Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #198836 > unrolled thread
| Started by | cyaiplexys <cyaiplexys@sitesplace.net> |
|---|---|
| First post | 2018-08-16 03:40 +0200 |
| Last post | 2018-08-18 11:00 +0200 |
| Articles | 2 on this page of 22 — 5 participants |
Back to article view | Back to linux.debian.user
Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-16 03:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? john doe <johndoe65534@mail.com> - 2018-08-16 08:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-16 13:50 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? john doe <johndoe65534@mail.com> - 2018-08-16 16:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-16 16:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Dave Sherohman <dave@sherohman.org> - 2018-08-16 19:10 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-16 20:10 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Brian <ad44@cityscape.co.uk> - 2018-08-16 21:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Dave Sherohman <dave@sherohman.org> - 2018-08-17 17:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-17 19:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? john doe <johndoe65534@mail.com> - 2018-08-17 19:20 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Brian <ad44@cityscape.co.uk> - 2018-08-17 19:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? john doe <johndoe65534@mail.com> - 2018-08-18 18:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Reco <recoverym4n@gmail.com> - 2018-08-18 19:30 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Brian <ad44@cityscape.co.uk> - 2018-08-18 20:10 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Brian <ad44@cityscape.co.uk> - 2018-08-17 20:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-17 20:40 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-17 20:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Brian <ad44@cityscape.co.uk> - 2018-08-17 20:10 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Dave Sherohman <dave@sherohman.org> - 2018-08-17 23:00 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? cyaiplexys <cyaiplexys@sitesplace.net> - 2018-08-17 23:30 +0200
Re: Fail2Ban Question: Can I do this without restarting the service? Dave Sherohman <dave@sherohman.org> - 2018-08-18 11:00 +0200
Page 2 of 2 — ← Prev page 1 [2]
| From | cyaiplexys <cyaiplexys@sitesplace.net> |
|---|---|
| Date | 2018-08-17 23:30 +0200 |
| Message-ID | <wnUtH-58b-5@gated-at.bofh.it> |
| In reply to | #198961 |
On 08/17/2018 04:58 PM, Dave Sherohman wrote: [Snipped some useful info] >> I *never ever* use port 22 for ssh. I pick some random port that I know >> isn't going to be used for anything else on the server and set ssh to use >> that port instead. How do I set ufw to use the ssh port of my choosing? > > In the ufw rule, just change "port 22" to whatever port you actually run > it on. The important thing, of course, is just that you don't block the > ssh port if you're doing this over ssh. I more than likely would be sure I can log into ssh before blocking anything else. >> That's not going to be possible to determine. I and the other admin (who >> also doesn't know about this stuff) both connect remotely via ssh and we >> both have dynamic IPs that are set (and changed) periodically (and at times >> we have no idea) by our ISP. Neither of us can afford a static IP to our >> homes. > > If you collect your DHCP-assigned addresses across a few changes, you > should be able to guess pretty accurately at the range of possible > addresses you might be assigned. Also, even with a single address, your > odds are pretty good if you just use the /24 CIDR block containing that > address, since most DHCP pools aren't going to be larger than that. > > So, e.g., I'm currently at a hotel with IP address 83.244.xxx.85. I > could almost certainly give access to the hotel's entire range of > dynamically-assigned IP addresses by allowing access from > 83.244.xxx.0/24. While I don't travel, the co-admin travels a LOT and doesn't always stay at hotels. Sometimes they are on the road, getting wifi other places, etc. So again, probably not possible to even get a good range. >> Can I do this too? >> >> ufw deny 22/tcp # Deny connection to port 22 (ssh default port) > > You could, but there's generally no point because all ports are denied > by default. You usually don't need to create specific deny rules unless > you have a port that you want to have open to the world, but then close > it for specific addresses, or if there's an IP address that you want to > allow access to all ports, except for a few specific ports. But (unless I was mistaken) wasn't port 22 open by default for ssh? So wouldn't I have to block it once I change and open the other ssh port? >> ufw allow [new-ssh-port]/tcp # Allow connection to new chosen ssh port > > This would work, and would allow every IP address in the world to > connect to your custom ssh port. (Which is not, IMO, a bad thing, but > your level of paranoia may vary.) Well, seeing as how the co-admin needs to get in too, it may be necessary. Who knows what IP they will have as they travel. >> Thing is, the bots hitting the server aren't getting 404 errors. They are >> trying to do php XSite injection on Wordpress sites and hitting actual web >> sites (HTTP 202). > > It just so happens I have a jail like that on a couple of my servers, > too. I have the filter in /etc/fail2ban/filter.d/http-get-dos.conf [Snip very good info] Thank you for this! That I think will come in very handy. > Based on what you've said so far, I expect you'll want to adjust the > maxretry/findtime/bantime values, but my experience has been that > banning offending IP addresses for 10 minutes generally seems to be > enough for them to give up and go bother someone else. We have seen otherwise. Once the ban is lifted, they just resume hammering the site. I think that it's a bot that is automatic and doesn't check to see if it was banned or not. It'll just keep going at whatever is in it's list ad-infinitum. > Banning for months at a time is unlikely to be necessary unless > you're dealing with a targeted attack. Seems like we just might be, actually. About 4 IPs keep on it no matter what. [Snipped more very useful info] >> (though Ubuntu seems to do things differently for Debian but that's OK >> since I would assume this stuff is the same for Debian and Ubuntu as >> for fail2ban/ufw?) > > I have limited experience with Ubuntu, but my impression is that their > differences (aside from release schedule) are primarily dealing with > end-user-focused applications. Networking and firewall management are > deep enough in the guts that I'm 99% sure they'll be the same in both > distros. That's good to hear that Debian stuff I learn here will also be good in case I need to make an Ubuntu server as well.
[toc] | [prev] | [next] | [standalone]
| From | Dave Sherohman <dave@sherohman.org> |
|---|---|
| Date | 2018-08-18 11:00 +0200 |
| Message-ID | <wo5fs-2Qu-19@gated-at.bofh.it> |
| In reply to | #198962 |
On Fri, Aug 17, 2018 at 05:28:50PM -0400, cyaiplexys wrote: > While I don't travel, the co-admin travels a LOT and doesn't always stay at > hotels. Sometimes they are on the road, getting wifi other places, etc. So > again, probably not possible to even get a good range. Yes, agreed, you probably will need to open your ssh port to the world. > >>Can I do this too? > >> > >>ufw deny 22/tcp # Deny connection to port 22 (ssh default port) > > > >You could, but there's generally no point because all ports are denied > >by default. You usually don't need to create specific deny rules unless > >you have a port that you want to have open to the world, but then close > >it for specific addresses, or if there's an IP address that you want to > >allow access to all ports, except for a few specific ports. > > But (unless I was mistaken) wasn't port 22 open by default for ssh? So > wouldn't I have to block it once I change and open the other ssh port? No, it's not open by default. That's why it's necessary to set up the "allow port 22 from..." (or whatever your alternate ssh port might be) rule before turning the firewall on with "ufw enable". If you've already opened port 22, then change your ssh port after enabling the firewall, you would handle this by adding an allow rule for the new port and then (after establishing a new ssh connection on the new port) deleting the "allow port 22" rule rather than by adding a "deny port 22". To do this, run "ufw status numbered" to find the number of the rule you want to remove, then "ufw delete [rule number]". (Handy tip: If you want to add a new rule that's similar to an existing rule, but can't remember the exact syntax, you can "ufw delete [the existing rule]" and say "no" when it asks to confirm the deletion. The confirmation message includes the command used to create the rule, so you can just copy/paste it and change the details as needed to create the new rule.) -- Dave Sherohman
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.debian.user
csiph-web