Moin,
wie der Titel schon sagt geht es um das Tool Fail2ban.
Zuerst ein paar Infos zu meinem System.
Hardware:
Intel Core i5 (4*2,66ghz)
6GB DDR3- Ram
Software:
Debian lenny mit Plesk als Admin Panel auf dem aktuellen apt-get upgrade stand
nachdem ich heute Fail2ban via apt-get install fail2ban installiert habe wollte ich mit der Standard konfiguration die Funktionstüchtigkeit testen.
Also 5mal falsch eingeloggt, gefreut als mir Fail2Ban die korreckte E-Mail mit log auszügen, whois der IP und der IP gesendet hat.
Dann habe ich vergessen meinen Router zu reconecten, konnte mich dann aber erstaunlicherweise immernoch auf meinem Server einloggen.
Die fail2ban.log liefert folgendes zu Tage:
Bei einem "Ban" kommt dann noch folgendes hinzu:
Sprich es wird nix gebannt. Ein extra FirewallScript oder ähnliches habe ich nicht am laufen (von der Standard Plesk Firewall abgesehen).
Ich habe meine beiden conf dateien als .txt anhang angehängt, da es ansonsten etwas voll geworden wäre =)
Sollte noch etwas fehlen reiche ich es natürlich nach.
Im vorraus vielen dank für die Hilfe.
MfG
PS: Hier noch die Ausgabe von Iptables -L
wie der Titel schon sagt geht es um das Tool Fail2ban.
Zuerst ein paar Infos zu meinem System.
Hardware:
Intel Core i5 (4*2,66ghz)
6GB DDR3- Ram
Software:
Debian lenny mit Plesk als Admin Panel auf dem aktuellen apt-get upgrade stand
nachdem ich heute Fail2ban via apt-get install fail2ban installiert habe wollte ich mit der Standard konfiguration die Funktionstüchtigkeit testen.
Also 5mal falsch eingeloggt, gefreut als mir Fail2Ban die korreckte E-Mail mit log auszügen, whois der IP und der IP gesendet hat.
Dann habe ich vergessen meinen Router zu reconecten, konnte mich dann aber erstaunlicherweise immernoch auf meinem Server einloggen.
Die fail2ban.log liefert folgendes zu Tage:
Code:
2010-05-26 15:16:31,436 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.3
2010-05-26 15:16:31,437 fail2ban.jail : INFO Creating new jail 'ssh'
2010-05-26 15:16:31,437 fail2ban.jail : INFO Jail 'ssh' uses poller
2010-05-26 15:16:31,447 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2010-05-26 15:16:31,447 fail2ban.filter : INFO Set maxRetry = 3
2010-05-26 15:16:31,448 fail2ban.filter : INFO Set findtime = 600
2010-05-26 15:16:31,448 fail2ban.actions: INFO Set banTime = 600
2010-05-26 15:16:31,511 fail2ban.jail : INFO Jail 'ssh' started
2010-05-26 15:16:31,534 fail2ban.actions.action: ERROR iptables -N fail2ban-ssh
iptables -A fail2ban-ssh -j RETURN
iptables -I INPUT -p tcp -m multiport --dports ssh -j fail2ban-ssh returned 100
Code:
2010-05-26 15:17:23,635 fail2ban.actions: WARNING [ssh] Ban 217.232.47.176
2010-05-26 15:17:23,637 fail2ban.actions.action: ERROR iptables -n -L INPUT | grep -q fail2ban-ssh returned 100
2010-05-26 15:17:23,638 fail2ban.actions.action: ERROR Invariant check failed. Trying to restore a sane environment
2010-05-26 15:17:23,670 fail2ban.actions.action: ERROR iptables -N fail2ban-ssh
iptables -A fail2ban-ssh -j RETURN
iptables -I INPUT -p tcp -m multiport --dports ssh -j fail2ban-ssh returned 100
2010-05-26 15:17:23,672 fail2ban.actions.action: ERROR iptables -n -L INPUT | grep -q fail2ban-ssh returned 100
2010-05-26 15:17:23,672 fail2ban.actions.action: CRITICAL Unable to restore environment
Ich habe meine beiden conf dateien als .txt anhang angehängt, da es ansonsten etwas voll geworden wäre =)
Sollte noch etwas fehlen reiche ich es natürlich nach.
Im vorraus vielen dank für die Hilfe.
MfG
PS: Hier noch die Ausgabe von Iptables -L
Code:
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:8443
ACCEPT tcp -- anywhere anywhere tcp dpt:8880
ACCEPT tcp -- anywhere anywhere tcp dpt:www
ACCEPT tcp -- anywhere anywhere tcp dpt:https
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT tcp -- anywhere anywhere tcp dpt:submission
ACCEPT tcp -- anywhere anywhere tcp dpt:smtp
ACCEPT tcp -- anywhere anywhere tcp dpt:ssmtp
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3s
ACCEPT tcp -- anywhere anywhere tcp dpt:imap2
ACCEPT tcp -- anywhere anywhere tcp dpt:imaps
ACCEPT tcp -- anywhere anywhere tcp dpt:poppassd
ACCEPT tcp -- 91-143-83-148.blue.kundencontroller.de anywhere tcp dpt:mysql
DROP tcp -- anywhere anywhere tcp dpt:mysql
DROP tcp -- anywhere anywhere tcp dpt:postgresql
DROP tcp -- anywhere anywhere tcp dpt:9008
DROP tcp -- anywhere anywhere tcp dpt:9080
DROP udp -- anywhere anywhere udp dpt:netbios-ns
DROP udp -- anywhere anywhere udp dpt:netbios-dgm
DROP tcp -- anywhere anywhere tcp dpt:netbios-ssn
DROP tcp -- anywhere anywhere tcp dpt:microsoft-ds
DROP udp -- anywhere anywhere udp dpt:openvpn
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
DROP icmp -- anywhere anywhere icmp type 8 code 0
ACCEPT all -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
DROP all -- anywhere anywhere
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain fail2ban-ssh (0 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Attachments
Last edited by a moderator: