Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 09-21-2005, 08:09 PM
mikelbeck
Guest
 
Posts: n/a
Default Attack thwarted by bfd

bfd just notifed me that somebody was trying to get into my VPS using ftp, and failed numerous times. bfd locked that person out:

The following are event logs for 31 login failures from 87.123.12.134 on service pure-ftpd (all time stamps are GMT -0400):
----
- Executed actions:
/etc/apf/apf -d 87.123.12.134 {bfd.pure-ftpd}

Just FYI, in case this person will try to get at other VPSs here.
Reply With Quote

  #2  
Old 09-21-2005, 08:17 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default

Added to my deny list =)
__________________
Got clue?
Reply With Quote

  #3  
Old 09-21-2005, 11:10 PM
BornOnline BornOnline is offline
Senior Member
 
Join Date: Feb 2005
Location: Earth
Posts: 173
BornOnline is on a distinguished road
Default

Well.. imagine that... lol

The following are event logs for 11 login failures from 87.123.12.134 on service pure-ftpd
----
- Executed actions:
/etc/apf/apf -d 87.123.12.134 {bfd.pure-ftpd
Reply With Quote

  #4  
Old 09-22-2005, 01:08 AM
capnqwest
Guest
 
Posts: n/a
Default

I don't know about you guys but I get anywhere from 10-25 notifications from BFD about attacks everyday. Some are minor (10-500 attempts) but every now and then I'll get a 4,000 plus attempt which is obviously a script kiddie.
Reply With Quote

  #5  
Old 09-22-2005, 02:36 AM
ozgreg
Guest
 
Posts: n/a
Default

I get between 10-15 a week but it is sadly increasing. So far from what I see from the logs they are nothing but script kiddies.
Reply With Quote

  #6  
Old 09-22-2005, 03:14 AM
KARanden's Avatar
KARanden KARanden is offline
Member
 
Join Date: Jun 2005
Location: Norway
Posts: 79
KARanden is on a distinguished road
Send a message via AIM to KARanden
Default

Quote:
Originally Posted by mikelbeck
bfd just notifed me that somebody was trying to get into my VPS using ftp, and failed numerous times. bfd locked that person out:

The following are event logs for 31 login failures from 87.123.12.134 on service pure-ftpd (all time stamps are GMT -0400):
----
- Executed actions:
/etc/apf/apf -d 87.123.12.134 {bfd.pure-ftpd}

Just FYI, in case this person will try to get at other VPSs here.
The same IP tried to get in to mine VPS also, with no luck

The IP belongs to Versatel in Germany.
__________________
Kjell Arne

From the other side of the "pond"
Norway
Reply With Quote

  #7  
Old 09-22-2005, 08:16 AM
Tony's Avatar
Tony Tony is offline
Senior Sysadmin
 
Join Date: Feb 2005
Location: France
Posts: 278
Tony is on a distinguished road
Default

Changing your SSH port to something none-default will cut down on all but the most serious of folks. =)
__________________
Tony
PowerVPS/DTG

Registered Linux User: #391982
Registered Linux Machine: #292899
Reply With Quote

  #8  
Old 09-22-2005, 08:32 AM
Zaf Zaf is offline
Senior Member
 
Join Date: Aug 2005
Posts: 294
Zaf is on a distinguished road
Default

Quote:
Originally Posted by ozgreg
I get between 10-15 a week but it is sadly increasing. So far from what I see from the logs they are nothing but script kiddies.
I've never received any notification yet till date. Maybe, there wasnt an attack, or maybe I should be more worried than you guys???? which log file should i check to know of these attacks?
__________________
Zaf
Reply With Quote

  #9  
Old 09-22-2005, 09:22 AM
mikelbeck
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Tony
Changing your SSH port to something none-default will cut down on all but the most serious of folks. =)
That's one of the first things I do when setting up a new VPS.

These login failures were coming in via FTP.
Reply With Quote

  #10  
Old 09-22-2005, 04:51 PM
ozgreg
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Shahzada
I've never received any notification yet till date. Maybe, there wasnt an attack, or maybe I should be more worried than you guys???? which log file should i check to know of these attacks?
Make sure your BFD email address is correct or if you have not already install logwatch as you also get notifications of BFD attacks in it's summary as well..
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
BFD management ikaruz Linux VPS - Security and Tuning 0 11-07-2006 07:57 AM
HELP - Denial of Service attack Charlie Linux VPS - Security and Tuning 10 09-22-2006 07:00 PM
Bfd, how to check if bfd is running? soidog Linux VPS - Security and Tuning 6 06-17-2006 12:07 AM
Prophet Mohammed attack - defaced canuck Linux VPS - Security and Tuning 7 02-20-2006 11:42 AM
A better BFD? StingRay Linux VPS - Security and Tuning 4 09-30-2005 12:31 AM



All times are GMT -4. The time now is 04:29 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006