LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 06-03-2008, 06:44 AM   #1
Zenya
LQ Newbie
 
Registered: Apr 2008
Posts: 2

Rep: Reputation: 0
BFD Rules outdated for pure-ftpd and syslog-ng?


Does anyone have any working rules for bfd thats currently working
with pure-ftpd? the default rules are a bit outdated as well as the pattern files, the sshd side of it works as intended but my lods are still littered with:

Code:
Jun  3 00:45:37 mystydragon pure-ftpd: (?@66.11.116.140) [WARNING] Authentication failed for user [Administrator]
Jun  3 00:45:53 mystydragon pure-ftpd: (?@66.11.116.140) [WARNING] Authentication failed for user [Administrator]
Jun  3 00:45:57 mystydragon pure-ftpd: (?@66.11.116.140) [WARNING] Authentication failed for user [Administrator]
the default rule seems to not pick anything up, i believe this is due to
not having the standard syslog daemon? and i dont think the rule will also DNS the target if it has a hostname instead of ip. So im curious if anyones wirrten up a new pattern file and new rules for pure-ftpd so that will pick it up and add them to the deny-hosts.rules in apf like ti does with sshd by default.


P.S yes i didnt edit out that ip as its been goin on for a good straight 2 weeks now, and ive sent numerous abuse reports to its domain.
 
Old 06-06-2008, 07:26 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Quote:
Originally Posted by Zenya View Post
the default rule seems to not pick anything up, i believe this is due to not having the standard syslog daemon?
Shouldn't matter I think. As long as local logs get logged to you're fine. Just change the logfile location in conf.bfd.


Quote:
Originally Posted by Zenya View Post
and i dont think the rule will also DNS the target if it has a hostname instead of ip.
And even if it did resolve names it shouldn't. While it may appear convenient to you as log reader, resolving is really too costly especially if you have huge amounts of connections from different sources and what does a hostname reveal anyway?


Quote:
Originally Posted by Zenya View Post
So im curious if anyones wirrten up a new pattern file and new rules for pure-ftpd so that will pick it up and add them to the deny-hosts.rules in apf like ti does with sshd by default.
If you can come up with some generic loglines I'm sure we could turn those into rules.


Quote:
Originally Posted by Zenya View Post
that ip as its been goin on for a good straight 2 weeks now
While sending reports is laudable a lot of ISPs archive complaints in their /dev/null mailbox (not that that should stop you from sending in any). Maybe add a static entry in your iptables rules for that offender or look into iptables modules like 'recent'.
 
  


Reply

Tags
apf, rules, syslogng


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Will the BFD or any brute force detector work if I am logging to a remote syslog serv abefroman Linux - Software 2 06-02-2008 05:08 AM
pure-ftpd-mysql activates pure-ftpd zvikamer Linux - Software 2 03-01-2008 12:11 PM
pure-ftpd syslog facility devacom Linux - Software 0 01-05-2005 07:11 AM
Pure FTPD help oACEo Linux - Newbie 2 12-07-2003 11:34 AM
help with pure-ftpd blank Linux - General 3 03-31-2002 10:54 AM


All times are GMT -5. The time now is 05:18 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration