Hallo zusammen, ich hab da ein Problem mit meinem Bind Server. Wenn ich "tail -f /var/log/messages mache finde ich durchweg folgendes vor:
Habe mich bereits im Internet erkundigt und bin auf den Dienst "Fail2Ban" gestoßen. Leider bekomme ich diesen nicht richtig zum laufen.
In der Config steht u.a. folgendes:
Aber der Angriff nimmt leider nicht so richtig ab.
Wie kann man dieses Problem am effektivsten Lösen?
PHP:
Apr 7 00:45:23 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:23 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:24 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:25 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 72.20.23.24#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 72.20.23.19#53: query (cache) 'ripe.net/ANY/IN' denied
Apr 7 00:45:26 s16191893 named[3208]: client 92.106.237.75#25345: query (cache) 'isc.org/ANY/IN' denied
Habe mich bereits im Internet erkundigt und bin auf den Dienst "Fail2Ban" gestoßen. Leider bekomme ich diesen nicht richtig zum laufen.
In der Config steht u.a. folgendes:
PHP:
[named-refused-udp]
enabled = true
filter = named-refused
action = iptables-multiport[name=Named, port="domain,953,53", protocol=udp]
sendmail-whois[name=Named, dest=you@mail.com]
logpath = /var/log/named/security.log
ignoreip = 127.0.0.1
# This jail blocks TCP traffic for DNS requests.
[named-refused-tcp]
enabled = true
filter = named-refused
action = iptables-multiport[name=Named, port="domain,953,53", protocol=tcp]
sendmail-whois[name=Named, dest=you@mail.com]
logpath = /var/log/named/security.log
ignoreip = 127.0.0.1
Aber der Angriff nimmt leider nicht so richtig ab.
Wie kann man dieses Problem am effektivsten Lösen?