Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
5 registered (Ruben, Bert, Mike L, Yarpâ„¢, driv), 19 Guests and 15 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/05/06
Posts: 14904
Top Posters (30 Days)
Ruben 67
SD 57
Gizmo 48
gliderdad 33
Dunny 21
driv 18
Iann128 16
dbremer 16
Stan 15
Mark S 13
Latest Photos
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Gizzo Marx
Page 1 of 4 1 2 3 4 >
Topic Options
#234647 - 02/10/10 10:56 PM Server getting attacked
Stan Offline

addict
Registered: 06/05/06
Posts: 687
my 1and1.com vps, according to the tech person at 1and1.com is coming under, i think he called it brute force attack from various places like china etc, and is shutting down my forum..

He suggested installing
man hosts.deny

Does anyone know how to do that? or what it does?

Thanks
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#234648 - 02/10/10 11:19 PM Re: Server getting attacked [Re: Stan]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
IP tables basically..

you might be better served to install a firewall that wraps the IPTables and has a very easy interface..

CSF firewall.. also handles the brute force crap that is inevitable on ANY server on the NET...

lots of things can be done.. ie: change your SSH port from 22 to a non standard... don't allow root SSH at all.. make them 'su' after login... and much more wink

i have the firewall automatically ban 'bad guys' and email me about it... makes for major peace of mind..

here's a typical example...

Code:
Time:    Wed Feb 10 20:25:46 2010 -0800
IP:      140.123.1.12 (TW/Taiwan Province of China/dns6.ccu.edu.tw)
Hits:    11
Blocked: Temporary Block

Sample of block hits:
Feb 10 20:24:16 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=194 TOS=0x00 PREC=0x00 TTL=56 ID=57140 PROTO=UDP SPT=53 DPT=40421 LEN=174 Feb 10 20:24:16 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=194 TOS=0x00 PREC=0x00 TTL=56 ID=57141 PROTO=UDP SPT=53 DPT=40421 LEN=174 Feb 10 20:24:18 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=153 TOS=0x00 PREC=0x00 TTL=56 ID=57202 PROTO=UDP SPT=53 DPT=40421 LEN=133 Feb 10 20:24:21 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=238 TOS=0x00 PREC=0x00 TTL=56 ID=57310 PROTO=UDP SPT=53 DPT=40421 LEN=218 Feb 10 20:24:21 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=420 TOS=0x00 PREC=0x00 TTL=56 ID=57311 PROTO=UDP SPT=53 DPT=40421 LEN=400 Feb 10 20:24:22 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=153 TOS=0x00 PREC=0x00 TTL=56 ID=57341 PROTO=UDP SPT=53 DPT=40421 LEN=133 Feb 10 20:24:23 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=238 TOS=0x00 PREC=0x00 TTL=56 ID=57362 PROTO=UDP SPT=53 DPT=40421 LEN=218 Feb 10 20:24:23 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=420 TOS=0x00 PREC=0x00 TTL=56 ID=57371 PROTO=UDP SPT=53 DPT=40421 LEN=400 Feb 10 20:24:25 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=238 TOS=0x00 PREC=0x00 TTL=56 ID=57405 PROTO=UDP SPT=53 DPT=40421 LEN=218 Feb 10 20:24:33 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=227 TOS=0x00 PREC=0x00 TTL=56 ID=57580 PROTO=UDP SPT=53 DPT=40421 LEN=207 Feb 10 20:24:49 server kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:76:c2:8f:9e:00:17:df:8d:64:0a:08:00 SRC=140.123.1.12 DST=74.50.5.2 LEN=227 TOS=0x00 PREC=0x00 TTL=56 ID=57976 PROTO=UDP SPT=53 DPT=40421 LEN=207 


I usually have taiwan, china and ukraine dudes running automated scanners and most servers have the same.. just have a good security setup... STRONG passwords and you'll be fine wink
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234658 - 02/11/10 09:40 AM Re: Server getting attacked [Re: SD]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
if his site is hosted on 1and1, shouldn't they be handling that?
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234666 - 02/11/10 12:20 PM Re: Server getting attacked [Re: Bad Frog]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
You would think.
Top
#234669 - 02/11/10 12:26 PM Re: Server getting attacked [Re: JAISP]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
it all depends... if it's a shared hosting solution, i'd assume so.. dunno what 1and1 is offering for him..

sometimes dedicated server packages just leave security up to the client or they charge for a 'managed hosting' kinda dealio to do that..
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234670 - 02/11/10 12:35 PM Re: Server getting attacked [Re: SD]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
it is a VPS, full root access, I understand the onus us on me to do what is needed. They look after problems with shared servers.
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#234671 - 02/11/10 12:45 PM Re: Server getting attacked [Re: Stan]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
I know when I see things like what you are talking about, I start blocking IP ranges in .htaccess

when I start seeing questionable errors, etc, I check the IP address against various databases to see if they are a known spammer or the like.

I also use a very old script called guardian from xav.com that allows me to add filters, so if someone is probing my site for known hacks and they match my filters, they get hit with a DOS and are automatically locked out of the site. anything that doesn't match an existing condition I get notified about so I can check it out.
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234675 - 02/11/10 01:02 PM Re: Server getting attacked [Re: Bad Frog]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
>>I start blocking IP ranges in .htaccess

Can that be done in the server root? I know it can be done in the domain root.

SIRDUDE... the stuff is way over my head, remember in tecky world I am only 11 inches tall. smile
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#234681 - 02/11/10 01:07 PM Re: Server getting attacked [Re: Stan]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
I'm on a virtual server, my htaccess in my root directory, vannin.com/.htaccess - same folder as your maine index page, robots.txt, etc.

I have it blocked so you can't browse it.
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234682 - 02/11/10 01:09 PM Re: Server getting attacked [Re: Stan]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
yah..

the quick/dirty way is just to add 'bad IPs' to your .htaccess in the domain root (public_html or httpdocs)

then you don't have those ips hitting your ubbthreads and causing undue load on queries that they shouldn't be allowed to do..

as for the other geek stuff i posted.. it's prolly best to have a geek do it (maybe your hosting provider should do it for FREE! )

dunno smile
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234687 - 02/11/10 01:45 PM Re: Server getting attacked [Re: SD]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
it is all the sites on the VPS that slow to a stop, I do not think there are extra hits on my threads.
ie is they are hitting the server root in

root/var/www/vhosts/clubadventist/httpdocs/"domainroot"
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#234689 - 02/11/10 01:45 PM Re: Server getting attacked [Re: Stan]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
1and1,com, is a great price, and you get what you pay for.
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#234690 - 02/11/10 01:52 PM Re: Server getting attacked [Re: Stan]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
yeppers wink
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234693 - 02/11/10 01:56 PM Re: Server getting attacked [Re: SD]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
well if it is all the sites on their server, it is their problem, not much you can do about it except yell at them, and they are such a huge company, I don't think that will work to well.
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234726 - 02/11/10 02:53 PM Re: Server getting attacked [Re: Bad Frog]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14904
Loc: Portland, OR; USA
FWIW, 1&1 is a joke as a host; i have like 8 of their free "unlimited" accounts from a promo years ago, it's still not worth using lol
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#234737 - 02/11/10 03:59 PM Re: Server getting attacked [Re: Gizmo]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
.htaccess does not cover your server root. For that you need to do a hosts deny file setup and that does not cover web browsers. the host.deny file only covers stuff like FTP, SSH, Telnet, and other resource servers on your server.

The cover it all you need to do both the host.deny and .htaccess
Top
#234738 - 02/11/10 04:09 PM Re: Server getting attacked [Re: JAISP]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
but the host.deny needs to be done by 1and1 correct? he can't access that. ?
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234748 - 02/11/10 04:55 PM Re: Server getting attacked [Re: Bad Frog]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14904
Loc: Portland, OR; USA
Well, it's a VPS, so he should have full root access
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#234761 - 02/11/10 07:31 PM Re: Server getting attacked [Re: Gizmo]
chep Offline
newbie
Registered: 12/31/06
Posts: 36
Hi,

Have had many sort of attacks from China, Brazil, and eastern Europe.

I use IPTables to block some countries completely. I get a master list from: http://www.wizcrafts.net/chinese-iptables-blocklist.html for example...

Once I get their list I put it into a script file and run it on the server. Something like this:

Code:
#!/bin/bash
# china blocklist
# generated from http://blacklists.linuxadmin.org

/sbin/iptables -A INPUT -p tcp -s 58.14.0.0/15 --dport 22 -j REJECT
/sbin/iptables -A INPUT -p tcp -s 58.16.0.0/13 --dport 22 -j REJECT
/sbin/iptables -A INPUT -p tcp -s 58.24.0.0/15 --dport 22 -j REJECT


A few other things is I move my default SSH port. This helps tremendously. On my server it is controlled in the file /etc/ssh/sshd_config

I changed or added this line. Except I used my secret numbers. These are not the actual numbers I used.
Code:
Port 1234


You may also want to consider moving your FTP ports as well. You can also do port scans against your server to see what is obviously visible to a hacker. There are tools for that at Sourceforge.net
Top
#234767 - 02/11/10 08:46 PM Re: Server getting attacked [Re: chep]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
http://www.configserver.com/free/csf/install.txt takes all of 10mins and this wraps the IPtables in a nice neat bow with a front end for WHM, if you have that..

http://www.lunarforums.com/dedicated_hos...l-t30205.0.html <-- good idea and also /var/shm too..

lotta stuff you can do to secure yourself...

the BIG thing and many don't do it is to set a VERY STRONG root password!! not like sirdude1234, which is gonna get cracked.. try something more like x?FHU%hJeIB}lFB9;b which is impossible to brute force wink

also.. don't allow root to SSH in.. force them to login with non privileged on a non standard port (like chep says above) then su to root...

smile
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234777 - 02/11/10 10:45 PM Re: Server getting attacked [Re: SD]
chep Offline
newbie
Registered: 12/31/06
Posts: 36
That looks like more than what I usually need. A couple of other things I do is - write a script to generate some logs and grovel them and email myself a relevant report.

I like to look at lastb command output as well as the bash_history and secure log. In case someone breaks in I might capture what they were doing. Looking at the secure logs will show you who is trying to break in sometimes. Of course I would also agree with the advice of a very strong password.

/usr/bin/lastb
tail -n 400 /var/log/secure
tail -n 200 ~/.bash_history
_________________________
All I have is a piece of hard rock candy. But it's not for eatin'. It's just for lookin' through
Top
#234782 - 02/12/10 07:29 AM Re: Server getting attacked [Re: chep]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
Yeah, don't forget to lock the barn after the horse gets out.

Looking at the logs to see what they do after they break in after watching them try forever is a great idea. If they can break in they can cover their tracks and only let you see what they want to let you see and may have done other things to aide them and you would never know it.

If you notice someone persistent in getting in it is best to block them and not wait till after they got in as if they were persistent then they are not just out to check out your server they are looking to do things to it you wouldn't like.

Good luck with that. I will be looking forward to getting spam from your server on behalf of those whom broke in some day.
Top
#234788 - 02/12/10 10:09 AM Re: Server getting attacked [Re: JAISP]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 593
Loc: Coast of Maine
my theory, if it looks even remotely like an attack, or someone probing for weak spots, ban the IP. if it is a legit user, they can contact me and we can sort it out.

I still get (failed) attempts from content spammers, I ban their IP anyway.
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234800 - 02/12/10 06:59 PM Re: Server getting attacked [Re: Bad Frog]
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
Guys let's stop beating up on 1and1 and give him some help, huh? Telling him 1and1 sucks doesn't fix his problem or answer what he cae here to find out.

Stan, SirDude has offered the best help. You could .htaccess but that means maintaining it, and it means apache has to serve the request and take up resources. It also doesn't protect brute force attacks on your FTP server, Mail server, and a number of other services. What I see here isn't a fix-all, but it should help.

