Re: Proftpd updates
Geert Janssens <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Organization | Kobalt W.I.T. |
| Message-ID | <[email protected]> |
Hi, I am happy to see changes in the proftpd log watch report. I have proftpd installed, and the log report I get is not very helpful right now to me. Mind you, it's very well possible this is due to a poorly configured proftpd ! I didn't have time yet to investigate this in detail. I do want to inform you though of some additional unrecognized log entries, since you are working in this area now: I have proftpd configured with mod_ldap, which enables ldap as an authentication backend for proftpd. With mod_ldap configured I get a lot of unrecognized messages like this: <domain name> (<ipaddress>[<ipaddress>]) - mod_ldap: pr_ldap_group_lookup(): ldap_search_st() failed: No such object and like this: <domain name> (<ipaddress>[<ipaddress>]) - mod_ldap: ldap_handle_getgroups(): ldap_search_st() failed: No such object <domainname> is the fully qualified domain name of my LDAP or proftpd server (I can't really tell which of the two, because they are on the same server for me). <ipaddress> is the ip address of the ftp client connecting. You can notice it appearing twice per log message. I presume the first would be the ip address, and the second the reverse resolved dns entry and for some reason the DNS resolution is not working. These two error messages always come together. First the one, immediatly followed by the second. Again, I don't know what should happen with these messages as I don't know why they appear yet. My proftpd setup seems to work fine, even with these errors, although it's possible the ldap connections fail all the time, and the pam fallback takes over each failed ldap attempt. I really can't tell just yet, but I did want to let you know about these additional unrecognised log messages, just in case they mean something you someone on the list. Regards, Geert On Sunday 25 March 2007 17:51, Mike Tremaine wrote: > Updates to the proftpd-messages service have been committed to CVS. A > lot of the changes are based on the patch that James Treworgy sent in > [so big thanks to him]. It should now work with both "-" and ":" formats > which seems to be the difference between syslog and stand alone > logging. Some simple Bugs got squished [BadShell had the wrong Hash in > the reporting section.] I've added Notice and Error reports, ignore > chroot notices, mod_delay and the no such user listings in favor of the > USER line. > > The only log line that I've seen that has not been handled yet is lines > like > > Unable to open password file > Unable to open group file > > Which I suspect are an attack vector from and ANON login trying to > change privileges. A little more research and I'll figure out how to > report those. > > -Mike > > > _______________________________________________ > Logwatch-Devel mailing list > [email protected] > http://www2.list.logwatch.org:81/mailman/listinfo/logwatch-devel -- Kobalt W.I.T. Web & Information Technology Brusselsesteenweg 152 1850 Grimbergen Tel : +32 479 339 655 Email: [email protected]