Does anyone know of an alternative to ipset for blocking IP
ranges of entire countries, that works with OpenVZ containers?
Does anyone know of an alternative to ipset for blocking IP
ranges of entire countries, that works with OpenVZ containers?
If you want to do exactly that, simply use CIDR notation with -s parameter.
However, if you need (just a guess) to protect SSH against
bruteforcing the passwords, that's normally performed a bit
differently.
Does anyone know of an alternative to ipset for blocking IP ranges of entire >countries, that works with OpenVZ containers?
If you want to do exactly that, simply use CIDR notation with -s
parameter.
Using IPTABLES ... or did you mean with ipset? I can't use ipset in
this specific case, and listing thousands of nets using IPTABLES is usually a bad idea.
If you want to do exactly that, simply use CIDR notation with -s
parameter.
Using IPTABLES ... or did you mean with ipset? I can't use ipset inWill this work?
this specific case, and listing thousands of nets using IPTABLES is
usually a bad idea.
https://github.com/tlhackque/BlockCountries
Does anyone know of an alternative to ipset for blocking IP rangesI wish... I use fail2ban.
of entire countries, that works with OpenVZ containers?
OpenVZ containers have limited memory
and you can soon fill it up with an all the subnets. With fail2ban
you can block the offenders easily. I have a "permaban" chain for
those repeat offenders.
I wish...
I use fail2ban. OpenVZ containers have limited memory and you can soon
fill it up with an all the subnets. With fail2ban you can block the offenders easily. I have a "permaban" chain for those repeat
offenders.
https://github.com/tlhackque/BlockCountries
Does anyone know of an alternative to ipset for blocking IP ranges
of entire countries, that works with OpenVZ containers?
I wish...
I use fail2ban. OpenVZ containers have limited memory and you can
soon fill it up with an all the subnets. With fail2ban you can block
the offenders easily. I have a "permaban" chain for those repeat
offenders.
If you want to do exactly that, simply use CIDR notation with -s
parameter.
Using IPTABLES ... or did you mean with ipset? I can't use ipset in
this specific case, and listing thousands of nets using IPTABLES is
usually a bad idea.
Will this work?
https://github.com/tlhackque/BlockCountries
This never works, as there would always be at least one trojaned
computer in your own country...
Limiting the number of connections per minute does that (SSH
protection) best. Especially being combined with key-only
authentification (if you choose proper algorithms, of course).
Very dangerous thing... However, it makes some fun to use it
against the admin^Widiot who installed it :-)
Being a security expert, I know (and use; and, obviously,
recommend) better method: limit the number of connections per
minute to 2 or 3, thus making any and all bruteforce attacks time-ineffective.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^Very dangerous thing... However, it makes some fun to
use it against the admin^Widiot who installed it :-)
I'm curious ... why is fail2ban dangerous?
Being a security expert, I know (and use; and, obviously,I don't see why these are mutually exclusive ... but maybe I'm
recommend) better method: limit the number of connections per
minute to 2 or 3, thus making any and all bruteforce attacks
time-ineffective.
not an expert enough. If you use key-only authentication for SSH
(for example), it makes perfect sense to add someone to a ban
list for 15-600 minutes if they fail 3 times (for example).
I quite often legitimately connect with 2-3-4 SSH sessions to the
same server within a few minutes, but they don't fail of course :)
Didn't you read the message before answering it?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642
and some others discovered since that.
I don't see why these are mutually exclusive ... but maybe I'm
not an expert enough. If you use key-only authentication for SSH
Don't you?
(for example), it makes perfect sense to add someone to a ban
list for 15-600 minutes if they fail 3 times (for example).
Now imagine someone had tricked your funny stupid fail2ban to ban
_you_...
I quite often legitimately connect with 2-3-4 SSH sessions to the
same server within a few minutes, but they don't fail of course :)
I guess you simply don't know about screen.
Good ${greeting_time}, Joaquim!
18 Dec 2017 21:40:18, you wrote to me:
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^Very dangerous thing... However, it makes some fun to
use it against the admin^Widiot who installed it :-)
I'm curious ... why is fail2ban dangerous?
Didn't you read the message before answering it?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642
and some others discovered since that.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^Very dangerous thing... However, it makes some fun to
use it against the admin^Widiot who installed it :-)
I'm curious ... why is fail2ban dangerous?
Didn't you read the message before answering it?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642
and some others discovered since that.
Is it an accident that you omitted to say that there were only 3 CVE announcements since CVE-2012-5642 and those were over 4 years ago or
are you just scaremongering?
Good ${greeting_time}, Nelgin!
20 Dec 2017 19:30:48, you wrote to me:
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^Very dangerous thing... However, it makes some fun to
use it against the admin^Widiot who installed it :-)
I'm curious ... why is fail2ban dangerous?
Didn't you read the message before answering it?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642
and some others discovered since that.
Is it an accident that you omitted to say that there were only 3 CVE announcements since CVE-2012-5642 and those were over 4 years ago or
are you just scaremongering?
P.S.: OMFG... I was about to answer to PoS without a realname...
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642
and some others discovered since that.
P.S.: OMFG... I was about to answer to PoS without a realname...
PoS yourself, mate.
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495948:06:34 |
| Calls: | 82 |
| Files: | 1,070 |
| Messages: | 287,106 |