3 ms·
You may have accidentally reinvented https://en.wikipedia.org/wiki/Fail2ban https://en.wikipedia.org/wiki/Fail2ban :)
by ringzero 7y ago
You may have accidentally reinvented https://en.wikipedia.org/wiki/Fail2ban https://en.wikipedia.org/wiki/Fail2ban :)
- JeremyMorgan 7y agoThat wasn't really the point of the article, I'm showing how to gather data on where they came from. Blocking is completely optional, and not for everyone.
- bdamm 7y agofail2ban is saving my bacon right now.
- ryanlol 7y agoFrom what? Generally fail2ban only exposes unnecessary attack surface while providing zero benefit.
- omgwtfbyobbq 7y agoHow does fail2ban expose attack surface?
- detaro 7y agoIt's code running on partially attacker-controlled inputs. It several times had vulnerabilities that allowed an attacker to trigger blocks for arbitrary IPs.
- cyc115 7y agoI remember there's a privEsc on old versions of fail2ban.
- omgwtfbyobbq 7y agoDo you remember roughly when the privEsc was? https://www.cvedetails.com/vulnerability-list/vendor_id-5567/Fail2ban.html https://www.cvedetails.com/vulnerability-list/vendor_id-5567...
- ryanlol 7y agoSketchy parsers operating on untrusted, unstructured log data. fail2ban is worse than useless.