Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229263

Re: swamp rat bots Q

From Keith Christian <keith1christian@gmail.com>
Newsgroups linux.debian.user
Subject Re: swamp rat bots Q
Date 2020-12-03 22:30 +0100
Message-ID <Bi4kO-55U-5@gated-at.bofh.it> (permalink)
References <BhWnf-85-7@gated-at.bofh.it> <BhXt0-105-17@gated-at.bofh.it> <BhXCF-13o-5@gated-at.bofh.it> <Bi1ZD-3y2-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Gene,

Fail2ban can be difficult to comprehend at first, so here are some ideas:

As either the fail2ban user (may need root), run this command to see
that fail2ban is active and what "jails" are active, a jail
corresponds to one type of message in the log file fail2ban is
watching, which are set up in /etc/fail2ban/filter.d/*.conf files and
configs in /etc/fail2ban/jail.conf:)
# fail2ban-client status

Also, look at fail2ban-client's options:
# fail2ban-client help

Fail2ban is essentially a log file miner ("tailer" as Greg said above)
that watches for the frequency that certain regex patterns appear in
the log file. The log file must have timestamps and FQDN's or
hostnames or IP addresses so that the incoming host can be identified
and the frequency of the incoming connections can be derived from the
timestamps.

Look in the /etc/fail2ban/filter.d/ directory for the files containing
regular expressions that fail2ban should use to match lines in the log
file it should monitor, try "cat
/etc/fail2ban/filter.d/apache-200.conf" to see the regex.

The two main file sets to get started with are the
/etc/fail2ban/filter.d/ files and the /etc/fail2ban/jail.conf file.
In the /etc/fail2ban/jail.conf file you'll see the filenames of the
conf files between brackets:

e.g. [apache-200] corresponds to /etc/fail2ban/filter.d/apache-200.conf

which contains settings for watching 200 OK in apache log files, and
the number of hits and the time window before the incoming host is
blocked.

Take a look at the fail2ban.log file for the latest "news:"
As root:
# tail -f /var/log/fail2ban.log
or,
# cat /var/log/fail2ban.log | tail to see what is going on, if anything.

To check whether fail2ban is running, the command below should return
a "fail2ban-server" line in the output.
# pgrep -fl fail2ban

TESTING / DEBUGGING:
Use the fail2ban-regex command to test log file samples and whether
your entries in /etc/fail2ban/filter.d/*.conf files and configs in
/etc/fail2ban/jail.conf are working without waiting around for another
inbound event.  fail2ban-regex will help you debug and/or fine-tune
the regex and timing so that fail2ban can do its job.

If the regex in the /etc/fail2ban/filter.d/*.conf file does not match
any lines in the log file that fail2ban is watching, NOTHING WILL BE
BANNED, since fail2ban does not see the timestamps and FQDN's or
hostnames or IP addresses in order to count hits and frequencies.
Hence: the regex in the /etc/fail2ban/filter.d/*.conf file is CRITICAL
to the proper operation of fail2ban.

There are a lot of conf files with regexes in
/etc/fail2ban/filter.d/*.conf so take a look for ideas.

Test with fail2ban-regex and when it shows a match, it will work in
"production."  Trim off a few lines in the log file and test like
this:
First, copy some lines from a log file such as
access_log.2020-12-03-00_00_00 to the /tmp directory and copy the
active apache.conf file in /etc/filter.d to /tmp also, so that you can
tune the regex without affecting "production."
# cp -pv /etc/fail2ban/filter.d/apache-200.conf /tmp

# cp -pv access_log.2020-12-03-00_00_00 /tmp   ## Edit the
/tmp/access_log.2020-12-03-00_00_00 file down to a few hundred lines
to speed up the debugging/tuning process.

Then, run this command line to test:
# fail2ban-regex --print-all-matched
/tmp/access_log.2020-12-03-00_00_00 /tmp/apache-200.conf

See what this produces.

