9 ms·
Thanks, I was unaware of this---I initially (naively?) thought that being banned would at least deter some wannabe attackers. In your experience, does it do any
by Topolomancer 5y ago
Thanks, I was unaware of this---I initially (naively?) thought that being banned would at least deter some wannabe attackers. In your experience, does it do anything if I start collecting some reports on repeat offenders and notify their ISP? Or is that just more wishful thinking of my part?
- tptacek 5y agoAbsolutely nothing will be done about reports of people running SSH scanners against your host; it would be like Cnut on his seashore throne ruling the waves to recede: even in the unlikely event that a hosting provider shut someone off (we probably would, if you told us), they'd be followed by 10,000 more.
- Topolomancer 5y agoThanks for the reality check, I appreciate it! At least I got a nice map out of this (and made sure that nothing was configured incorrectly, to the best of my knowledge)...
- bombcar 5y agoYou can get a similar reduction in ssh scans simply by moving the port (and doing nothing else) as the majority of scans only hit port 22. Whether this is worth the hassle is left to the reader: if you have passwords disabled and only use keys it really shouldn’t matter.
- creeble 5y agoIn my experience, they find it anyway. I've run ssh on non-standard ports for over 20 years, and my auth.log is gets a hundred knocks an hour - and mind you, they all return "no key". It's just life, and it will continue to get worse. Secure your server and ignore it.
- pvg 5y agoruling the waves This aggression will not stand
- NavinF 5y agoEh I’ve scanned the entire IPv4 space and tested default passwords over ssh from both AWS and my Comcast connection at home and never got banned from either one. I’m sure it can happen, but it’s no big deal. The GP is right: If you use ed25519 keys, looking at logs and playing whack a mole with countries is just security theater for people who are new to the internet and get scared when their MOTD says “500 failed logins”.
- arjvik 5y agoHow long did scanning the entire IPv4 space take?
- NavinF 5y ago~4 hours on a 1G port, IIRC I’m sure you could do it a lot faster with a better CPU and 20% commit on a 10G port
- kkirsche 5y agoThat depends on the machine you are using. Tools like mass scan to locate open ssh ports and then testing them doesn’t need to take long if you have a beefy machine and pipe to the internet.
- chockchocschoir 5y agomasscan with the right setup (namely hardware + drivers but also connection obviously) can scan the entire IPv4 space (+ all ports) in ~5 minutes. Source Code: https://github.com/robertdavidgraham/masscan https://github.com/robertdavidgraham/masscan Article from PoC || GTFO with more internal details on how it works: https://www.alchemistowl.org/pocorgtfo/pocorgtfo15.pdf https://www.alchemistowl.org/pocorgtfo/pocorgtfo15.pdf (Page 66) [Note: PDF is both a valid PDF + valid ZIP file with source code]
- cube00 5y agoAs an individual your reports will likely be ignored, however if you do want to report consider contributing to a service like AbuseIPDB. It probably doesn't do much either but at least it feels like I'm doing my part to report abuse and maybe some ISPs will choose to act on it.
- klausagnoletti 5y agoThat's one of many reason why https://crowdsec.net/ https://crowdsec.net/ was created. It collects (anonymized) threat intelligence from all users, vets it and distributes it as relevant blocklists. Once there's enough users it will be a very effective way to fight bad guys. And unlike your suggestion it DOES make a difference. Currently around 800k signals are collected daily and around 19k vetted malevolent ips are distributed to users on a daily basis.
- taf2 5y agoYou should just not allow any IP to access your server to begin with… have a list of trusted IPs - this and only allow public / private key access with a second factor device and I think you should be good…
- 71a54xd 5y agoI like to be able to maintain contact with my servers outside of a few specific ip's - I've locked myself out far too many times when I whitelist a very small number. Anyone have a better workaround for this?
- whartung 5y agoPerhaps a port knock. I don't know the mechanics, but a port knock is hitting pre-defined ports in a pre-defined order. When you "shave and a haircut" the ports properly, the server opens something up. In this case white listing (gray listing?) the IP that the knock came from. You could add a layers to it to make it more complicated.
- tptacek 5y agoPlease don't use silly stuff like port knocking. Your SSH server already does a cryptographically sound authentication step. "Port knocking" is even more performative than fail2ban.
- PeterisP 5y agoIMHO there's no need to worry (but you should disable password access), but if you really want to, port knocking is an option.
- stock_toaster 5y agoMaybe use spiped[1] if you are worried about ssh security? [1]: https://www.tarsnap.com/spiped.html https://www.tarsnap.com/spiped.html
- randomtwiddler 5y ago
- ufmace 5y agoI don't think this idea is aligned with how these types of attacks actually work. The dumb stuff like this is almost entirely automated, nobody will notice enough to be deterred by it. Possibly whoever is running it will get a list of servers where the bruteforce login attempts worked, or maybe they just get some kind of low-effort thing like cryptominer or spam server installed automatically. If an actual person of at least modest skill takes an interest in your server in particular, they're probably not going to do the sorts of things that would trigger fail2ban anyways. They're going to do things like probe around as lightly as possible to determine which services and which versions are running where to try and find things that are misconfigured or at known-vulnerable versions.