5 ms·
Fail2ban security update
- knyt 12y agoUnrelated to this disclosure, I have acquired quite a lot of Fail2Ban attack reports generated by hosts around the world. I put together an initial set of charts showing attacks by country; I was wondering if anyone had any ideas for interesting things that should be done to analyze/visualize the data. The data set contains the IP addresses for attacker and victim, the date, and the service name for each of a couple million attack reports. edit: https://int80k.com/ftb/ https://int80k.com/ftb/
- thaumaturgy 12y agoI wouldn't mind seeing that; your data eclipses mine by about a lot. Plotting your data on a world map would be kinda neat. D3.js is a good tool for that. Animate it over time for even more bonus points. :-) Or, scrub your information from the data and post it for others to mess with. I have several thousand entries for ssh, ssh-root, and spam abuse in my badhosts table.
- nick_riviera 12y ago+1 for this. Grouping by ASN and netblock owner would be nice as well. I'm happy to shoot down entire ISPs.
- knyt 12y agoDo you know where maps between IP addresses and ASNs/netblocks might be available for download? I can't immediately find this on IANA's website or on those of the RIRs, and I think it'd be too much to grab from whois.
- thaumaturgy 12y agoArin will allow you to download portions of their database for research purposes, but it requires an account and it looks like there's an approval process. You wouldn't have to query every IP, you'd just have to query IPs not covered by a result range from a previous lookup. I'd be willing to help on this; I have a whois module I wrote for another spam tool, I should be able to pretty easily adapt it for this.
- alepper 12y agohttp://www.routeviews.org http://www.routeviews.org provides access to live and snapshot BGP data.
- knyt 12y agoI think that change over time could be pretty cool, especially if the host locations can be resolved down to the city or province. I'll check out D3.js. I did a first take using Kartograph: https://int80k.com/ftb/ https://int80k.com/ftb/
- thaumaturgy 12y agoNice. And I see now why you're not wanting to release the data: I thought this was data on your network. Good job grabbing that email address.
- ForHackernews 12y agoHow do you own mail.com?
- gioele 12y agoHave you seen https://www.dshield.org/ https://www.dshield.org/ by SANS ISC? «DShield is a community-based collaborative firewall log correlation system. It receives logs from volunteers world wide and uses them to analyze attack trends.»
- castorio 12y agosimilar approach: https://8ack.de/honeypot/ https://8ack.de/honeypot/ check the Country-Page
- whiteagle 12y agoThank you for this, I'll better start upgrading my servers...
- sneak 12y agoFail2ban is fundamentally a wrong answer to the problem. If you're taking the time to install such things, you should instead either be turning off password authentication (relying only on keys) or shorewall (to default deny ssh access except to authorized subnets) or both. Waiting for multiple authentication failures to mark a host/net as "bad" is fundamentally a bad idea. Stop using passwords.
- thomaslutz 12y agoWhy can't I use key-based auth and fail2ban as well? E.g. to prevent DDoSing. Fail2Ban does more than just monitor SSH.
- knyt 12y agoI've used Fail2Ban even with SSH password authentication turned off. It's still helpful for preventing huge error logs full of pointless password guesses. It's also useful for applications where you have to use passwords or where you need to allow anonymous requests but you don't want attackers using up all of your resources. VoIP (public-facing and handset-facing SIP) servers are my example of both of those situations.
- justizin 12y agoright, anyone who has undergone frequent ssh brute force attacks knows that they can create a nontrivial amount of cpu usage.
- daviddede 12y agoNot new: http://dcid.me/texts/attacking-log-analysis-tools.html http://dcid.me/texts/attacking-log-analysis-tools.html It had a similar vuln many years ago.
- kolev 12y agoYou don't need fail2ban, you need fwknop.
- NickSharp 12y agoIn case anyone needs it, here is the command line to patch fail2ban: sudo apt-get update sudo apt-get install --only-upgrade fail2ban Although it's considered best practice to upgrade all packages, like this: sudo apt-get update sudo apt-get upgrade
- stevekemp 12y agoNote that Debian release do not install sudo by default, unlike Ubuntu. So if you have not installed sudo, or do not have permission to use it, then you should use "su - " to become root, then run "apt-get update;apt-get upgrade".