Add fail2ban logging to PAM authentication requests

This commit is contained in:
matt335672
2022-03-01 16:02:37 +00:00
parent 1746ac2f79
commit 8e27f231fd
4 changed files with 51 additions and 22 deletions
+9 -5
View File
@@ -159,16 +159,18 @@ scp_msg_in_start(struct trans *trans)
int
scp_send_gateway_request(struct trans *trans,
const char *username,
const char *password)
const char *password,
const char *connection_description)
{
int rv;
rv = libipm_msg_out_simple_send(
trans,
(int)E_SCP_GATEWAY_REQUEST,
"ss",
"sss",
username,
password);
password,
connection_description);
/* Wipe the output buffer to remove the password */
libipm_msg_out_erase(trans);
@@ -181,12 +183,14 @@ scp_send_gateway_request(struct trans *trans,
int
scp_get_gateway_request(struct trans *trans,
const char **username,
const char **password)
const char **password,
const char **connection_description)
{
/* Make sure the buffer is cleared after processing this message */
libipm_set_flags(trans, LIBIPM_E_MSG_IN_ERASE_AFTER_USE);
return libipm_msg_in_parse(trans, "ss", username, password);
return libipm_msg_in_parse(trans, "sss", username, password,
connection_description);
}
/*****************************************************************************/
+6 -2
View File
@@ -150,6 +150,7 @@ scp_msg_in_reset(struct trans *trans);
* @param trans SCP transport
* @param username Username
* @param password Password
* @param connection_description Description of the connection
* @return != 0 for error
*
* Server replies with E_SCP_GATEWAY_RESPONSE
@@ -157,7 +158,8 @@ scp_msg_in_reset(struct trans *trans);
int
scp_send_gateway_request(struct trans *trans,
const char *username,
const char *password);
const char *password,
const char *connection_description);
/**
* Parse an incoming E_SCP_GATEWAY_REQUEST message (SCP server)
@@ -165,12 +167,14 @@ scp_send_gateway_request(struct trans *trans,
* @param trans SCP transport
* @param[out] username Username
* @param[out] password Password
* @param[out] connection_description Description of the connection
* @return != 0 for error
*/
int
scp_get_gateway_request(struct trans *trans,
const char **username,
const char **password);
const char **password,
const char **connection_description);
/**
* Send an E_SCP_GATEWAY_RESPONSE (SCP server)
+33 -14
View File
@@ -37,6 +37,33 @@
#include "auth.h"
#include "session.h"
/**************************************************************************//**
* Logs an authentication failure message
*
* @param username Username
* @param connection_description Connection details
*
* The message is intended for use by fail2ban. Make changes with care.
*/
static void
log_authfail_message(const char *username, const char *connection_description)
{
char ip[64];
const char *ipp;
if (connection_description != NULL &&
connection_description[0] != '\0')
{
g_get_ip_from_description(connection_description, ip, sizeof(ip));
ipp = ip;
}
else
{
ipp = "unknown";
}
LOG(LOG_LEVEL_INFO, "AUTHFAIL: user=%s ip=%s time=%d",
username, ipp, g_time1());
}
/******************************************************************************/
static int
@@ -45,8 +72,11 @@ process_gateway_request(struct trans *trans)
int rv;
const char *username;
const char *password;
const char *connection_description;
if ((rv = scp_get_gateway_request(trans, &username, &password)) == 0)
rv = scp_get_gateway_request(trans, &username, &password,
&connection_description);
if (rv == 0)
{
int errorcode = 0;
tbus data;
@@ -73,9 +103,7 @@ process_gateway_request(struct trans *trans)
}
else
{
/* g_writeln("username or password error"); */
LOG(LOG_LEVEL_INFO, "Username or password error for user: %s",
username);
log_authfail_message(username, connection_description);
}
rv = scp_send_gateway_response(trans, errorcode);
auth_end(data);
@@ -168,16 +196,7 @@ process_create_session_request(struct trans *trans)
}
else
{
char ip[64];
g_get_ip_from_description(sp.connection_description,
ip, sizeof(ip));
/*
* The message is intended for use by fail2ban, so for
* future-proofing we only log the IP address rather than the
* connection description */
LOG(LOG_LEVEL_INFO,
"AUTHFAIL: user=%s ip=%s time=%d",
sp.username, ip, g_time1());
log_authfail_message(sp.username, sp.connection_description);
}
if (do_auth_end)
+3 -1
View File
@@ -228,7 +228,9 @@ xrdp_mm_send_gateway_login(struct xrdp_mm *self, const char *username,
xrdp_wm_log_msg(self->wm, LOG_LEVEL_DEBUG,
"sending login info to session manager, please wait...");
return scp_send_gateway_request(self->pam_auth_trans, username, password);
return scp_send_gateway_request(
self->pam_auth_trans, username, password,
self->wm->client_info->connection_description);
}
/*****************************************************************************/