4 ms·
There are several ways to deal with it. Basic: 1. SSH - security related - modify sshd config - no password auth, only key based, no root login, other than th
by daemon13 14y ago
There are several ways to deal with it.
Basic:
1. SSH - security related - modify sshd config - no password auth, only key based, no root login, other than that the default sshd config for Ubuntu 12.04 is pretty ok.
PermitRootLogin no
If you do not use IPv6, you can disable sshd to use it.
#ListenAddress ::
ListenAddress 0.0.0.0
2. SSH - ease of maintenance related - change default port from 22 to smth else. This will not help against targeted attacks, but this will reduce the noise in the logs and will allow better visibility of attack attempts.
#Port 22
Port 63777 (or whatever)
Don't forget to reload ssh for changes to take effect and check with netstat what's running where.
If you are concerned with getting locked out you can do this:
2.1. enable sshd to listen on multiple ports simultaneously
Port 22
Port 63777 (or whatever)
2.2. Login through Port 63777, and only then disable Port 22.
3. The PRC thing - fail2ban and hosts is simple but not the best tools for the job.
3.1. You can disable access to your site for all China (or any other country for this matter) using ipset. Much better speed and ease of maintenance, it's even better then using iptables itself [ipset is iptables module], one set can contain/block up to 65000+ IPs.
3.2. If you want smth more targeted, then consider either sshguard or psad. They can be configured to block inline and dynamically add rules [perm/temp] to iptables.
Edit: forgot to mention another cute recipe. see below
If you are on AWS and are using security groups (you should), after you are done on the server, you can go to the security group in AWS Mgt Console and remove ingress for ssh ports. Now your server is accessible only on 80/443 and ssh is NOT accessible to anyone. Later, when you need to access the server - enable ingress for the ssh ports, do your job and disable again.
- fluffle 14y agoThanks to all, and especially this post, for detailed security recommendations. I hope they convince others that security is important and not to be taken lightly. I don't really think that security-by-obscurity alone is a good enough solution. I already disable both root logins and passwords on my shell, and have something that tails logs to firewall IPs that are doing nasty things that show up in my logs. It's cute that you assume I'm running Linux though ;-) I ended up firewalling the entire /14 that /24 was assigned from, because, well, China bothers me...
- daemon13 14y agoGood it was helpful. Have a look at ipset. It is easy to use and very powerful. According to one of the sources China is appr. 5000 IP sub-nets only. one ipset can block up to 65000+. One of the sources for IP is MaxiMind - they shall have a free set of fresh IPs.