Bug 197854

Summary: security/sshguard patch to trigger on syslog entries with <facility.level>
Product: Ports & Packages Reporter: jakob.alvermark
Component: Individual Port(s)Assignee: Mark Felder <feld>
Status: Closed FIXED    
Severity: Affects Some People Flags: bugzilla: maintainer-feedback? (feld)
Priority: ---    
Version: Latest   
Hardware: Any   
OS: Any   
Attachments:
Description Flags
Patch to attack_scanner.l none

Description jakob.alvermark 2015-02-20 16:08:54 UTC
Created attachment 153223 [details]
Patch to attack_scanner.l

syslogd -v adds <facility.level> to the logs.
Attached patch makes sshguard trigger on those lines as well.
Comment 1 Bugzilla Automation freebsd_committer freebsd_triage 2015-02-20 16:08:54 UTC
Auto-assigned to maintainer feld@FreeBSD.org
Comment 2 Mark Felder freebsd_committer freebsd_triage 2015-02-20 21:11:03 UTC
Thanks for the patch! Can you confirm if it still matches entries when -v is not passed? I believe that was an issue from way back when this was discussed on the  upstream mailing lists.
Comment 3 jakob.alvermark 2015-02-22 13:29:31 UTC
(In reply to Mark Felder from comment #2)

Yes. I have run it in debug mode and fed it logs both with and without <facility.level>
Comment 4 Mark Felder freebsd_committer freebsd_triage 2015-03-05 13:58:48 UTC
This hasn't been overlooked; I've just been looking for more testers. I expect this will land in the tree soon.
Comment 5 commit-hook freebsd_committer freebsd_triage 2015-03-24 02:11:41 UTC
A commit references this bug:

Author: feld
Date: Tue Mar 24 02:11:27 UTC 2015
New revision: 382063
URL: https://svnweb.freebsd.org/changeset/ports/382063

Log:
  Enable matching of syslog entries with <facility.level>

  PR:		197854

Changes:
  head/security/sshguard/Makefile
  head/security/sshguard/files/patch-src-parser-attack_scanner.l
  head/security/sshguard/files/patch-src-sshguard.c
Comment 6 commit-hook freebsd_committer freebsd_triage 2015-03-24 02:23:44 UTC
A commit references this bug:

Author: feld
Date: Tue Mar 24 02:23:31 UTC 2015
New revision: 382064
URL: https://svnweb.freebsd.org/changeset/ports/382064

Log:
  Restore lost changes to patch-src-parser-attack_scanner.l

  PR:		197854

Changes:
  head/security/sshguard/Makefile
  head/security/sshguard/files/patch-src-parser-attack_scanner.l