38 ms·
Is it normal to get hundreds of break-in attempts per day?
- kristofferR 16y agoI've noticed this too. Almost immediately after I signed up and created a hosting account with KnownHost, the hacking attempts started, even before I had logged in to Cpanel for the first time. I got an automated email every time somebody failed to log in, so my iPhone was plinging every few seconds for 30 minutes before I added a filter in GMail to mark those mails as read. I've since installed fail2ban.
- eli 16y agoI've got a script set up to scan my logs and temporarily ban clearly malicious IPs. It finds a few hundred new ones each day.
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- hvs 16y agofail2ban does a nice job of this.
- njharman 16y agoI'd say hundreds is not normal. It is order of magnitude too low.
- wtn 16y agoHow would you define an order of mangitude in this case?
- seiji 16y agoAt times, a few hundred per minute is "normal." I prefer port knocking or two factor auth as a solution to brute force attacks. http://code.google.com/p/google-authenticator/ http://code.google.com/p/google-authenticator/
- lsc 16y agoeh, disabling password auth solves the problem almost as well.
- epenn 16y agoMy home firewall catches 20-25 failed login attempts per day, all of which seem to originate in China. I'm tempted to setup a honeypot that'll show a fake bash prompt just to see what gets thrown at it. Naturally I assume there is an elite international force that will stop at nothing to break in and steal the larger original jpegs of my Facebook photos as well as all of my college homework. I'm on to you, elite international force!
- nickbp 16y agoThey're likely more interested in obtaining hops from which to attack other machines.
- jamroom 16y agoYou can eliminate 99% of these attempted logins by changing your SSH port from the standard 22 to something else (say 2177 or whatever). Login as root (or su), open the /etc/ssh/sshd_config file and change the port number. Save your changes and restart ssh with "/etc/init.d/ssh restart" and you are good to go. You'll want to update any SSH clients you use to use the proper port (-p option on command line). Hope this helps!
- drdaeman 16y agoThis won't give you much security (most of entropy is in your password/keyfile), but will highly lower the convenience, because you'd have to use `-p 2177` or put the port number in `$HOME/.ssh/config`. Same goes to port-knocking. Just throw in denyhosts/fail2ban, and follow simple rules (no root login, no password/keyboard-interactive logins, possibly, except for special emergency "oh-shit-i've-lost-my-keyfile" account with secure passphrase and non-dictionary username), and you'll be perfectly safe.
- eru 16y agoYou are right about the entropy in one sense. So against a determined attacker the port does not matter. On the other hand, most drive-by attackers won't bother going for the other ports. Perhaps you can make some argument involving the probability/entropy/information of the attacks vs your defenses.
- ulf 16y agoEven better is to additionally setup a fake SSHd at port 22, so that port scanners do not even bother keeping on looking for the port and instead use what they suspect to be working
- mfontani 16y agoI use https://code.google.com/p/kippo/ https://code.google.com/p/kippo/ as a ssh honeypot, and https://github.com/mfontani/kippo-stats https://github.com/mfontani/kippo-stats to display stats about it (number of attempts, successful logins, most usernames tried, most passwords tried for "root"). The data is quite interesting. Here's a snapshot of where most "attacks" to my honeypot originate from (the more, the brighter): http://darkpan.com/files/latlong255.png http://darkpan.com/files/latlong255.png
- mike-cardwell 16y agosudo apt-get install denyhosts Job done.
- chrisaycock 16y agoThere's also fail2ban, which monitors more services than just SSH: http://www.fail2ban.org/ http://www.fail2ban.org/
- troels 16y agoHave never heard of this tool before. Is it a standard thing or is it only for the clinically paranoid?
- bediger 16y agoI'm too lazy and too stupid to put in denyhosts or any of the other anti-guessing software, but I have put in a 7-second delay on password-authenticated SSH logins, as per http://www.aerospacesoftware.com/howtos/ssh-kiddies.html http://www.aerospacesoftware.com/howtos/ssh-kiddies.html That makes my sshd less a honeypot and more a tarpit. I also put in an output line so I can see what passwords they're guessing.
- tvon 16y agoFWIW, denyhosts and mod-security don't seem to require any real additional configuration beyond just installing them on Ubuntu 10.10 (and copying the example config for mod-security from /usr/share/doc/mod-security-common/examples).
- 9ec4c12949a4f3 16y agoSimilar thing happens on other levels. For instance, web logs contain pages of failed logins to phpmyadmin (it's not even installed on the server, lol).
- fretlessjazz 16y agoI run Rails and became tired of seeing 404s to standard ASP or PHP software (such as phpmyadmin), so I added this to our Apache conf: RewriteRule \.(asp|aspx|php|jsp)$ - [F,L,NC] RewriteRule (w00tw00t) - [F,L,NC] RewriteRule (phpmyadmin) - [F,L,NC] RewriteRule (php-my-admin) - [F,L,NC] That cuts off those requests before they hit a Rails process and suck up any additional resources.
