Re: : OT? -- Banning IP's making high volume of bad requests
David Thornton <[email protected]> Fri, 19 Sep 2014 09:57:10 -0400
| Newsgroups | gmane.org.user-groups.linux.tolug |
|---|---|
| Message-ID | <CAHcykVrkmozcZiJaPjxbJ+oVfZdFbXJ8pB6F7J97n+HfGp5xRQ@mail.gmail.com> |
--001a11c2a02234aa7505036b7ac5 Content-Type: text/plain; charset=UTF-8 I think you guys are missing the point. He want to tell fail2ban : if ip x asks for url y ban it on the firewall. I googled "fail2ban http request to firewall" and got a direct hit , you sunk my battleship. http://serverfault.com/questions/416926/automatically-block-ip-who-requests-certain-url David On Fri, Sep 19, 2014 at 9:20 AM, Myles Braithwaite <me-qIX3qoPyADtH8hdXm2+x1laTQe2KTcn/@public.gmane.org> wrote: > The easiest option is to add the IP address to your`/etc/hosts.deny` file. > This will block them from accessing your server indefinitely (so check and > make sure they aren't coming from a public access point that your users are > likely to use). > > > On Sep 19, 2014, at 7:44 AM, Matt Price <[email protected]> wrote: > > > > Hi folks, > > > > Earlier this week the ubuntu server my courses run on was compromised > > and started spammming. I have done some hardening and among > > otherthings installed fail2ban and logwatch, then put the server back > > up yesterday afternoon. > > > > This morning I woke up to see hundreds of thousands of requests from > > 2 IPs to a web page that has a known exploit. Here is a log entry: > > > > 195.154.136.19 - - [19/Sep/2014:07:33:10 -0400] "POST /xmlrpc.php > > HTTP/1.0" 403 470 "-" "Mozilla/4.0 (compatible: MSIE 7.0; Windows NT > > 6.0)" > > > > I would like to tell fail2ban to block these IP's when this happens -- > > they aren't doing any damage yet but they account for most of my > > bandwith right now and I would rather they not keep me o ntheir 'easy > > targets' list. Does anyone know how to do this -- if not with > > fail2ban than with some other tool? > > > > Thanks, > > > > Matt > > -- > > The Toronto Linux Users Group. Meetings: http://gtalug.org/ > > TLUG requests: Linux topics, No HTML, wrap text below 80 columns > > How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists > -- > The Toronto Linux Users Group. Meetings: http://gtalug.org/ > TLUG requests: Linux topics, No HTML, wrap text below 80 columns > How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists > --001a11c2a02234aa7505036b7ac5 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I think you guys are missing the point. He want to tell fa= il2ban : if ip x asks for url y ban it on the firewall.<div><br></div><div>= I googled "fail2ban http request to firewall" and got a direct hi= t , you sunk my battleship.</div><div><br></div><div><a href=3D"http://serv= erfault.com/questions/416926/automatically-block-ip-who-requests-certain-ur= l">http://serverfault.com/questions/416926/automatically-block-ip-who-reque= sts-certain-url</a><br></div><div><br></div><div>David</div></div><div clas= s=3D"gmail_extra"><br><div class=3D"gmail_quote">On Fri, Sep 19, 2014 at 9:= 20 AM, Myles Braithwaite <span dir=3D"ltr"><<a href=3D"mailto:me@mylesbr= aithwaite.com" target=3D"_blank">me-qIX3qoPyADtH8hdXm2+x1laTQe2KTcn/@public.gmane.org</a>></span> wro= te:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-= left:1px #ccc solid;padding-left:1ex">The easiest option is to add the IP a= ddress to your`/etc/hosts.deny` file. This will block them from accessing y= our server indefinitely (so check and make sure they aren't coming from= a public access point that your users are likely to use).<br> <div class=3D"HOEnZb"><div class=3D"h5"><br> > On Sep 19, 2014, at 7:44 AM, Matt Price <<a href=3D"mailto:moptop99= @gmail.com">[email protected]</a>> wrote:<br> ><br> > Hi folks,<br> ><br> > Earlier this week the ubuntu server my courses run on was compromised<= br> > and started spammming.=C2=A0 I have done some hardening and among<br> > otherthings installed fail2ban and logwatch, then put the server back<= br> > up yesterday afternoon.<br> ><br> > This morning I woke up to see=C2=A0 hundreds of thousands of requests = from<br> > 2 IPs to a web page that has a known exploit.=C2=A0 Here is a log entr= y:<br> ><br> > <a href=3D"tel:195.154.136.19" value=3D"+19515413619">195.154.136.19</= a> - - [19/Sep/2014:07:33:10 -0400] "POST /xmlrpc.php<br> > HTTP/1.0" 403 470 "-" "Mozilla/4.0 (compatible: MS= IE 7.0; Windows NT<br> > 6.0)"<br> ><br> > I would like to tell fail2ban to block these IP's when this happen= s --<br> > they aren't doing any damage yet but they account for most of my<b= r> > bandwith right now and I would rather they not keep me o ntheir 'e= asy<br> > targets' list.=C2=A0 Does anyone know how to do this -- if not wit= h<br> > fail2ban than with some other tool?<br> ><br> > Thanks,<br> ><br> > Matt<br> > --<br> > The Toronto Linux Users Group.=C2=A0 =C2=A0 =C2=A0 Meetings: <a href= =3D"http://gtalug.org/" target=3D"_blank">http://gtalug.org/</a><br> > TLUG requests: Linux topics, No HTML, wrap text below 80 columns<br> > How to UNSUBSCRIBE: <a href=3D"http://gtalug.org/wiki/Mailing_lists" t= arget=3D"_blank">http://gtalug.org/wiki/Mailing_lists</a><br> --<br> The Toronto Linux Users Group.=C2=A0 =C2=A0 =C2=A0 Meetings: <a href=3D"htt= p://gtalug.org/" target=3D"_blank">http://gtalug.org/</a><br> TLUG requests: Linux topics, No HTML, wrap text below 80 columns<br> How to UNSUBSCRIBE: <a href=3D"http://gtalug.org/wiki/Mailing_lists" target= =3D"_blank">http://gtalug.org/wiki/Mailing_lists</a><br> </div></div></blockquote></div><br></div> --001a11c2a02234aa7505036b7ac5-- -- The Toronto Linux Users Group. Meetings: http://gtalug.org/ TLUG requests: Linux topics, No HTML, wrap text below 80 columns How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists