create account

RE: Secure Your Linux Server with Fail2Ban by bilbo

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @krnel/secure-your-linux-server-with-fail2ban

· @bilbo ·
I see a lot of agressive e.g. 2-3 failed attempt configurations that forgot to whitelist their own IP, so good job there and I just wanted to reiterate that point because it is very easy to hit 3 failed attempts.

What I did not see is what I consider the best part of fail 2 ban: with minimal knowledge of regex you can create custom filters, which means you can monitor any file for specific lines and leave it up to a simple fail2ban setting (in /etc/fail2ban/filter.d which is uneditable by the apache/nginx user) for deciding whether the offending IP has done enough to warrant a ban.

Protect drupal or wordpress installations without use of yet another plugin requiring several updates per year? Yes please.

Even more powerful, any time a web developer is sanitizing input they can simply log it when the code detects a condition they would never expect.  For instance, a log line might look like "SUSPICIOUS BEHAVIOR by [IP]: submitting data to a dropdown box that is not one of the dropdown items"  And the rest -- monitoring a user for how frequently they conduct a suspicious act and banning when appropriate -- is all handled by fail2ban.  Instead what I frequently see is a developer writing the entire logging, checking, banning, and cleanup sequence into every page load.  Just look at popular security plugins for wordpress/drupal.  If you have control of the server, fail2ban and a custom filter makes for a far better option with a fraction of the effort.
👍  ,
properties (23)
authorbilbo
permlinkre-krnel-secure-your-linux-server-with-fail2ban-20161204t170919702z
categorycybersecurity
json_metadata{"tags":["cybersecurity"]}
created2016-12-04 17:09:18
last_update2016-12-04 17:09:18
depth1
children1
last_payout2017-01-04 15:36:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,474
author_reputation24,103,890,446
root_title"Secure Your Linux Server with Fail2Ban"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,915,324
net_rshares81,499,213,821
author_curate_reward""
vote details (2)
@krnel ·
Thanks for the feedback and extra suggestions. Much appreciated :)
properties (22)
authorkrnel
permlinkre-bilbo-re-krnel-secure-your-linux-server-with-fail2ban-20161204t172303001z
categorycybersecurity
json_metadata{"tags":["cybersecurity"]}
created2016-12-04 17:23:03
last_update2016-12-04 17:23:03
depth2
children0
last_payout2017-01-04 15:36:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length66
author_reputation1,343,547,270,297,082
root_title"Secure Your Linux Server with Fail2Ban"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,915,425
net_rshares0