UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
Our Sponsors
Latest Postings
Burger King gone Wild!
by ZER0_DECEPTION
Today at 10:08 AM
PDX 2600
by rbcp
Yesterday at 12:46 AM
The Pirate Bay- shut down?
by ZER0_DECEPTION
08/05/08 09:07 PM
Windows Events for Changing Access rights to a folder or a File
by Gizmo
08/05/08 12:32 PM
question about IE and CSS
by §intå×
08/04/08 08:51 PM
Server
by Gizmo
08/01/08 01:29 AM
Miss mash of urban ledgends told so well
by ZER0_DECEPTION
07/28/08 06:35 AM
Geek Code Write in 1993 I like it
by Gizmo
07/18/08 11:05 PM
I read this and laughed
by Gizmo
07/18/08 10:58 PM
Vote for President
by IceMyst
07/18/08 06:38 AM
Topic Options
#17025 - 07/07/05 08:00 PM ssh/auth/apache security
busfault Offline
Junior Member

Registered: 12/20/04
Posts: 22
Loc: NY
I have a fair amount of Linux experience, however I am not sure what to do, or how to go about, working on this issue.
Currently I am allowing only a couple of ways to access my machine (300MHz Pentium with Debian Linux Unstable) of which are ftp, http, and ssh. I was looking through my logs and I am getting a bulk of traffic that is obvious script crap. For instance my auth.log is filled with invalid logins of numerous usernames, (alphabetic I may add) and in my Apache logs they are filled with obvious attempts to break Apache, well mostly Windows IIS.
So enough with the scenario, I would like to know how I can make it so that when there are numerous unwanted attempts that I can put their IPs into a blacklist that won't be allowed to connect to my machine at all. So that when that IP tries to connect it doesn't even get to the application. Then perhaps I would like to be able to let that address sit for a period of time before it is let back in, so that I don't block legitimate connections since person's IPs change.
Any help would be greatly appreciated.
_________________________
-----BEGIN GEEK CODE BLOCK-----
GCS/E d- s++:- a- C+++ UL+++ P+ L++ E-- W- N+ o-- K- w--- O M+ V-- PS++ PE-- Y+ PGP t+ 5++ X+ R+++ tv+ b++ DI++ D--- G++ e+ h r+++ y++++
------END GEEK CODE BLOCK------

Top
Our Sponsors
Sponsor Our Sponsors

Top  
#17026 - 07/08/05 01:38 AM Re: ssh/auth/apache security
Gizmo Administrator Offline
Community Owner
*****

Registered: 02/28/02
Posts: 6923
Loc: Portland, OR; USA
Use a non-standard port for SSH, disable Telnet; for your apache you can make a .htaccess file and ban ip's directly (I prefer masks myself); an example would be:

Taken directly from UGN's .htaccess file:
Code:
# Deny users IP's #
order allow,deny
#deny from 123.45.6.7 - Bans Direct IP
#deny from 012.34.5. - Bans IP block 012.34.5.*
#deny from .undergroundnews.com - bans host of *.undergroundnews.com
deny from .kestii.go.ro
allow from all
_________________________
Donate to UGN Security here.
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top



Moderator:  Infinite 
Forum Stats
6907 Members
44 Forums
10360 Topics
45095 Posts

Max Online: 677 @ 06/30/07 10:06 PM
Top Posters
Gizmo 6923
UGN Security 3341
§intå× 3250
IceMyst 1449
SilentRage 1273
Ice 1146
pergesu 1134
Infinite 1039
jonconley 954
Girlie 903
Newest Members
mcscrwdy25, mobi, rsreseller, Everest, naskweeky
6907 Registered Users
Who's Online
0 Registered (), 4 Guests and 5 Spiders online.
Key: Admin, Global Mod, Mod
Latest News
Update Humpday - Aug 06, 2008
by Gizmo
08/06/08 08:05 AM
Update Humpday - Jul 30th, 2008
by Gizmo
07/31/08 11:17 AM
Photo Gallery Update
by Gizmo
07/25/08 05:14 AM
Update Humpday - Jul 23rd, 2008
by Gizmo
07/23/08 01:02 PM
New Update Humpday
by Gizmo
07/17/08 08:21 AM


Donate

Get the Google FireFox Toolbar
Get Firefox!
Get FireFox!