
13th July 2006, 19:07
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 414
Thanks: 13
Thanked 5 Times in 5 Posts
|
|
How to ban failed SSH, FTP, POP3 and SMTP logins?
So, as title says I am interested in findig the best possible way to ban all of IP's from where failed logins originate for ssh, ftp, pop3 and smtp services.
I past few days few hackers from China are permanently trying to login in any/all of those services. My complaints to their network's hostmasteers were hopeless.
As I am still under attack 24h daily, I am open to all sugestions.
P.S. DenyHosts installed for SSH. Logcheck too.
__________________
Nenad Bulatovic
---------------
Debian Lenny & ISPConfig 3
|

13th July 2006, 20:21
|
|
Local Meanie
|
|
Join Date: Apr 2006
Location: Switzerland
Posts: 1,046
Thanks: 4
Thanked 34 Times in 32 Posts
|
|
For SSH I have this running:
http://www.howtoforge.com/preventing...with_denyhosts
on Debian Sarge and a SuSE 9.2 server
Oh, you have DenyHosts already ^^
|

13th July 2006, 20:32
|
|
Moderator
|
|
Join Date: Dec 2005
Location: The Netherlands
Posts: 2,010
Thanks: 254
Thanked 134 Times in 120 Posts
|
|
Not sure if FWSNORT is of use to you..
I'm using PSAD, but thats a Port Scan Attack Detector.
|

13th July 2006, 20:35
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 414
Thanks: 13
Thanked 5 Times in 5 Posts
|
|
How to use DenyHosts for FTP or mail login ? Is it possible?
__________________
Nenad Bulatovic
---------------
Debian Lenny & ISPConfig 3
|

13th July 2006, 21:41
|
|
Moderator
|
|
Join Date: Dec 2005
Location: The Netherlands
Posts: 2,010
Thanks: 254
Thanked 134 Times in 120 Posts
|
|
An other one I just found.. Fail2Ban
|

14th July 2006, 12:37
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,595 Times in 2,446 Posts
|
|
|

14th July 2006, 13:05
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 414
Thanks: 13
Thanked 5 Times in 5 Posts
|
|
Thank you.
After I reported attacks to china network hostmaster attacks siezed, for now.
But I will install some of these solutions.
BTW does DenyHosts and BlockHosts interfere one with another?
on the other hand I have toughts about installing FreeSCO or IPCop on separate machine instead of hardware router...?
Which one is better FreeSCO or IPCop ?
__________________
Nenad Bulatovic
---------------
Debian Lenny & ISPConfig 3
|

14th July 2006, 13:09
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 414
Thanks: 13
Thanked 5 Times in 5 Posts
|
|
Quote:
|
Originally Posted by edge
|
Some people are claiming that there are some problems with it.
BTW all of the solutions are mostly for SSH or FTP but I need solutions for SMTP and POP3 as I noticed that hackers are trying to break in mail server too. Probably they want to use it for spaming. What is the best solution to keep seafe mail server from brute force password crack?
__________________
Nenad Bulatovic
---------------
Debian Lenny & ISPConfig 3
|

14th July 2006, 13:12
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
One thing for smtp stuff from china would be greylisting... (postgrey)...
If I got the time I will post sth. how to use with ISPConfig...
Regarding the SSH-Stuff, I just moved my SSH port, since then I did not find any scan for ssh...
For that purpose I disabled the ISPConfig firewall (because it does not let me close port 22) and set it up on the shell via firehol
|

14th July 2006, 13:17
|
|
Senior Member
|
|
Join Date: Nov 2005
Location: Novi Sad, Serbia
Posts: 414
Thanks: 13
Thanked 5 Times in 5 Posts
|
|
Quote:
|
Originally Posted by Ben
One thing for smtp stuff from china would be greylisting... (postgrey)...
If I got the time I will post sth. how to use with ISPConfig...
Regarding the SSH-Stuff, I just moved my SSH port, since then I did not find any scan for ssh...
For that purpose I disabled the ISPConfig firewall (because it does not let me close port 22) and set it up on the shell via firehol
|
When attack occurs, and that could be in middle of night, I don't have time to ask for "graylist". Password chechk which occurs dozen times pre second can put significant load on server. Only "ban" method is solutions in such occurences.
__________________
Nenad Bulatovic
---------------
Debian Lenny & ISPConfig 3
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 11:04.
|
Recent comments
1 day 9 hours ago
1 day 14 hours ago
1 day 19 hours ago
1 day 21 hours ago
2 days 11 hours ago
2 days 11 hours ago
2 days 16 hours ago
2 days 22 hours ago
2 days 23 hours ago
3 days 59 min ago