Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
3 registered (57-Vette, Stan, SteveS), 55 Guests and 17 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 10/19/08
Posts: 52
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 3 of 4 < 1 2 3 4 >
Topic Options
#234777 - 02/11/10 10:45 PM Re: Server getting attacked [Re: SD]
chep Offline
newbie
Registered: 12/31/06
Posts: 36
That looks like more than what I usually need. A couple of other things I do is - write a script to generate some logs and grovel them and email myself a relevant report.

I like to look at lastb command output as well as the bash_history and secure log. In case someone breaks in I might capture what they were doing. Looking at the secure logs will show you who is trying to break in sometimes. Of course I would also agree with the advice of a very strong password.

/usr/bin/lastb
tail -n 400 /var/log/secure
tail -n 200 ~/.bash_history
_________________________
All I have is a piece of hard rock candy. But it's not for eatin'. It's just for lookin' through
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#234782 - 02/12/10 07:29 AM Re: Server getting attacked [Re: chep]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
Yeah, don't forget to lock the barn after the horse gets out.

Looking at the logs to see what they do after they break in after watching them try forever is a great idea. If they can break in they can cover their tracks and only let you see what they want to let you see and may have done other things to aide them and you would never know it.

If you notice someone persistent in getting in it is best to block them and not wait till after they got in as if they were persistent then they are not just out to check out your server they are looking to do things to it you wouldn't like.

Good luck with that. I will be looking forward to getting spam from your server on behalf of those whom broke in some day.
Top
#234788 - 02/12/10 10:09 AM Re: Server getting attacked [Re: JAISP]
Bad Frog Offline
addict
Registered: 05/13/08
Posts: 596
Loc: Coast of Maine
my theory, if it looks even remotely like an attack, or someone probing for weak spots, ban the IP. if it is a legit user, they can contact me and we can sort it out.

I still get (failed) attempts from content spammers, I ban their IP anyway.
_________________________
"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"
Top
#234800 - 02/12/10 06:59 PM Re: Server getting attacked [Re: Bad Frog]
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
Guys let's stop beating up on 1and1 and give him some help, huh? Telling him 1and1 sucks doesn't fix his problem or answer what he cae here to find out.

Stan, SirDude has offered the best help. You could .htaccess but that means maintaining it, and it means apache has to serve the request and take up resources. It also doesn't protect brute force attacks on your FTP server, Mail server, and a number of other services. What I see here isn't a fix-all, but it should help.

IPtables, if done right, can prevent any access at all, thus mitigating brute force attacks.
_________________________
This thread for sale. Click here!
Top
#234839 - 02/13/10 05:58 PM Re: Server getting attacked [Re: David Dreezer]
Stan Online   partay

old hand
Registered: 06/05/06
Posts: 709
Thanks for the help, everyone,
here is my next problem

I DON'T HAVE A CLUE HOW TO DO THIS smile

code.
Quote:
Installation
============
Installation is quite straightforward:

rm -fv csf.tgz
wget http://www.configserver.com/free/csf.tgz
tar -xzf csf.tgz
cd csf
sh install.sh

Next, test whether you have the required iptables modules:

perl /etc/csf/csftest.pl

Don't worry if you cannot run all the features, so long as the script doesn't
report any FATAL errors

You should not run any other iptables firewall configuration script. For
example, if you previously used APF+BFD you can remove the combination (which
you will need to do if you have them installed otherwise they will conflict
horribly):

sh /etc/csf/remove_apf_bfd.sh
etc etc etc


I am only a humble macintosh guy, never learned command
Top
#234845 - 02/13/10 07:19 PM Re: Server getting attacked [Re: Stan]
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
log in via a terminal, putty will work, and type exactly what he has there, line by line.
_________________________
This thread for sale. Click here!
Top
#234848 - 02/13/10 07:34 PM Re: Server getting attacked [Re: David Dreezer]
SD Offline
Registered: 04/19/07
Posts: 4056
Loc: SoCal, USA
one thing i'd recommend doing BEFORE the 1st thing in that tutorial is to go to your setups directory..

ie: /root/setups or a lotta times /var/usr/src or /var/usr/local/src

THEN do what it says.. that way you keep all the downloaded stuff in one place instead of into whatever directory you login to..

to change directory, use the 'cd' command... so to go to /var/usr/src dir.. 'cd /var/usr/src' would do it..
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#234897 - 02/15/10 11:08 PM Re: Server getting attacked [Re: SD]
chep Offline
newbie
Registered: 12/31/06
Posts: 36
Quote:
I will be looking forward to getting spam from your server on behalf of those whom broke in some day.


I'm pretty sure you will not be getting any spam from my server. At any rate why don't you take a hike and stick to the subject. I offered some helpful information. It's not something to ridicule people over. YOu have no idea about how I cover my server's security other than a few tidbits of information I have dropped here - which isn't much of anything worth attacking someone over. It's personal jabs like yours which makes contributing on the internet a little less than a mere friendly matter. I'm sure that age has a lot to do with it.

Stan good luck :-)
_________________________
All I have is a piece of hard rock candy. But it's not for eatin'. It's just for lookin' through
Top
#235328 - 03/05/10 10:51 AM Re: Server getting attacked [Re: chep]
Stan Online   partay

old hand
Registered: 06/05/06
Posts: 709
ok, trying to get this fixed... had trouble with my terminal program on my mac so i picked up a windows 7....

what am I doing wrong? the CD command is not taking

Thanks everyone for the help.


Attachments
photo1.gif (14 downloads)

Top
#235329 - 03/05/10 11:04 AM Re: Server getting attacked [Re: Stan]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10164
Loc: Aberdeen, WA
It would appear that your initial command to unpack the csf.tgz file was incorrect.

You should run the command:

Code:
tar -xzf csf.tgz
Top
Page 3 of 4 < 1 2 3 4 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image