如何让Fail2Ban的nginx-botsearch匹配指定字符串且排除后缀多余字符
Got it, let's sort out this filtering issue for your WordPress login endpoints on Ubuntu 16.04's Fail2Ban 0.9.3. The goal is to catch requests to http://example.com/wp-login.php or http://example.com/folder/wp-login.php, but ignore those with random extra characters appended (like wp-login.phpasdfasdf). Here's how to adjust your filters:
Step 1: Edit the botsearch-common.local Filter
Since nginx-botsearch relies on botsearch-common, we'll modify that file to tighten up the regex for wp-login.php:
sudo nano /etc/fail2ban/filter.d/botsearch-common.local
Step 2: Update the Regex Pattern
Look for the line in your failregex definition that includes wp-login\.php. By default, it might look something like this:
failregex = ... wp-login.php ...
We need to add a word boundary check to ensure wp-login.php isn't followed by extra alphanumeric characters. Replace the plain wp-login\.php with:
wp-login\.php\b
Or, if you want to explicitly account for URL parameters (like wp-login.php?action=login) or the end of the request line, use this more precise pattern:
wp-login\.php(?:\?| |$)
What this does:
\bis a word boundary, which stops matches wherewp-login.phpis followed by letters, numbers, or underscores (exactly the kind of extra characters you want to exclude).(?:\?| |$)matches either a question mark (start of URL parameters), a space (end of the request path before HTTP version), or the end of the line—covering all valid use cases for the login path.
Step 3: Test the Regex
Before applying changes, verify the regex works with your actual logs using fail2ban-regex:
sudo fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-botsearch.local
Check the output to confirm:
- Valid requests to
wp-login.php(with or without subfolders/parameters) are marked as matched. - Requests like
wp-login.phpasdfasdfare not matched.
Step 4: Restart Fail2Ban
Once you're satisfied with the test results, restart the service to apply the new filter:
sudo systemctl restart fail2ban
That should do it—your nginx-botsearch jail will now only target legitimate wp-login.php paths and ignore those maliciously modified ones.
内容的提问来源于stack exchange,提问作者Harold Fischer

