Viewing a response to: @krnel/secure-your-linux-server-with-fail2ban
I see a lot of agressive e.g. 2-3 failed attempt configurations that forgot to whitelist their own IP, so good job there and I just wanted to reiterate that point because it is very easy to hit 3 failed attempts. What I did not see is what I consider the best part of fail 2 ban: with minimal knowledge of regex you can create custom filters, which means you can monitor any file for specific lines and leave it up to a simple fail2ban setting (in /etc/fail2ban/filter.d which is uneditable by the apache/nginx user) for deciding whether the offending IP has done enough to warrant a ban. Protect drupal or wordpress installations without use of yet another plugin requiring several updates per year? Yes please. Even more powerful, any time a web developer is sanitizing input they can simply log it when the code detects a condition they would never expect. For instance, a log line might look like "SUSPICIOUS BEHAVIOR by [IP]: submitting data to a dropdown box that is not one of the dropdown items" And the rest -- monitoring a user for how frequently they conduct a suspicious act and banning when appropriate -- is all handled by fail2ban. Instead what I frequently see is a developer writing the entire logging, checking, banning, and cleanup sequence into every page load. Just look at popular security plugins for wordpress/drupal. If you have control of the server, fail2ban and a custom filter makes for a far better option with a fraction of the effort.
author | bilbo |
---|---|
permlink | re-krnel-secure-your-linux-server-with-fail2ban-20161204t170919702z |
category | cybersecurity |
json_metadata | {"tags":["cybersecurity"]} |
created | 2016-12-04 17:09:18 |
last_update | 2016-12-04 17:09:18 |
depth | 1 |
children | 1 |
last_payout | 2017-01-04 15:36:09 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,474 |
author_reputation | 24,103,890,446 |
root_title | "Secure Your Linux Server with Fail2Ban" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 1,915,324 |
net_rshares | 81,499,213,821 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
krnel | 0 | 81,499,213,821 | 25% | ||
hoek | 0 | 0 | 100% |
Thanks for the feedback and extra suggestions. Much appreciated :)
author | krnel |
---|---|
permlink | re-bilbo-re-krnel-secure-your-linux-server-with-fail2ban-20161204t172303001z |
category | cybersecurity |
json_metadata | {"tags":["cybersecurity"]} |
created | 2016-12-04 17:23:03 |
last_update | 2016-12-04 17:23:03 |
depth | 2 |
children | 0 |
last_payout | 2017-01-04 15:36:09 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 66 |
author_reputation | 1,343,547,270,297,082 |
root_title | "Secure Your Linux Server with Fail2Ban" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 1,915,425 |
net_rshares | 0 |