diff --git a/csf/csf.deny b/csf/csf.deny index 83235f1..f74ec72 100644 --- a/csf/csf.deny +++ b/csf/csf.deny @@ -15,4 +15,4 @@ # tcp/udp|in/out|s/d=port,port,...|s/d=ip # # See readme.txt for more information regarding advanced port filtering -# + diff --git a/csf/csf.ignore b/csf/csf.ignore index b5e086d..18aa6f0 100644 --- a/csf/csf.ignore +++ b/csf/csf.ignore @@ -32,6 +32,7 @@ 188.25.145.85 86.127.10.154 + # RND 82.76.35.228 86.120.251.224 diff --git a/shadow b/shadow index 5b55e24..9d934b2 100644 --- a/shadow +++ b/shadow @@ -35,7 +35,7 @@ dovecot:!!:18526:::::: dovenull:!!:18526:::::: postfix:!!:18526:::::: mysql:!!:18526:::::: -madalin:$6$EiMxEtxQguelfC4J$gD2fVn5XDfgJG.50Stc9/tZtL2VxJNBmAklHZj2k9nIzQRuU.rzEwf5ktDUy/4f/..R5AUvE3Q2IWnniZ7xIZ0:18764:0:99999:7::: +madalin:$6$o5gdTOT7LTSGwvLw$RWG5G9gx7lGmA7yqkTYueqZcm.5C5tUmngV01pmiqWpfFkH9uUoJMx1p3lZUP8R.h43NYIiH7IePvP1sHd4aN/:19296:0:99999:7::: sslh:!!:18527:::::: vampi:$6$tRIULiDksEzmp1/r$0wXDJUfPNaUIio90.hQrQy10943EpXazN7GdVxo1ZFh3hWfHaw.X3uWl6UVTBZgWfgmk3719HzfnoYNwHhpfb.:18639:0:99999:7::: _rspamd:!!:18527:::::: diff --git a/squid/squid.conf b/squid/squid.conf index 99eee66..7f11679 100644 --- a/squid/squid.conf +++ b/squid/squid.conf @@ -1,3 +1,5 @@ +workers 4 + acl localnet src 10.0.0.0/8 # RFC1918 possible internal network acl localnet src 172.16.0.0/12 # RFC1918 possible internal network acl localnet src 192.168.0.0/16 # RFC1918 possible internal network diff --git a/ssh/sshrc b/ssh/sshrc index 1bca499..6f0e7d5 100755 --- a/ssh/sshrc +++ b/ssh/sshrc @@ -2,16 +2,16 @@ export PATH="/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/opt/bin:$PATH" -#DATE="$(date)" +DATE="$(date)" HOSTNAME="$(hostname)" -#USERIP="$(echo "$SSH_CONNECTION" | cut -d " " -f 1)" +USERIP="$(echo "$SSH_CONNECTION" | cut -d " " -f 1)" #RDNS="$(dig -x "$USERIP" +short)" -if [[ "$USER" == "laser" ]] +if [[ "$USER" == "laser" || "$USER" == "madalin" ]] then curl -s -X POST -H "content-type: application/json" -d '{"routing_key":"1969ec3d30b74608d0135d6321275bb7","event_action":"trigger","payload":{"summary":"User '"$USER"' has logged in via SSH!!","source":"/etc/ssh/sshrc","severity":"critical","component":"exploratory-stats","group":"prod-d atapipe","class":"deploy"}}' https://events.pagerduty.com/v2/enqueue - #echo "User $USER logged in via SSH using ip address: $USERIP (dns: $RDNS) at $DATE" >> /var/log/ssh-logins.log + echo "User $USER logged in via SSH using ip address: $USERIP on $DATE" >> /var/log/ssh-logins.log else - #echo "User $USER logged in via SSH using ip address: $USERIP (dns: $RDNS) at $DATE" >> /var/log/ssh-logins.log + echo "User $USER logged in via SSH using ip address: $USERIP on $DATE" >> /var/log/ssh-logins.log exit 0 fi