Re: fail2ban

Dale Stirling <[email protected]>
Newsgroups gmane.comp.security.web-applications
Message-ID <[email protected]>
Kai,

Here are a few ideas:

Apache Allow,Deny something like.

Order Deny Allow
Deny <the ip making requests>
Allow all

IP tables:

iptables -A INPUT --source <ip making requests> -j REJECT

That will block the IP from making any connections to your server.

Also fail2ban has several ready made apache rules in it it would not
be hard to copy and adapt one of these the pre made rules are in
/etc/fail2ban/fal2ban.d and /etc/fail2ban/jail.conf

Dale

On Fri, Oct 22, 2010 at 2:40 AM, Kai Witzke <[email protected]> wrote:
> Hey everybody!
>
> I have some serious problems with flooding attacks to my apache2. No
> problems with logins oder syn floods, just a huge amount of simple
> requests to my server from the same ip. Anyone got a nice howto on that
> or maybe a nice regex prepared for counting such requests and blocking
> the greedy ones?
>
> thanks in advance
> Kai
>
>
>
>
> This list is sponsored by Cenzic
> --------------------------------------
> Let Us Hack You. Before Hackers Do!
> It's Finally Here - The Cenzic Website HealthCheck. FREE.
> Request Yours Now!
> http://www.cenzic.com/2009HClaunch_Securityfocus
> --------------------------------------
>
>



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.