Re: : OT? -- Banning IP's making high volume of bad requests

David Thornton <[email protected]> Fri, 19 Sep 2014 09:57:10 -0400
Newsgroups gmane.org.user-groups.linux.tolug
Message-ID <CAHcykVrkmozcZiJaPjxbJ+oVfZdFbXJ8pB6F7J97n+HfGp5xRQ@mail.gmail.com>
--001a11c2a02234aa7505036b7ac5
Content-Type: text/plain; charset=UTF-8

I think you guys are missing the point. He want to tell fail2ban : if ip x
asks for url y ban it on the firewall.

I googled "fail2ban http request to firewall" and got a direct hit , you
sunk my battleship.

http://serverfault.com/questions/416926/automatically-block-ip-who-requests-certain-url

David

On Fri, Sep 19, 2014 at 9:20 AM, Myles Braithwaite <me-qIX3qoPyADtH8hdXm2+x1laTQe2KTcn/@public.gmane.org>
wrote:

> The easiest option is to add the IP address to your`/etc/hosts.deny` file.
> This will block them from accessing your server indefinitely (so check and
> make sure they aren't coming from a public access point that your users are
> likely to use).
>
> > On Sep 19, 2014, at 7:44 AM, Matt Price <[email protected]> wrote:
> >
> > Hi folks,
> >
> > Earlier this week the ubuntu server my courses run on was compromised
> > and started spammming.  I have done some hardening and among
> > otherthings installed fail2ban and logwatch, then put the server back
> > up yesterday afternoon.
> >
> > This morning I woke up to see  hundreds of thousands of requests from
> > 2 IPs to a web page that has a known exploit.  Here is a log entry:
> >
> > 195.154.136.19 - - [19/Sep/2014:07:33:10 -0400] "POST /xmlrpc.php
> > HTTP/1.0" 403 470 "-" "Mozilla/4.0 (compatible: MSIE 7.0; Windows NT
> > 6.0)"
> >
> > I would like to tell fail2ban to block these IP's when this happens --
> > they aren't doing any damage yet but they account for most of my
> > bandwith right now and I would rather they not keep me o ntheir 'easy
> > targets' list.  Does anyone know how to do this -- if not with
> > fail2ban than with some other tool?
> >
> > Thanks,
> >
> > Matt
> > --
> > The Toronto Linux Users Group.      Meetings: http://gtalug.org/
> > TLUG requests: Linux topics, No HTML, wrap text below 80 columns
> > How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists
> --
> The Toronto Linux Users Group.      Meetings: http://gtalug.org/
> TLUG requests: Linux topics, No HTML, wrap text below 80 columns
> How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists
>

--001a11c2a02234aa7505036b7ac5
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I think you guys are missing the point. He want to tell fa=
il2ban : if ip x asks for url y ban it on the firewall.<div><br></div><div>=
I googled &quot;fail2ban http request to firewall&quot; and got a direct hi=
t , you sunk my battleship.</div><div><br></div><div><a href=3D"http://serv=
erfault.com/questions/416926/automatically-block-ip-who-requests-certain-ur=
l">http://serverfault.com/questions/416926/automatically-block-ip-who-reque=
sts-certain-url</a><br></div><div><br></div><div>David</div></div><div clas=
s=3D"gmail_extra"><br><div class=3D"gmail_quote">On Fri, Sep 19, 2014 at 9:=
20 AM, Myles Braithwaite <span dir=3D"ltr">&lt;<a href=3D"mailto:me@mylesbr=
aithwaite.com" target=3D"_blank">me-qIX3qoPyADtH8hdXm2+x1laTQe2KTcn/@public.gmane.org</a>&gt;</span> wro=
te:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex">The easiest option is to add the IP a=
ddress to your`/etc/hosts.deny` file. This will block them from accessing y=
our server indefinitely (so check and make sure they aren&#39;t coming from=
 a public access point that your users are likely to use).<br>
<div class=3D"HOEnZb"><div class=3D"h5"><br>
&gt; On Sep 19, 2014, at 7:44 AM, Matt Price &lt;<a href=3D"mailto:moptop99=
@gmail.com">[email protected]</a>&gt; wrote:<br>
&gt;<br>
&gt; Hi folks,<br>
&gt;<br>
&gt; Earlier this week the ubuntu server my courses run on was compromised<=
br>
&gt; and started spammming.=C2=A0 I have done some hardening and among<br>
&gt; otherthings installed fail2ban and logwatch, then put the server back<=
br>
&gt; up yesterday afternoon.<br>
&gt;<br>
&gt; This morning I woke up to see=C2=A0 hundreds of thousands of requests =
from<br>
&gt; 2 IPs to a web page that has a known exploit.=C2=A0 Here is a log entr=
y:<br>
&gt;<br>
&gt; <a href=3D"tel:195.154.136.19" value=3D"+19515413619">195.154.136.19</=
a> - - [19/Sep/2014:07:33:10 -0400] &quot;POST /xmlrpc.php<br>
&gt; HTTP/1.0&quot; 403 470 &quot;-&quot; &quot;Mozilla/4.0 (compatible: MS=
IE 7.0; Windows NT<br>
&gt; 6.0)&quot;<br>
&gt;<br>
&gt; I would like to tell fail2ban to block these IP&#39;s when this happen=
s --<br>
&gt; they aren&#39;t doing any damage yet but they account for most of my<b=
r>
&gt; bandwith right now and I would rather they not keep me o ntheir &#39;e=
asy<br>
&gt; targets&#39; list.=C2=A0 Does anyone know how to do this -- if not wit=
h<br>
&gt; fail2ban than with some other tool?<br>
&gt;<br>
&gt; Thanks,<br>
&gt;<br>
&gt; Matt<br>
&gt; --<br>
&gt; The Toronto Linux Users Group.=C2=A0 =C2=A0 =C2=A0 Meetings: <a href=
=3D"http://gtalug.org/" target=3D"_blank">http://gtalug.org/</a><br>
&gt; TLUG requests: Linux topics, No HTML, wrap text below 80 columns<br>
&gt; How to UNSUBSCRIBE: <a href=3D"http://gtalug.org/wiki/Mailing_lists" t=
arget=3D"_blank">http://gtalug.org/wiki/Mailing_lists</a><br>
--<br>
The Toronto Linux Users Group.=C2=A0 =C2=A0 =C2=A0 Meetings: <a href=3D"htt=
p://gtalug.org/" target=3D"_blank">http://gtalug.org/</a><br>
TLUG requests: Linux topics, No HTML, wrap text below 80 columns<br>
How to UNSUBSCRIBE: <a href=3D"http://gtalug.org/wiki/Mailing_lists" target=
=3D"_blank">http://gtalug.org/wiki/Mailing_lists</a><br>
</div></div></blockquote></div><br></div>

--001a11c2a02234aa7505036b7ac5--
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists