bar top left
bar top right
left curve
right curve
Welcome, Guest
Go to bottom
Post Reply
Post New Topic
Page: 12345
TOPIC: Unable to Install Fail2Ban
*
#67236
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 156
You need to move ssh away from 22, you probably don't need ftp exposed, do you have folks using you as a IMAP server, what is running on 2222 ? ( too obvious), WTF telnet!! immediately turn that off, Only allow https from trusted networks. you have FOP AMI MYSQL possibly exposed.

(back to the drawing board ? )

your FreePBX ARI/recordings is both broken and leaking, this is normal but very bad in Elastix, are you sure your very old vtiger login is secure?

I guess in other words, get your Firewall working first before you do the IDS thingy, try CSF it's easy as pie
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
dicko
Ethically, I no longer support PaloSanto, Sorry.
Platinum Boarder
Posts: 4100
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Not available Birthday: 01/21
Last Edit: 2010/12/24 02:18 By dicko.
There are other solutions!!
Reply Quote
 
#67237
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 19
I must have done something incorrectly, I thought I had moved from port 22, no one use machine for IMAP and was not aware that telnet was even on - never activated it, and 2222 ???? I've only had this box up and running for a week or so and this is the first time I have a chance to mess with it. As you say, back to the drawing board.

Thanks
Amphibian
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Amphibian
At my age, I don't have time to read the book.....
Expert Boarder
Posts: 553
graphgraph
User Offline Click here to see the profile of this user
Gender: Male monster_cookie21482 Amphibian Solutions monster_cookie2148 Location: Texas my friend, Texas Birthday: 01/01
"I may not be the sharpest tool in the shed, but, I'm not the only dull tool in the shed either.
Reply Quote
 
#67239
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 19
I thought port 22 was changed under /etc/ssh/sshd_config by uncommetting "Port 22 and changing it to another value? I had changed it to 2222, not right???

Amphibian
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Amphibian
At my age, I don't have time to read the book.....
Expert Boarder
Posts: 553
graphgraph
User Offline Click here to see the profile of this user
Gender: Male monster_cookie21482 Amphibian Solutions monster_cookie2148 Location: Texas my friend, Texas Birthday: 01/01
"I may not be the sharpest tool in the shed, but, I'm not the only dull tool in the shed either.
Reply Quote
 
#67244
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 156
I can only see you from the outside of your network,

netstat -aunt

will show you all the services you have running, each and every one presenting on 0.0.0.0 needs to be examined as to whether it should be allowed through your firewall, and if so to what address space should be allowed to access it.

don't forget that I also see the services running on your firewall, telnet is probably originating from there, it should not be.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
dicko
Ethically, I no longer support PaloSanto, Sorry.
Platinum Boarder
Posts: 4100
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Not available Birthday: 01/21
Last Edit: 2010/12/24 03:24 By dicko.
There are other solutions!!
Reply Quote
 
#67248
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 19
I issued that command earlier when you maid mention of telnet running, I'm not showing telnet as active on machine or on firewall or router. I have even tried to telnet to all the machines on network and none are telnet active.

I'm also not sure I follow your directive to "your FreePBX ARI/recordings is both broken and leaking", have to research that one.


Amphibian
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Amphibian
At my age, I don't have time to read the book.....
Expert Boarder
Posts: 553
graphgraph
User Offline Click here to see the profile of this user
Gender: Male monster_cookie21482 Amphibian Solutions monster_cookie2148 Location: Texas my friend, Texas Birthday: 01/01
"I may not be the sharpest tool in the shed, but, I'm not the only dull tool in the shed either.
Reply Quote
 
#67249
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 156
To audit your network it is necessary to do it from both sides, get an external shell login from someone and look back at your network.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
dicko
Ethically, I no longer support PaloSanto, Sorry.
Platinum Boarder
Posts: 4100
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Not available Birthday: 01/21
There are other solutions!!
Reply Quote
 
#67250
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 19
Well, that's my prob, I don't have anyone to do that with that is why I'm so appreciative of your help this evening.

See, AH like me don't have very many friends you know, especially in the Tech department

The broken or leaky thingee looks like an upgrade requirement. Will do update and get back with you, been up 32 hours now, taking a break and will return in a few hours. Thanks once again you have been very helpful. I owe you big time.


Amphibian
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Amphibian
At my age, I don't have time to read the book.....
Expert Boarder
Posts: 553
graphgraph
User Offline Click here to see the profile of this user
Gender: Male monster_cookie21482 Amphibian Solutions monster_cookie2148 Location: Texas my friend, Texas Birthday: 01/01
Last Edit: 2010/12/24 04:28 By Amphibian.
"I may not be the sharpest tool in the shed, but, I'm not the only dull tool in the shed either.
Reply Quote
 
#67251
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 105
Amphibian wrote:
I thought the 172 was an IP address. Since this box is on a DSL whom assigns different IP at times, I have gone with dyndns.org. Will this script accept the dyndns.org instead of a IP number?

Amphibian



If you need to allow your dyndns host you can use csf.

www.configserver.com/cp/csf.html

You can insert your dyndns host into /etc/csf/csf.dyndns


Happy Christmas to all!!!
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
ramoncio
Gold Boarder
Posts: 1674
graphgraph
User Offline Click here to see the profile of this user
Reply Quote
 
#67270
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 19
Hey ramoncio,

Sorry I missed you, I called it a night just before your post. Thanks for the reply. I see I'm going to have to put a larger fuel tank on my Ultr-lite and fly down to Dicko's and Your place to take you guys to lunch, you both have been very helpful and knowledgeable, not only me, with this forum. It can't be stated enough how lost we all would be without you guys.

I looked CSF over earlier this morning after Dicko mentioned it in a post. I'm going to try to load CFS later today and see how knowledgeable I am to set it up.

I did read on the CFS site that "You should not run any other iptables firewall configuration script. For example, if you previously used APF+BFD you can remove the combination (which you will need to do if you have them installed otherwise they will conflict horribly): .....",

are there any scripts known (and where they are located) that I have to remove to prevent conflict?


Thanks again & Merry Christmas
Amphibian
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Amphibian
At my age, I don't have time to read the book.....
Expert Boarder
Posts: 553
graphgraph
User Offline Click here to see the profile of this user
Gender: Male monster_cookie21482 Amphibian Solutions monster_cookie2148 Location: Texas my friend, Texas Birthday: 01/01
"I may not be the sharpest tool in the shed, but, I'm not the only dull tool in the shed either.
Reply Quote
 
#67275
Re:Unable to Install Fail2Ban 2 Years, 4 Months ago Karma: 156
Generally too many cooks will spoil the broth, but CSF and fail2ban will coexist quite easily, just

chkconfig fail2ban off
service fail2ban stop
make two executable scripts in /etc/csf directory:=

[root@pbx csf]# cat csfpre.sh
#!/bin/sh
/etc/init.d/fail2ban stop

[root@pbx csf]# cat csfpost.sh
#!/bin/sh
/etc/init.d/fail2ban start

this will start fail2ban afgetr csf starts and vece versa, the scripts do not conflict.

I posted a regex.custom.pm somewhere around here that will hopefully do the same for csf without fail2banbut am not sure if it as effective as fail2ban
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
dicko
Ethically, I no longer support PaloSanto, Sorry.
Platinum Boarder
Posts: 4100
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Not available Birthday: 01/21
There are other solutions!!
Reply Quote
 
Go to top
Post Reply
Post New Topic
Page: 12345
Moderators: Bob, jgutierrez

elastix

Protected by Spam Fighter