Bug 772470 - Strange format of ban messages, sent to all users
Summary: Strange format of ban messages, sent to all users
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: fail2ban
Version: 16
Hardware: Unspecified
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Axel Thimm
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-01-08 16:21 UTC by Göran Uddeborg
Modified: 2013-02-13 08:58 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-02-13 08:58:09 UTC
Type: ---


Attachments (Terms of Use)

Description Göran Uddeborg 2012-01-08 16:21:13 UTC
Description of problem:
I'm not sure exactly when it started, but ban and unban messages have some strange leading characters.  More precisely, it is the bytes 0277, '<'. '2', '8', and '>'.  When displayed, the 0277 byte is usually presented as an upside down question mark, or a white question mark on black bottom, depending on context.  I'm not sure how bugzilla will treat it, but here is a messages line pasted.

  Jan  8 16:24:00 mimmi �<28>fail2ban.actions: WARNING [ssh-iptables] Ban ...

In addition, it appears this format confuses syslog somehow.  In addition to writing this to /var/log/messages, it also writes it to all logged-in users, as if it was an emergency message.

Version-Release number of selected component (if applicable):
fail2ban-0.8.4-27.fc16.noarch

How reproducible:
Almost every time.  I do see some occasional message in /var/log/messages that looks normal.

Steps to Reproduce:
1. Start fail2ban, with an active ssh-iptables jail
2. Do broken login attempts from some other host until the jail triggers
  
Actual results:
Strange message in /var/log/messages and on all terminals registered by "who".

Expected results:
A normal message in /var/log/messages only.

Additional info:
This happens only to Ban and Unban messages from the fail2ban.actions logger.  Even other messages from the same logger are normal, like for example

  Jan  8 16:15:11 mimmi fail2ban.actions: INFO   Set banTime = 1800

Comment 1 Jens Kuehnel 2012-01-15 10:38:28 UTC
Hi,

I have the same problem with Fedora 16 and the EPEL-6 package.
The "strange" character is a UTF BOM (Byte order mark).
The hex of the bom is ef bb bf.

It happens with all jails.

What I already tried:

 * search all packages belonging to fail2ban for a BOM or <28>. (none found).
 * convert jail.conf from UTF8 to ISO8859-1 (line 176 has some UTF8 ticks)
 * start fail2ban with LANG=C, LANG=en_US.UTF-8 and LANG=en_US

Nothing helped.

Comment 2 Adam Huffman 2012-07-19 10:06:45 UTC
I'm seeing this too.  The problem has been reported upstream at:

https://github.com/fail2ban/fail2ban/issues/32

though there hasn't been a release incorporating this fix yet.

Comment 3 Tomas Hajek 2012-10-03 15:29:11 UTC
Hi,
  I have the same issue (CentOS 6.3) using EPEL-6 fail2ban-0.8.4 package.
  I was able to suppress this dumping to console by changing the logtarget in /etc/fail2ban/fail2ban.conf to /var/log/fail2ban
 and also changing the logtarget in /etc/logrotate.d/fail2ban (otherwise the console output will start again after a log rotate.
  Any news on this being fixed or an updated package in EPEL as it does appear to be fixed in the fail2ban upstream?
thanks,

Comment 4 Fedora End Of Life 2013-01-16 10:20:54 UTC
This message is a reminder that Fedora 16 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 16. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '16'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 16's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 16 is end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" and open it against that version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 5 Fedora End Of Life 2013-02-13 08:58:12 UTC
Fedora 16 changed to end-of-life (EOL) status on 2013-02-12. Fedora 16 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.