Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Wed Feb 03, 2010 2:21 am 
Offline
Senior Newbie

Joined: Thu Dec 10, 2009 4:34 pm
Posts: 7
I've noticed my denyhosts setup is blocking some other linode users. Since this can only happen after x number of invalid SSH login attempts, what is the best approach according to the community for dealing with this?

1. ignore it and let denyhosts do its job
2. warn the other linode users their site(s) might be compromised
3. file a report with linode

I'm inclined to pick 1, because I don't have time to mess with it, but if there is a strong community sense of self-policing these kinds of thing, I'd be happy to contribute.

cheers!


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 2:24 am 
Offline
Senior Member
User avatar

Joined: Sun Dec 27, 2009 11:12 pm
Posts: 1038
Location: Colorado, USA
Send the log snippet to abuse@linode.com

Either those systems are compromised - or the owners are morons to sh*t in their own backyard.

Either way they need to be cleaned up.


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 7:45 am 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
vonskippy wrote:
Send the log snippet to abuse@linode.com

Either those systems are compromised - or the owners are morons to sh*t in their own backyard.

Either way they need to be cleaned up.

+1 - they are sh*tting in our back yard.

_________________
/ Peter


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 11:04 am 
Offline
Senior Newbie

Joined: Thu Dec 10, 2009 4:34 pm
Posts: 7
Okay, I gather the relevant logs and forward them on :)


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 5:25 pm 
Offline
Junior Member

Joined: Wed May 21, 2008 5:34 am
Posts: 46
Website: http://www.eve-razor.com/forum
Location: Austin, Tx
assuming the ssh login attempts are coming from the local network you should add a firewall rule to block ssh/telnet traffic.

else fail2ban or denyhosts is perfect... oh and reporting is always nice.


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 8:27 pm 
Offline
Senior Member

Joined: Mon Dec 07, 2009 6:46 am
Posts: 331
fail2ban etc... waste of resources. Just move ssh away from port 22. You can still keep logging syn packets incoming at port 22 if you wish to file reports.


Top
   
 Post subject:
PostPosted: Wed Feb 03, 2010 10:30 pm 
Offline
Senior Newbie

Joined: Thu Dec 10, 2009 4:34 pm
Posts: 7
actually, we only allow key-based authentication, but we keep denyhosts on, to trigger complete service bans. I know it is mostly futile in the big scheme of things, but it does provide a curious diversion from time to time.


Top
   
 Post subject:
PostPosted: Thu Feb 04, 2010 4:49 pm 
Offline
Senior Member

Joined: Wed Feb 13, 2008 2:40 pm
Posts: 126
+1 for abuse@linode.com, they're very responsive.

make sure to include src & dest IPs as well.


Top
   
 Post subject:
PostPosted: Thu Feb 04, 2010 6:35 pm 
Offline
Senior Newbie

Joined: Thu Dec 10, 2009 4:34 pm
Posts: 7
Yes, they responded right away and in fact, they had already been alerted earlier about the trouble boxes and had already been working with them to address the issue. I was very impressed! :D


Top
   
 Post subject:
PostPosted: Sat Feb 06, 2010 7:02 pm 
Offline
Senior Newbie

Joined: Sun Jan 31, 2010 8:42 pm
Posts: 17
waynemr wrote:
Yes, they responded right away


Always reassuring to know, After reading this i installed DenyHost and im hoping nothing like this happens to me!


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group