nostromos bLog | |||||
"bLog means boring-Log"
categories
* all entries (445)
* concerts (28)
* misc (120)
* techtalk (18)
* travel (241)
`-bruxelles_07 (8)
`-hongkong_09 (13)
`-iceland_10 (14)
`-ireland_16 (7)
`-newzealand_11 (5)
`-scandinavia_07 (22)
`-scandinavia_16 (17)
`-scotland_15 (11)
`-strasbourg_08 (4)
* zoo (38)
`-schoenbrunn (16)
chronology
|
Fri, 21 Feb 2014 the key (0 comments)
yippieh, we got the key to our new flat. awesome!
top [ ^ ]
Tue, 18 Feb 2014 fail2ban and badips.com (0 comments)
++ alert ++ tech-talk ++ alert ++ tech-talk ++ alert ++
having sshd on default port 22 will cause a lot of ssh brute-force attacks - every sysadmin knows this nuisance. so far i used freebsd's "pf" firewall with "max-src-conn-rate" and overloading the blacklisting table. to remove the banned ips after a while i used "expiretable". so far this worked fine, but it was for ssh connections only.
to also address other brute-force attacks, i tried "fail2ban", and added rules to block imaps bruteforce attacks. while doing research on the internet i came across a site that combines ip banning with reporting the ip to badips.com. so i included this one too, and now have a graphical representation of all the reported attacker ips. see it here.
isn't that lovely? also notice the cool ninja in the 8-bit style logo. strangely enough, since i set this all up, there are not many brute-force attacks. what's wrong with the internetz?
so far i like "fail2ban", except for it's really crappy documentation. it makes use of the power of regex to scan all kind of logfiles you feed to it. so this is really a powerful tool.
top [ ^ ]
Fri, 07 Feb 2014 cat cake (0 comments)
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaw, look what i got!
top [ ^ ]
|