5 ms·
Fail2ban is not in the same realm as port knocking, and to "bin it" would be foolish security posture at best, and negligent at worst.
by hatradiowigwam 1y ago
Fail2ban is not in the same realm as port knocking, and to "bin it" would be foolish security posture at best, and negligent at worst.
- mdhb 1y agoI’m not super familiar with the intricacies of fail2ban and don’t currently understand why op made that claim but would very much like to know more because he is talking about a topic he is highly regarded for and I respect that. I just don’t have the context.
- Joel_Mckay 1y agoPort-knocking mainly mitigates slow distributed-brute-force login attacks, and works best when ports are interleaved with several tripwire black-hole and knock-port-close firewall rules. Use-cases: 1. helps auto-ban hosts doing port-scans or using online vulnerability scanners 2. helps reduce further ingress for a few minutes as the hostile sees the site is "down". Generally, try to waste as much of a problem users time as possible, as it changes the economics of breaking networked systems. 3. the firewall rule-trigger delay means hostiles have a harder time guessing which action triggered a IP ban. If every login attempt costs 3 days, folks would have to be pretty committed to breaking into a simple website. 4. keeps failed login log noise to a minimum, so spotting actual problems is easier 5. Easier to forensically analyze the remote packet stream when doing a packet dump tap, as only the key user traffic is present 6. buys time to patch vulnerable code when zero day exploits hits other hosts exposed services 7. most administrative ssh password-less key traffic should be tunneled over SSL web services, and thus attackers have a greater challenge figuring out if dynamic service-switching is even active People that say it isn't a "security policy" are somewhat correct, but are also naive when it comes to the reality of dealing with nuisance web traffic. Fail2ban is slightly different in that it is for setting up tripwires for failed email logins, and known web-vulnerability scanners etc. Then whispering that IP ban period to the firewall (must override the default config.) Finally, if the IP address for some application login session changes more than 5 times an hour, one should also whisper a ban to the firewalls. These IP ban rules are often automatically shared between groups to reduce forum spam, VoIP attacks, and problem users. Popular cloud-based VPN/proxies/Tor-exit-nodes run out of unique IPs faster than most assume. Have a nice day, =3
- akerl_ 1y agoIf a slow brute force attack is working on your system, all the port knocking and tripwires and whatever are just gimmicks. Don’t waste resources putting lipstick on the pig.
- Joel_Mckay 1y agoStolen password-less key bots are also common these days, and again it is more about reducing log noise. "Don’t waste resources putting lipstick on the pig." I would never kink-shame someone that ignored the recent CVE-2025-48416, that proved exposing unprotected services is naive =3
- akerl_ 1y agoIf somebody has a stolen credential, they aren’t going to be brute forcing at all. Likewise that CVE wouldn’t be attacked by a brute force attack. But I see you’ve backpedaled to this being about log noise, not security.
- Joel_Mckay 1y agoThreat detection is a higher security priority than prevention in my experience. One may believe whatever they like, as both our intentions are clear friend. Have a wonderful day =3
- akerl_ 1y agoIt's weird to assign them comparatively like that but also, what does that have to do with fail2ban? The roving spam it blocks are not threats, and stolen credentials aren't going to be detected by it.
- Joel_Mckay 1y agoIn general, bots/worms/clowns will first check if a host/router is already infected or vulnerable to a shim. Thus, tripwires on those checks or URI often auto-ban infected/hostile hosts before a scan fully escalates to a successful payload. Note, people don't want a VM delta-snapshot of their zero-day around for automated analysis. 99.98% of hostile traffic simply reuse already published testing tools, or services like Shodan to target hosts. One shouldn't waste resources guessing the motives behind problem traffic. =3
- deleted 1y ago[deleted]
- tptacek 1y agoNo, fail2ban is cargo cult security, and if you actually "need" it, you've misconfigured your system. Don't allow password authentication.
- deleted 1y ago[deleted]
- dugite-code 1y agoIMHO Fial2ban, just like port knocking, isn't cargo cult security. They are a single tool that can be included in a general system security arsenal, not the only tool you should use but one of a suite of tools that can be used depending on what you want to achieve. Personally I use fwknop for port knocking as it doesn't suffer from replay attacks as it's an encrypted packet. But still serves the same niche
- akerl_ 1y agoThe point being made is that unless "what you want to achieve" is "run a tool that isn't improving your security posture", port knocking isn't providing value to the security model. Hence the cargo cult.
- dugite-code 1y agoI can't agree that it's "a tool that isn't improving your security posture", if it's a layer on top of other tools, you might argue it's effectiveness isn't great but to say it's effectively nothing is a reach.