5 ms·
If this doesn't get to install fail2ban don't know what will.
by OptionX 3y ago
If this doesn't get to install fail2ban don't know what will.
- lloydatkinson 3y agoAnd SSH key only login
- mdaniel 3y agoI was actually thinking about that: OT1H, fail2ban would really clean up the list, so it's not monopolized by the one joker, but OTOH given sufficient spans of time it would make the output go quiet, which for this specific case defeats the purpose I actually much prefer the projects that give the caller a fake shell, and watch what they type after "breaking in." It'd be the Kitboga of ssh attacks :-D
- Sodman 3y agoI would 100% watch the Kitboga of ssh attacks, is that something that exists today? The closest I've seen so far is password purgatory - https://www.troyhunt.com/sending-spammers-to-password-purgatory-with-microsoft-power-automate-and-cloudflare-workers-kv/ https://www.troyhunt.com/sending-spammers-to-password-purgat...
- OrangeMusic 3y ago> give the caller a fake shell, and watch what they type after "breaking in." Oh YES! Do it, please! We could learn a lot!
- nubinetwork 3y agoI believe one of ISC dshield's related projects can do this.
- mdaniel 3y agoThanks for the reference; after some link chasing I was able to end up on the project I believe you're thinking of: https://github.com/cowrie/cowrie#features https://github.com/cowrie/cowrie#features (appears to be BSD-3-Clause: https://github.com/cowrie/cowrie/blob/master/LICENSE.rst https://github.com/cowrie/cowrie/blob/master/LICENSE.rst )
- firstlink 3y agoI don't see the point of fail2ban on a server without password login, except to keep the log file tidy. That isn't worth risk of locking out legitimate users due to misconfiguration or user error. CMV.
- fragmede 3y agoKeeping the log file tidy isn't just an OCD thing. If you're searching for a needle in a haystack, where needle is "suspicious login", and the haystack is "all of the login attempts from the past the months", your job is made much easier when the haystack is much smaller. That said, the fail2ban defaults are way too low and I've locked myself out with them. They can be turned way up (ban after way many more attempts) so that there's no risk of locking out legitimate users. (Assuming your users didn't forget their exact password and then generated a small dictionary to try with.) On a server with potential misconfiguration, accepting passwords is one of them.