
13th July 2006, 20:07
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 377
Thanks: 3
Thanked 2 Times in 2 Posts
|
|
How to ban failed SSH, FTP, POP3 and SMTP logins?
So, as title says I am interested in findig the best possible way to ban all of IP's from where failed logins originate for ssh, ftp, pop3 and smtp services.
I past few days few hackers from China are permanently trying to login in any/all of those services. My complaints to their network's hostmasteers were hopeless.
As I am still under attack 24h daily, I am open to all sugestions.
P.S. DenyHosts installed for SSH. Logcheck too.
|

13th July 2006, 21:21
|
|
Pseudo Lawyer
|
|
Join Date: Apr 2006
Location: Switzerland
Posts: 857
Thanks: 3
Thanked 25 Times in 23 Posts
|
|
For SSH I have this running:
http://www.howtoforge.com/preventing...with_denyhosts
on Debian Sarge and a SuSE 9.2 server
Oh, you have DenyHosts already ^^
|

13th July 2006, 21:32
|
|
Moderator
|
|
Join Date: Dec 2005
Location: The Netherlands
Posts: 1,721
Thanks: 148
Thanked 98 Times in 91 Posts
|
|
Not sure if FWSNORT is of use to you..
I'm using PSAD, but thats a Port Scan Attack Detector.
|

13th July 2006, 21:35
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 377
Thanks: 3
Thanked 2 Times in 2 Posts
|
|
How to use DenyHosts for FTP or mail login ? Is it possible?
|

13th July 2006, 22:41
|
|
Moderator
|
|
Join Date: Dec 2005
Location: The Netherlands
Posts: 1,721
Thanks: 148
Thanked 98 Times in 91 Posts
|
|
An other one I just found.. Fail2Ban
|

14th July 2006, 13:37
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,853
Thanks: 781
Thanked 1,558 Times in 1,477 Posts
|
|
|

14th July 2006, 14:05
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 377
Thanks: 3
Thanked 2 Times in 2 Posts
|
|
Thank you.
After I reported attacks to china network hostmaster attacks siezed, for now.
But I will install some of these solutions.
BTW does DenyHosts and BlockHosts interfere one with another?
on the other hand I have toughts about installing FreeSCO or IPCop on separate machine instead of hardware router...?
Which one is better FreeSCO or IPCop ?
|

14th July 2006, 14:09
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 377
Thanks: 3
Thanked 2 Times in 2 Posts
|
|
Quote:
|
Originally Posted by edge
|
Some people are claiming that there are some problems with it.
BTW all of the solutions are mostly for SSH or FTP but I need solutions for SMTP and POP3 as I noticed that hackers are trying to break in mail server too. Probably they want to use it for spaming. What is the best solution to keep seafe mail server from brute force password crack?
|

14th July 2006, 14:12
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 830
Thanks: 5
Thanked 41 Times in 36 Posts
|
|
One thing for smtp stuff from china would be greylisting... (postgrey)...
If I got the time I will post sth. how to use with ISPConfig...
Regarding the SSH-Stuff, I just moved my SSH port, since then I did not find any scan for ssh...
For that purpose I disabled the ISPConfig firewall (because it does not let me close port 22) and set it up on the shell via firehol
|

14th July 2006, 14:17
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 377
Thanks: 3
Thanked 2 Times in 2 Posts
|
|
Quote:
|
Originally Posted by Ben
One thing for smtp stuff from china would be greylisting... (postgrey)...
If I got the time I will post sth. how to use with ISPConfig...
Regarding the SSH-Stuff, I just moved my SSH port, since then I did not find any scan for ssh...
For that purpose I disabled the ISPConfig firewall (because it does not let me close port 22) and set it up on the shell via firehol
|
When attack occurs, and that could be in middle of night, I don't have time to ask for "graylist". Password chechk which occurs dozen times pre second can put significant load on server. Only "ban" method is solutions in such occurences.
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 06:42.
|
Recent comments
22 hours 9 min ago
1 day 3 hours ago
1 day 3 hours ago
1 day 3 hours ago
1 day 4 hours ago
1 day 6 hours ago
1 day 9 hours ago
1 day 9 hours ago
1 day 9 hours ago
1 day 11 hours ago