That should help you get started.

Keith

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-03 14:00 +0100
  Re: swamp rat bots Q john doe <johndoe65534@mail.com> - 2020-12-03 14:10 +0100
    Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-03 15:10 +0100
      Re: swamp rat bots Q Greg Wooledge <wooledg@eeg.ccf.org> - 2020-12-03 15:20 +0100
        Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-03 20:00 +0100
          Re: swamp rat bots Q Håkon Alstadheim <hakon@alstadheim.priv.no> - 2020-12-03 22:00 +0100
          Re: swamp rat bots Q Keith Christian <keith1christian@gmail.com> - 2020-12-03 22:30 +0100
      Re: swamp rat bots Q john doe <johndoe65534@mail.com> - 2020-12-03 16:40 +0100
  Re: swamp rat bots Q Andy Smith <andy@strugglers.net> - 2020-12-04 03:20 +0100
    Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 06:10 +0100
      Re: swamp rat bots Q Andy Smith <andy@strugglers.net> - 2020-12-04 07:10 +0100
        Re: swamp rat bots Q john doe <johndoe65534@mail.com> - 2020-12-04 07:40 +0100
          Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 08:00 +0100
        Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 07:50 +0100
          Re: swamp rat bots Q john doe <johndoe65534@mail.com> - 2020-12-04 08:20 +0100
          Re: swamp rat bots Q Andy Smith <andy@strugglers.net> - 2020-12-04 08:50 +0100
      Re: swamp rat bots Q "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2020-12-04 11:50 +0100
        Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 14:50 +0100
      Re: swamp rat bots Q Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-04 12:00 +0100
  Re: swamp rat bots Q "hdv@gmail" <hdv.jadev@gmail.com> - 2020-12-04 10:00 +0100
    Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 14:50 +0100
      Re: swamp rat bots Q Reco <recoverym4n@enotuniq.net> - 2020-12-04 18:40 +0100
        Re: swamp rat bots Q grumpy@mailfence.com - 2020-12-04 19:10 +0100
          Re: swamp rat bots Q Reco <recoverym4n@enotuniq.net> - 2020-12-04 19:20 +0100
            Re: swamp rat bots Q Carl Fink <carlf@panix.com> - 2020-12-04 19:30 +0100
            Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 21:00 +0100
        Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 21:00 +0100
          Re: swamp rat bots Q Tixy <tixy@yxit.co.uk> - 2020-12-04 22:20 +0100
            Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-04 23:10 +0100
              Re: swamp rat bots Q Tixy <tixy@yxit.co.uk> - 2020-12-04 23:40 +0100
                Re: swamp rat bots Q Gene Heskett <gheskett@shentel.net> - 2020-12-05 01:00 +0100
                Re: swamp rat bots Q Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-05 11:00 +0100
                Re: swamp rat bots Q elvis <elvis@dogonfire.com> - 2020-12-05 01:50 +0100
                Re: swamp rat bots Q grumpy@mailfence.com - 2020-12-05 02:00 +0100
    Web-bot tarpit aka spider trap (was: swamp rat bots Q) Nicolas George <george@nsup.org> - 2020-12-04 15:10 +0100
      Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) Gene Heskett <gheskett@shentel.net> - 2020-12-04 17:10 +0100
        Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) <tomas@tuxteam.de> - 2020-12-04 22:10 +0100
          Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) "Martin McCormick" <martin.m@suddenlink.net> - 2020-12-06 20:20 +0100
            Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) David Christensen <dpchrist@holgerdanske.com> - 2020-12-06 21:30 +0100
            Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) Charles Curley <charlescurley@charlescurley.com> - 2020-12-06 23:10 +0100
              Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) Gene Heskett <gheskett@shentel.net> - 2020-12-07 02:30 +0100
                Re: Web-bot tarpit aka spider trap (was: swamp rat bots Q) Doug McGarrett <dmcgarrett@optonline.net> - 2020-12-07 04:00 +0100

csiph-web