IPtables, if done right, can prevent any access at all, thus mitigating brute force attacks.
_________________________
This thread for sale. Click here!
Top
#234839 - 02/13/10 05:58 PM Re: Server getting attacked [Re: David Dreezer]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
Thanks for the help, everyone,
here is my next problem

I DON'T HAVE A CLUE HOW TO DO THIS smile

code.
Quote:
Installation
============
Installation is quite straightforward:

rm -fv csf.tgz
wget http://www.configserver.com/free/csf.tgz
tar -xzf csf.tgz
cd csf
sh install.sh

Next, test whether you have the required iptables modules:

perl /etc/csf/csftest.pl

Don't worry if you cannot run all the features, so long as the script doesn't
report any FATAL errors

You should not run any other iptables firewall configuration script. For
example, if you previously used APF+BFD you can remove the combination (which
you will need to do if you have them installed otherwise they will conflict
horribly):

sh /etc/csf/remove_apf_bfd.sh
etc etc etc


I am only a humble macintosh guy, never learned command
Top
#234845 - 02/13/10 07:19 PM Re: Server getting attacked [Re: Stan]
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
log in via a terminal, putty will work, and type exactly what he has there, line by line.
_________________________
This thread for sale. Click here!
Top
#234848 - 02/13/10 07:34 PM Re: Server getting attacked [Re: David Dreezer]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
one thing i'd recommend doing BEFORE the 1st thing in that tutorial is to go to your setups directory..

ie: /root/setups or a lotta times /var/usr/src or /var/usr/local/src

THEN do what it says.. that way you keep all the downloaded stuff in one place instead of into whatever directory you login to..

to change directory, use the 'cd' command... so to go to /var/usr/src dir.. 'cd /var/usr/src' would do it..
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234897 - 02/15/10 11:08 PM Re: Server getting attacked [Re: SD]
chep Offline
newbie
Registered: 12/31/06
Posts: 36
Quote:
I will be looking forward to getting spam from your server on behalf of those whom broke in some day.


I'm pretty sure you will not be getting any spam from my server. At any rate why don't you take a hike and stick to the subject. I offered some helpful information. It's not something to ridicule people over. YOu have no idea about how I cover my server's security other than a few tidbits of information I have dropped here - which isn't much of anything worth attacking someone over. It's personal jabs like yours which makes contributing on the internet a little less than a mere friendly matter. I'm sure that age has a lot to do with it.

Stan good luck :-)
_________________________
All I have is a piece of hard rock candy. But it's not for eatin'. It's just for lookin' through
Top
#235328 - 03/05/10 10:51 AM Re: Server getting attacked [Re: chep]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
ok, trying to get this fixed... had trouble with my terminal program on my mac so i picked up a windows 7....

what am I doing wrong? the CD command is not taking

Thanks everyone for the help.


Attachments
photo1.gif (13 downloads)

_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#235329 - 03/05/10 11:04 AM Re: Server getting attacked [Re: Stan]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10164
Loc: Aberdeen, WA
It would appear that your initial command to unpack the csf.tgz file was incorrect.

You should run the command:

Code:
tar -xzf csf.tgz
Top
#235330 - 03/05/10 11:25 AM Re: Server getting attacked [Re: Rick]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
I should have caught that typo.. thanks for pointing it out, everything seemed to work fine

It said to do a bunch of stuff, and then it said it was installed, so was it telling itself to make those adjustments or is that something I have to figure out?

Thanks again for your help!


Attachments
Screen shot 2010-03-05 at 8.19.18 AM.gif (15 downloads)

_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#235331 - 03/05/10 11:28 AM Re: Server getting attacked [Re: Stan]
Stan Offline

addict
Registered: 06/05/06
Posts: 687
also, how does one take a partial screen shot with windows 7????
_________________________
As of Aug - 2010 I am using version 7.5.6 and hosted by http://www.mindraven.com/

UBBsite
http://clubadventist.com
Top
#235332 - 03/05/10 12:17 PM Re: Server getting attacked [Re: Stan]
SD Offline
Registered: 04/19/07
Posts: 4031
Loc: SoCal, USA
get firefox then an add-on to assist you..

Linky Poo to add-ons

one of the 1st two works fine..

i personally use SnagIt, which is a separate program, but they all do what you want smile
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
Page 1 of 4 1 2 3 4 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Edit Post
by Bert
Today at 01:19 PM
A positive note
by SteveS
Yesterday at 09:36 PM
How to locate links to particular site if they are only used in images?
by Conrad
02/10/12 09:41 PM
Pictures not displaying
by Marker23
02/09/12 10:04 PM
Issue with logging out constantly
by Flanuva
02/09/12 07:05 PM
Forum Stats
10213 Members
36 Forums
33667 Topics
180917 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image