Skip to main content

fail2ban and sshutout for Mageia7


Fail2ban
 "Fail2ban is an extensible Swiss-army knife of brute-force authentication prevention and it comes with an additional filters to detect other attempts to compromise your system. If you do nothing but install it, run it, keep it updated and turn on its filters for any services you run, especially SSH, you will be far better off than you were otherwise." --  Greg Bledsoe


$ sudo urpmi fail2ban

Once installed, it will be started automatically. The configuration file is located in /etc/fail2ban.conf

$ sudo urpmi sshutout

Sshutout
Sshutout is Bill DuPree's system daemon that is intended to be run from the server startup script. It periodically monitors log files looking for multiple failed login attempts via the Secure Shell daemon (sshd, or optionally, sshd2). The daemon is meant to address what are known as "dictionary attacks" which are scripted, brute-force attacks that use lists of user names and passwords to attempt unauthorized intrusions.  You can use chkconfig to start it.

$ sudo chkconfig --level 5 sshutout on

The sshutout GitHub page has some pretty good - but brief - documentation of its use. The complete documentation is found in /usr/share/doc/sshutout/sshutout.html after you have installed the application. The configuration file is found at /etc/sshutout.conf.

The daemon reads /var/log/messages to see what intruders might be afoot, so you must also install rsyslog or syslog-ng if your system uses sysctl to run system services.


RESOURCES

fail2ban Wiki

Using fail2ban to Block Brute Force Attacks

fail2ban README

sshutout at GitHub

Comments

Popular posts from this blog

DOS4GW.EXE Version 2.01a and Alternative DOS Extenders

DOS4GW.EXE The Tenberry DOS extender DOS4GW.EXE was used by many early DOS games. I still enjoy playing many of these games and DOS4GW.EXE is usable with DOSBox , so they can be played on Linux. However, the version of DOS4GW.EXE that was included with the game was whatever was current at the time. The most recent version that includes many bugfixes that possibly affected the games when used with DOSBox have been fixed in the latest version, 2.01a. It's not free at US$49, but you can downloaded it here . Simply substitute it for whatever version of DOS4GW.EXE your game provided and enjoy the bug-fixed goodness. Tenberry also makes a "high-performance" "pro" version of DOS4GW.EXE, but it costs $300. I think that they could sell quite a few of these to hobby users (since, you know, DOS is dead) for US$5. Open Souce to the Rescue There are better performing, free and Open Source alternatives available and worth a look. DPMI Explained Let's unders

Unreal Tournament GOTY/UT99 for Modern Linux

Released on November 16, 1999, Unreal Tournament (also known as UT99) is an arena first-person shooter for Multiplayer on-line competition or you can play against bots off-line. It features several game types, with more details provided at Wikipedia . The game was re-released on February 25, 2000 as Unreal Tournament Game of the Year Edition (GOTY) which included the three bonus packs released previously and additional mods, or game modifiers that had become popular. It is the GOTY version that is available from STEAM or  GOG.com . The GOG version for Windows installs in Linux and plays well using WINE , PlayOnLinux or Codeweaver's Crossover . There is a Linux binary available in two versions, one for the original game and one for the GOTY edition . Also provided at that site is the Official Bonus Pack with a Linux installer. All these Linux installers are created with makeself . There are some issues using such a crusty old Linux binary. Let's see why getting a Lin

Burning 25GB M-Discs in Linux

The popular GUI DVD-authoring apps like K3B and Brasero, do not support burning ISO images in sizes greater than 4GB, which is odd, since they can detect the discs and can create an ISO image greater than 4GB. Please recognize that "4.7GB" is sleazy marketing misrepresenting GigaBytes, i.e. 1000  and not 1024. If translated to actual capacities, single layer DVD±R[W] capacity is only 4.4GB, and 26GB BluRay Disc is actually 23.3GB. Keep this in mind when creating your ISO images to burn manually. I purchased a Blue-Ray writer (an LG-brand Hitachi Model WP40NB30 )  hoping to use the 25GB M-Discs to archive some of the files I have accumulated spread out over several computers. Fortunately, the growisofs tool comes to the rescue, so from the command line, I just execute as a regular user: $ growisofs -speed=1 -Z /dev/sr1=big-image.iso I need the lower speed to keep from prematurely emptying the buffer which borks the disc. Although older, this page provides plenty