(struct xrdp_mm *self, const char *username, xrdp_wm_log_msg(self->wm, LOG_LEVEL_DEBUG, "sending login info to session manager, please wait..."); - return scp_send_gateway_request(self->pam_auth_trans, username, password); + return scp_send_gateway_request( + self->pam_auth_trans, username, password, + self->wm->client_info->connection_description); } /*****************************************************************************/