Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

possible to prevent break-in attempts over ssh?

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
7 posts • Page 1 of 1
Author
Message
dmccarthy
n00b
n00b
Posts: 2
Joined: Tue Jul 11, 2006 8:12 pm

possible to prevent break-in attempts over ssh?

  • Quote

Post by dmccarthy » Wed Aug 16, 2006 10:28 am

Hi,
I've a gentoo box on the internet. I occasionally see ssh break-in attempts in my /var/log/auth.log file, lines like

Code: Select all

Aug 15 13:34:00 www1 sshd[18547]: Invalid user vincent from 80.48.253.130
Aug 15 13:34:02 www1 sshd[18549]: Invalid user women from 80.48.253.130
repeated ad-nauseam from the same address, trying different usernames. Now the box is safe from this sort of attack as it only allows access via public key, but the attempts annoy me. Is there any tool out there that denies access from a specific ip address if too many dodgy usernames are attempted? Indeed, is there some other way of thwarting such script-kiddie nonsense?
Thanks
Denis
Top
Janne Pikkarainen
Veteran
Veteran
User avatar
Posts: 1143
Joined: Tue Jul 29, 2003 6:36 pm
Location: Helsinki, Finland
Contact:
Contact Janne Pikkarainen
Website

  • Quote

Post by Janne Pikkarainen » Wed Aug 16, 2006 10:34 am

emerge fail2ban. Very simple to setup and it automatically bans some IP address for some period of time after X failed login attempts.
Yes, I'm the man. Now it's your turn to decide if I meant "Yes, I'm the male." or "Yes, I am the Unix Manual Page.".
Top
wynn
Advocate
Advocate
User avatar
Posts: 2421
Joined: Fri Apr 01, 2005 10:45 am
Location: UK

  • Quote

Post by wynn » Wed Aug 16, 2006 11:23 am

The Handlers Diary Security Tip of the day: Handling brute-force login attempts has some useful tips.
The avatar is jorma, a "duck" from "Elephants Dream": the film and all the production materials have been made available under a Creative Commons Attribution 2.5 License, see orange.blender.org for details.
Top
dmccarthy
n00b
n00b
Posts: 2
Joined: Tue Jul 11, 2006 8:12 pm

  • Quote

Post by dmccarthy » Wed Aug 16, 2006 3:50 pm

I'll try it - thanks
Top
James Wells
n00b
n00b
User avatar
Posts: 57
Joined: Fri Sep 10, 2004 4:26 pm

  • Quote

Post by James Wells » Thu Aug 17, 2006 12:43 am

Greetings,

I tried fail2ban and didn't like it. Instead I use;

Code: Select all

iptables -A SSHD -p tcp -m state --state NEW -m recent --update --seconds 86400 --hitcount 3 --rttl -j DROPLOG
iptables -A SSHD -p tcp -m state --state NEW -m recent --set -j ACCEPT

iptables -A DROPLOG -m limit --limit 3/minute --limit-burst 10 -j LOG --log-prefix 'iptables Droplog: '
iptables -A DROPLOG -j DROP
Note that this method does not require any other packages than iptables and, for me anyway, works better than fail2ban and sshdfilter.
Top
Janne Pikkarainen
Veteran
Veteran
User avatar
Posts: 1143
Joined: Tue Jul 29, 2003 6:36 pm
Location: Helsinki, Finland
Contact:
Contact Janne Pikkarainen
Website

  • Quote

Post by Janne Pikkarainen » Thu Aug 17, 2006 7:34 am

James Wells: Wow. You must be the first one I've seen who doesn't like fail2ban. What was so annoying in it? :)
Yes, I'm the man. Now it's your turn to decide if I meant "Yes, I'm the male." or "Yes, I am the Unix Manual Page.".
Top
James Wells
n00b
n00b
User avatar
Posts: 57
Joined: Fri Sep 10, 2004 4:26 pm

  • Quote

Post by James Wells » Sat Aug 19, 2006 2:42 am

Janne Pikkarainen wrote:James Wells: Wow. You must be the first one I've seen who doesn't like fail2ban. What was so annoying in it? :)
It's not so much that I dislike it, more that I don't 'like' it.

The reasoning is fairly simple. The core functionality of both fail2ban and sshdfilter is using iptables to block port 22 access to specific hosts, based on source IP address. The solution I posted does the exact same thing, just without the extra bells and whistles which I really see no need for.

I should probably point out that this is one of the things I love most about Unix... There is always more than one right way to do things.
Top
Post Reply

7 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic