+#
+
+# deb cdrom:[Debian GNU/Linux stretch-DI-alpha7 _Stretch_ - Official Snapshot amd64 NETINST Binary-1 20160630-14:29]/ stretch main
+
# deb http://ftp-stud.hs-esslingen.de/debian stretch main
# main stretch repositories
-# Generated by iptables-save v1.6.0 on Wed Jul 19 21:37:54 2017
+# Generated by iptables-save v1.6.0 on Wed Jul 19 21:42:25 2017
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
-:OUTPUT ACCEPT [2:472]
-:fail2ban-dovecot - [0:0]
-:fail2ban-postfix - [0:0]
-:fail2ban-roundcube - [0:0]
-:fail2ban-sshd - [0:0]
-:fail2ban-sshd-ddos - [0:0]
+:OUTPUT ACCEPT [66:13536]
:mysql - [0:0]
--A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-postfix
--A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-dovecot
--A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-roundcube
--A INPUT -p tcp -m multiport --dports 22 -j fail2ban-sshd-ddos
--A INPUT -p tcp -m multiport --dports 22 -j fail2ban-sshd
-A INPUT -s 220.192.0.0/12 -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -s 222.184.0.0/13 -p tcp -m multiport --dports 22 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -s 220.192.0.0/12 -p tcp -m multiport --dports 22 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -p tcp -m tcp --dport 3306 -j mysql
-A INPUT -j NFLOG --nflog-prefix "INPUT Reject " --nflog-threshold 1
-A INPUT -j REJECT --reject-with icmp-port-unreachable
--A fail2ban-dovecot -j RETURN
--A fail2ban-postfix -j RETURN
--A fail2ban-roundcube -j RETURN
--A fail2ban-sshd -j RETURN
--A fail2ban-sshd-ddos -j RETURN
-A mysql -s 127.0.0.1/32 -j ACCEPT
-A mysql -s 185.48.118.130/32 -j ACCEPT
-A mysql -s 10.12.20.5/32 -j ACCEPT
-A mysql -j NFLOG --nflog-prefix "MySQL Reject " --nflog-threshold 1
-A mysql -j REJECT --reject-with icmp-port-unreachable
COMMIT
-# Completed on Wed Jul 19 21:37:54 2017
-# Generated by iptables-save v1.6.0 on Wed Jul 19 21:37:54 2017
+# Completed on Wed Jul 19 21:42:25 2017
+# Generated by iptables-save v1.6.0 on Wed Jul 19 21:42:25 2017
*nat
-:PREROUTING ACCEPT [0:0]
-:INPUT ACCEPT [0:0]
-:OUTPUT ACCEPT [0:0]
-:POSTROUTING ACCEPT [0:0]
+:PREROUTING ACCEPT [76:3960]
+:INPUT ACCEPT [23:1804]
+:OUTPUT ACCEPT [19:1598]
+:POSTROUTING ACCEPT [19:1598]
COMMIT
-# Completed on Wed Jul 19 21:37:54 2017
+# Completed on Wed Jul 19 21:42:25 2017
-# Generated by ip6tables-save v1.6.0 on Wed Jul 19 21:37:54 2017
+# Generated by ip6tables-save v1.6.0 on Wed Jul 19 21:42:25 2017
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
-A mysql -j NFLOG --nflog-prefix "IPv6 MySQL Reject " --nflog-threshold 1
-A mysql -j REJECT --reject-with icmp6-port-unreachable
COMMIT
-# Completed on Wed Jul 19 21:37:54 2017
+# Completed on Wed Jul 19 21:42:25 2017
sharedscripts
create 644
postrotate
- /usr/bin/chronyc -a cyclelogs > /dev/null 2>&1 || true
+ /usr/bin/chronyc cyclelogs > /dev/null 2>&1 || true
endscript
}
Linux sarah 4.9.0-0.bpo.2-amd64 #1 SMP Debian 4.9.18-1~bpo8+1 (2017-04-10) x86_64 GNU/Linux
-Debian GNU/Linux 8.8 (jessie)
+Debian GNU/Linux 9.0 (stretch)
____ _
/ ___| __ _ _ __ __ _| |__
\___ \ / _` | '__/ _` | '_ \
|____/ \__,_|_| \__,_|_| |_|
-Die menschliche Dummheit ist keine historische Sache. Die menschliche
-Dummheit existiert allgemein, sogar bis in alle Ewigkeit hinein. Diese
-Dummheit gehört zum Menschen. Sie ist eine strukturelle Angelegenheit.
- -- Laszlo Krasznahorkai
+Ich gehe jetzt in den Birkenwald,
+denn meine Pillen wirken bald.
Today is Setting Orange, the 54th day of Confusion in the YOLD 3183
#### MODULES ####
#################
-$ModLoad imuxsock # provides support for local system logging
-$ModLoad imklog # provides kernel logging support
-#$ModLoad immark # provides --MARK-- message capability
+module(load="imuxsock") # provides support for local system logging
+module(load="imklog") # provides kernel logging support
+#module(load="immark") # provides --MARK-- message capability
module(load="immark" Interval="600")
# provides UDP syslog reception
-#$ModLoad imudp
-#$UDPServerRun 514
+#module(load="imudp")
+#input(type="imudp" port="514")
# provides TCP syslog reception
-#$ModLoad imtcp
-#$InputTCPServerRun 514
+#module(load="imtcp")
+#input(type="imtcp" port="514")
###########################
$DirCreateMode 0755
$Umask 0022
-module(
- load="builtin:omfile"
- Template="RSYSLOG_FileFormat"
- FileCreateMode="0644"
- DirCreateMode="0755"
- fileOwnerNum="0"
- fileGroupNum="0"
- dirOwnerNum="0"
- dirGroupNum="0"
-)
-
#
# Where to place spool and state files
#
# Emergencies are sent to everybody logged in.
#
*.emerg :omusrmsg:*
-
-#
-# I like to have messages displayed on the console, but only on a virtual
-# console I usually leave idle.
-#
-#daemon,mail.*;\
-# news.=crit;news.=err;news.=notice;\
-# *.=debug;*.=info;\
-# *.=notice;*.=warn /dev/tty8
-
-# The named pipe /dev/xconsole is for the `xconsole' utility. To use it,
-# you must invoke `xconsole' with the `-file' option:
-#
-# $ xconsole -file /dev/xconsole [...]
-#
-# NOTE: adjust the list below, or you'll go crazy if you have a reasonably
-# busy site..
-#
-daemon.*;mail.*;\
- news.err;\
- *.=debug;*.=info;\
- *.=notice;*.=warn |/dev/xconsole
set incsearch " Incremental search
set autowrite " Automatically save before commands like :next and :make
set hidden " Hide buffers when they are abandoned
+set mouse= " Disable mouse usage (all modes)
autocmd FileType sls set tabstop=2 expandtab shiftwidth=2 softtabstop=2
autocmd FileType python set tabstop=4 expandtab shiftwidth=4 softtabstop=4