Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

fail2ban

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 05-Mar-2008, 09:55 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
fail2ban

I just ran across this little security-related utility today. I don't know if it's available for Windows, but it's an awesome little tool for *nix servers.

What it does is read the access logs, real time, for any service it is configured to protect, i.e., ftp server, web server, ssh, etc... and immediately bans IP addresses based upon failed logins. It puts an immediate halt to things such as dictionary attacks.

It is simple to configure, extremely easy to install and set up, and at the same time highly configurable. It will work with both standalone daemons and services made available through inetd or xinetd.

Here is a link to their home page. http://www.fail2ban.org/wiki/index.php/Main_Page



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #2  
Old 05-Mar-2008, 10:10 PM
Sparky's Avatar
Sparky Sparky is offline
Premium Member
Posts: 5,001
Points: 2421 Sparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 points
Power: 79
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCTS N+ A+
WIP: Server 2008 upgrade & 70-284
Handy utility that. One of my FTP servers is getting hammered with fake log-ins just now.


Me: You need to buy a couple of servers.
Customer: Whats wrong with the servers I have?
Me: Well, you dont have *any* servers just now.
Customer: WTF! I thought I did!

 
Reply With Quote
  #3  
Old 05-Mar-2008, 10:14 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
Quote:
Originally Posted by Sparky View Post
Handy utility that. One of my FTP servers is getting hammered with fake log-ins just now.
That it is. It's one of the handiest little security tools I've run across in a long time. Very little learning curve and very effective.



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #4  
Old 05-Mar-2008, 10:38 PM
S0l5 S0l5 is offline
New Member
Posts: 39
Points: 0 S0l5 has no points
Power: 1
None
Join Date: 04 Mar 2008
Not bad tool, might just use it on my SSH server, i was wandering got any tutorials or articles on securing SSH?

 
Reply With Quote
  #5  
Old 05-Mar-2008, 11:02 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
Quote:
Originally Posted by S0l5 View Post
Not bad tool, might just use it on my SSH server, i was wandering got any tutorials or articles on securing SSH?
Take a look at the following link and see if it helps.

http://blog.unixlore.net/2006/04/fiv...ecure-ssh.html



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #6  
Old 05-Mar-2008, 11:19 PM
hbroomhall hbroomhall is offline
Premium Member
Posts: 5,976
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 85
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
Er - securing SSH? It *is* secure - unless you do something silly.

If you want to read up on SSH get the O'Reilly book on it. Goes into a *lot* of detail.

Harry.

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 08:40 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages