Add fail2ban logging to PAM authentication requests
This commit is contained in:
+9
-5
@@ -159,16 +159,18 @@ scp_msg_in_start(struct trans *trans)
|
||||
int
|
||||
scp_send_gateway_request(struct trans *trans,
|
||||
const char *username,
|
||||
const char *password)
|
||||
const char *password,
|
||||
const char *connection_description)
|
||||
{
|
||||
int rv;
|
||||
|
||||
rv = libipm_msg_out_simple_send(
|
||||
trans,
|
||||
(int)E_SCP_GATEWAY_REQUEST,
|
||||
"ss",
|
||||
"sss",
|
||||
username,
|
||||
password);
|
||||
password,
|
||||
connection_description);
|
||||
|
||||
/* Wipe the output buffer to remove the password */
|
||||
libipm_msg_out_erase(trans);
|
||||
@@ -181,12 +183,14 @@ scp_send_gateway_request(struct trans *trans,
|
||||
int
|
||||
scp_get_gateway_request(struct trans *trans,
|
||||
const char **username,
|
||||
const char **password)
|
||||
const char **password,
|
||||
const char **connection_description)
|
||||
{
|
||||
/* Make sure the buffer is cleared after processing this message */
|
||||
libipm_set_flags(trans, LIBIPM_E_MSG_IN_ERASE_AFTER_USE);
|
||||
|
||||
return libipm_msg_in_parse(trans, "ss", username, password);
|
||||
return libipm_msg_in_parse(trans, "sss", username, password,
|
||||
connection_description);
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
|
||||
+6
-2
@@ -150,6 +150,7 @@ scp_msg_in_reset(struct trans *trans);
|
||||
* @param trans SCP transport
|
||||
* @param username Username
|
||||
* @param password Password
|
||||
* @param connection_description Description of the connection
|
||||
* @return != 0 for error
|
||||
*
|
||||
* Server replies with E_SCP_GATEWAY_RESPONSE
|
||||
@@ -157,7 +158,8 @@ scp_msg_in_reset(struct trans *trans);
|
||||
int
|
||||
scp_send_gateway_request(struct trans *trans,
|
||||
const char *username,
|
||||
const char *password);
|
||||
const char *password,
|
||||
const char *connection_description);
|
||||
|
||||
/**
|
||||
* Parse an incoming E_SCP_GATEWAY_REQUEST message (SCP server)
|
||||
@@ -165,12 +167,14 @@ scp_send_gateway_request(struct trans *trans,
|
||||
* @param trans SCP transport
|
||||
* @param[out] username Username
|
||||
* @param[out] password Password
|
||||
* @param[out] connection_description Description of the connection
|
||||
* @return != 0 for error
|
||||
*/
|
||||
int
|
||||
scp_get_gateway_request(struct trans *trans,
|
||||
const char **username,
|
||||
const char **password);
|
||||
const char **password,
|
||||
const char **connection_description);
|
||||
|
||||
/**
|
||||
* Send an E_SCP_GATEWAY_RESPONSE (SCP server)
|
||||
|
||||
+33
-14
@@ -37,6 +37,33 @@
|
||||
#include "auth.h"
|
||||
#include "session.h"
|
||||
|
||||
/**************************************************************************//**
|
||||
* Logs an authentication failure message
|
||||
*
|
||||
* @param username Username
|
||||
* @param connection_description Connection details
|
||||
*
|
||||
* The message is intended for use by fail2ban. Make changes with care.
|
||||
*/
|
||||
static void
|
||||
log_authfail_message(const char *username, const char *connection_description)
|
||||
{
|
||||
char ip[64];
|
||||
const char *ipp;
|
||||
if (connection_description != NULL &&
|
||||
connection_description[0] != '\0')
|
||||
{
|
||||
g_get_ip_from_description(connection_description, ip, sizeof(ip));
|
||||
ipp = ip;
|
||||
}
|
||||
else
|
||||
{
|
||||
ipp = "unknown";
|
||||
}
|
||||
LOG(LOG_LEVEL_INFO, "AUTHFAIL: user=%s ip=%s time=%d",
|
||||
username, ipp, g_time1());
|
||||
}
|
||||
|
||||
/******************************************************************************/
|
||||
|
||||
static int
|
||||
@@ -45,8 +72,11 @@ process_gateway_request(struct trans *trans)
|
||||
int rv;
|
||||
const char *username;
|
||||
const char *password;
|
||||
const char *connection_description;
|
||||
|
||||
if ((rv = scp_get_gateway_request(trans, &username, &password)) == 0)
|
||||
rv = scp_get_gateway_request(trans, &username, &password,
|
||||
&connection_description);
|
||||
if (rv == 0)
|
||||
{
|
||||
int errorcode = 0;
|
||||
tbus data;
|
||||
@@ -73,9 +103,7 @@ process_gateway_request(struct trans *trans)
|
||||
}
|
||||
else
|
||||
{
|
||||
/* g_writeln("username or password error"); */
|
||||
LOG(LOG_LEVEL_INFO, "Username or password error for user: %s",
|
||||
username);
|
||||
log_authfail_message(username, connection_description);
|
||||
}
|
||||
rv = scp_send_gateway_response(trans, errorcode);
|
||||
auth_end(data);
|
||||
@@ -168,16 +196,7 @@ process_create_session_request(struct trans *trans)
|
||||
}
|
||||
else
|
||||
{
|
||||
char ip[64];
|
||||
g_get_ip_from_description(sp.connection_description,
|
||||
ip, sizeof(ip));
|
||||
/*
|
||||
* The message is intended for use by fail2ban, so for
|
||||
* future-proofing we only log the IP address rather than the
|
||||
* connection description */
|
||||
LOG(LOG_LEVEL_INFO,
|
||||
"AUTHFAIL: user=%s ip=%s time=%d",
|
||||
sp.username, ip, g_time1());
|
||||
log_authfail_message(sp.username, sp.connection_description);
|
||||
}
|
||||
|
||||
if (do_auth_end)
|
||||
|
||||
+3
-1
@@ -228,7 +228,9 @@ xrdp_mm_send_gateway_login(struct xrdp_mm *self, const char *username,
|
||||
xrdp_wm_log_msg(self->wm, LOG_LEVEL_DEBUG,
|
||||
"sending login info to session manager, please wait...");
|
||||
|
||||
return scp_send_gateway_request(self->pam_auth_trans, username, password);
|
||||
return scp_send_gateway_request(
|
||||
self->pam_auth_trans, username, password,
|
||||
self->wm->client_info->connection_description);
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
|
||||
Reference in New Issue
Block a user