

Sshguard サービスのログ活動を監視します。それは、ローカルのファイアウォールの送信元アドレスを遮断することによって危険な活動についてのメッセージに反応します。Sshguard は透過的にいくつかのログ フォーマット一度に (syslog、syslog-ン、metalog、multilog、プレーン テキスト メッセージ) を認識できるし、箱から出して、SSH、いくつかの ftpds および dovecot を含む多くのサービスに対する攻撃を検出する巧妙なパーサーを採用しています。すべての主要なファイアウォール システムを操作できるし、IPv6、ホワイト リスト、懸濁液、およびログ メッセージ認証機能をサポートします。


2011-02-15 06:46

This is a milestone release, coming after 18 months of development and testing and a long list of beta and RC releases. Two major features are introduced: the LogSucker, to monitor many log sources at once, and attack dangerousness, to punish attacks with fine-tuned severity. Along with these comes a long list of further minor features, signatures, and fixes. All users are strongly recommended to update to this version, and report missing signatures to http://sshguard.net/newsignature/ .

2010-08-09 18:10

This release candidate fixes the last known bugs submitted by users for 1.5rc3. Fixes cover mainly Solaris portability, plus whitelisting and a rare assertion violation and file descriptor leak. This is the last RC planned before 1.5 stable.

2010-04-13 07:12

This release fixes compilation issues on Solaris, fixes the "hosts" backend's logic for temporary files, and fixes the blacklist module to avoid inconsistencies in saved blacklists.

2010-03-02 22:28

With respect to 1.5beta3, this release completes support for IPv6 by adding support for CIDR-based IPv6 whitelisting and whitelisting of both IPv4 and IPv6 addresses when adding hosts. IPv4-mapped IPv6 addresses are passed to backend firewalls as IPv4. This is the last release that adds features for 1.5. The next releases will only fix bugs until 1.5 stable.

2010-02-12 05:39

Sshguard now recognizes "last message repeated N times" messages, contextually and per-source. Attackers are now gauged with dangerousness instead of attack counts by adjusting the '-a' option. Support for Sendmail relaying abuse and for vsftpd authentication failure messages has been added. The recognition of messages of Gentoo's PAM implementation for authentication failure has been added.