- mfontani 16y agoOn Lighty, I simply have: url.redirect = ( "^(.*)php(.*)$" => "http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.37.3.tar.bz2", # other stuff ) I do not use php on the server.. I don't know if these kits end up downloading the kernel or not, though.
- buro9 16y agoPlease don't do this... having bots launch a DDoS attack on kernel.org is not good. Just throw the request away or return a 404 at the load balancer level. If you're on Apache use mod_security, if you're not put Varnish in front and configure it to return simple 404 errors on such pages. But don't mod_rewrite, redirect or otherwise throw traffic onto someone else's server, let alone one that will result in a traffic cost for them.
- T-hawk 16y ago> Please don't do this... having bots launch a DDoS attack on kernel.org is not good. Yeah, point them at microsoft.com instead! Should be easy to find a hefty service pack or DirectX install for the bots to hit...
- xorglorb 16y agoEven though not all of us like Microsoft, you still shouldn't do this. The best way to handle this is to send random data at 10b/s and slow down the bots.
- ck2 16y agoYou MUST try the free and awesome configserver firewall http://configserver.com/cp/csf.html http://configserver.com/cp/csf.html It's fantastic. Among a million other things, monitors logs for several kinds failed login attempts and can automagically ban them via iptables (with timeouts if you so desire). Be sure to donate to keep this fantastic software alive if you use it.
- tcopeland 16y agoAs some of the commenters on serverfault suggested, the easiest fix is to just disable password auth in sshd_config. No need to fool with denyhost's whitelisting and whatnot, just use public key auth only.
- megamark16 16y agoThis and changing the port to something non standard is what keeps me sleeping like a baby at night.
- mbailey 16y agoYes. And I'm sure it's been said: fail2ban
- asnyder 16y agoDenyhosts is pretty good too.
- wingo 16y agoI went to look at my logs and realized I forgot both my own and root's password on my linode. Doh!
- edu 16y agouse private/public key to login!!!
- wingo 16y agoI do indeed; that's why I had forgotten my password, because I always log in with my key. Amusing, this!
- getsat 16y agoYou'll have to reboot the Linode to change the root password from your control panel. Do not use passwords to auth over SSH! Use ssh-keygen to generate a key and copy the contents of the .pub to your ~/.ssh/authorized_keys and disable PasswordAuthentication in /etc/ssh/sshd_config and /etc/init.d/ssh reload
- maratd 16y agoThere are really two issues here. One is SSH and the other is HTTP. SSH is easy. Get a static ip or figure out the ip range for your ISP. Drop any connection not in that IP range using iptables on that port. Done. HTTP requires more creativity. It really depends on how you have things set up. I have a honeypot default vhost on Apache. If you enter just the IP address for the server, you get the honeypot. That's what most of these bots will hit. The 404 errors caused are very annoying and mess up the logs. On the honeypot, I have a RewriteRule that rewrites anything that would cause a 404 to index.html which is a blank page.
- idm 16y agoUse a VPN (openvpn), and attach sshd to your VPN subnet instead of using 0.0.0.0 or your publicly routable IP. This is also great for any other services you might want to administer remotely. It's normal to bind your database/cache to 127.0.0.1, but you can also bind to an IP in your VPN subnet, which makes it a little easier than tunneling through SSH to access your database.
- Vivtek 16y agoYes. Well - actually, no. Mere hundreds are kind of abnormally low.
- yalogin 16y agoFor SSH break-in attempts an easier solution would be to use a random (at least alpha numeric) userid. These dictionary based attacks only use standard, most generic login ids.
- JoshTriplett 16y agoNo need to bother making your userid cryptographically secure; either turn off passwords or use a secure password. It doesn't matter whether the bots find a valid username, as long as they can't guess your password.
- bkaid 16y agoI created a free test server on Windows Azure a few weeks ago with remote desktop access enabled and had failed login attempts within 2 minutes of the server going live, without publishing the ip address or dns name anywhere.
- sucuri2 16y agoOSSEC (open source) is very good at blocking those. It looks at all your logs and blocks brute forces via SSH, HTTP, etc... Link: http://ossec.net http://ossec.net
- jarin 16y agoIf you're running a Rails server on Ubuntu, protecting your server is as simple as deploying your app with Moonshine, with the ssh, iptables, and denyhosts plugins. It requires maybe 7-10 lines of configuration to have a fairly well-insulated system: # config/moonshine.yml :ssh: :port: 9024 :allow_users: - rails # app/manifests/application_manifest.rb configure({ :denyhosts => { :admin_email => 'admin@example.com' } }) recipe :ssh recipe :iptables recipe :denyhosts
- aquarin 16y agoI have thousands attempts at my nginx server mostly from China and most of them checking for free proxy server. I am even convinced it is some sort of automatic software scanning IP ranges for proxy. Freedom is difficult in some countries.
- aquarin 16y agoIf you see requests like: "GET http://somesite/proxycheck.php http://somesite/proxycheck.php Try this in Nginx server config: if ($request ~* "^[^ ]+[ ]+[^:]+://" ) { return 444; } 444 is nonstandard Nginx code that closes the connection without sending any headers.