Re: [CentOS] Dealing with brute force attacks

2009-05-17 Thread James Matthews
What you can try doing is putting some services on a non standered port (like SSH on port 4583) This will stop most (not all) attacks coming in at port 22. James On Fri, May 15, 2009 at 8:21 PM, James B. Byrne byrn...@harte-lyne.cawrote: On: Thu, 14 May 2009 13:00:09 -0700, Scott Silva

Re: [CentOS] Dealing with brute force attacks

2009-05-15 Thread William Merlotto
Hi! I suggest another software, OSSEC (http://www.ossec.net/). It's more complete (and complex) than fail2ban. Regards, -- William -- Prognus Software Livre http://www.prognus.com.br 2009/5/15 Robert Heller hel...@deepsoft.com At Thu, 14 May 2009 13:00:09

Re: [CentOS] Dealing with brute force attacks

2009-05-15 Thread James B. Byrne
On: Thu, 14 May 2009 13:00:09 -0700, Scott Silva ssi...@sgvwater.com wrote: http://packages.sw.be/fail2ban/ Thank you, got it. In the meantime I revised my existing iptables rules to throttle connections to ssh, pop3, imap and ftp (which service is not running in any case). Thanks for all

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Chris Boyd
On May 14, 2009, at 9:46 AM, James B. Byrne wrote: 2. Moving pass the obvious and unhelpful everything, what services are particularly vulnerable to these types of attacks? Does a list exist anywhere? If it's reachable over the 'net, it will eventually get pounded. POP, IMAP, SMTP Auth,

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Bill Campbell
On Thu, May 14, 2009, James B. Byrne wrote: Over the weekend one of our servers at a remote location was hammered by an IP originating in mainland China. This attack was only noteworthy in that it attempted to connect to our pop3 service. You might look at fail2ban which can automatically create

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Rudi Ahlers
On Thu, May 14, 2009 at 5:48 PM, Bill Campbell cen...@celestial.com wrote: On Thu, May 14, 2009, James B. Byrne wrote: Over the weekend one of our servers at a remote location was hammered by an IP originating in mainland China. This attack was only noteworthy in that it attempted to connect

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread David G . Miller
James B. Byrne byrn...@... writes: Over the weekend one of our servers at a remote location was hammered by an IP originating in mainland China. This attack was only noteworthy in that it attempted to connect to our pop3 service. We have long had an IP throttle on ssh connections to

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Lanny Marcus
On Thu, May 14, 2009 at 9:46 AM, James B. Byrne byrn...@harte-lyne.ca wrote: Over the weekend one of our servers at a remote location was hammered by an IP originating in mainland China.  This attack was only noteworthy in that it attempted to connect to our pop3 service. About 6 years ago,

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread James B. Byrne
On: Thu, 14 May 2009 08:48:36 -0700, Bill Campbell cen...@celestial.com wrote: You might look at fail2ban which can automatically create iptables blocks when things like this happen. I went to the source forge website, but the rh rpm is inaccessible. I really do not wish to join yet another

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Rudi Ahlers
On Thu, May 14, 2009 at 8:46 PM, James B. Byrne byrn...@harte-lyne.cawrote: I went to the source forge website, but the rh rpm is inaccessible. I really do not wish to join yet another mailing list simply to report this so if anyone here is a member there as well please let them know.

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread nate
James B. Byrne wrote: I went to the source forge website, but the rh rpm is inaccessible. I really do not wish to join yet another mailing list simply to report this so if anyone here is a member there as well please let them know. looks like they already know..

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Scott Silva
on 5-14-2009 11:46 AM James B. Byrne spake the following: On: Thu, 14 May 2009 08:48:36 -0700, Bill Campbell cen...@celestial.com wrote: You might look at fail2ban which can automatically create iptables blocks when things like this happen. I went to the source forge website, but the rh

Re: [CentOS] Dealing with brute force attacks

2009-05-14 Thread Robert Heller
At Thu, 14 May 2009 13:00:09 -0700 CentOS mailing list centos@centos.org wrote: on 5-14-2009 11:46 AM James B. Byrne spake the following: On: Thu, 14 May 2009 08:48:36 -0700, Bill Campbell cen...@celestial.com wrote: You might look at fail2ban which can automatically create