LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-03-2008, 02:44 PM   #1
MikeOfAustin
Member
 
Registered: Apr 2007
Location: texas
Distribution: mandriva 2007.0 / edgy
Posts: 63

Rep: Reputation: 15
Denyhosts not updating hosts.deny


My denyhosts is not updating the hosts.deny file for dictionary attacks. It's been running for a while now, and nothing ever gets added. My ssh is at a non-standard port, so I never see any dictionary attacks there. The only reason I want to run denyhosts is to protect my vsftpd.

I have to following userdef set in my denyhosts.conf file
Code:
USERDEF_FAILED_ENTRY_REGEX=.* vsftpd.* authentication failure.* rhost=(?P<host>\S+) user=(?P<user>\S+).*

USERDEF_FAILED_ENTRY_REGEX=.* vsftpd.* authentication failure.* rhost=(?P<host>\S+)
I also have thousands of these entries in my auth.log
Code:
Nov 30 09:10:49 mediacenter vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=Administrator rhost=82.213.5.228
Nov 30 09:10:53 mediacenter vsftpd: pam_unix(vsftpd:auth): check pass; user unknown
Nov 30 09:10:53 mediacenter vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=Administrator rhost=82.213.5.228
Nov 30 09:10:56 mediacenter vsftpd: pam_unix(vsftpd:auth): check pass; user unknown
Nov 30 09:10:57 mediacenter vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=Administrator rhost=82.213.5.228
Nov 30 09:11:00 mediacenter vsftpd: pam_unix(vsftpd:auth): check pass; user unknown
Nov 30 09:11:00 mediacenter vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=Administrator rhost=82.213.5.228
But it's simply not updating the host.deny file. It's not got any entries at all.

However, in the /var/lib/denyhosts/hosts-restriced file, I have

Code:
117.102.83.99:0:Sat Nov 29 15:28:40 2008
192.168.1.121:0:Sat Nov 29 15:28:40 2008
192.88.168.35:0:Mon Dec  1 18:02:56 2008
61.142.17.124:0:Tue Dec  2 07:44:56 2008
63.82.82.17:0:Tue Dec  2 19:50:56 2008
71.97.107.175:0:Sat Nov 29 15:28:40 2008
Any idea what's wrong?

Last edited by MikeOfAustin; 12-03-2008 at 02:50 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
can't restrict sshd access through hosts.allow and hosts.deny but was working earlier farhan Linux - Security 4 04-18-2008 07:41 AM
DenyHosts - false /etc/hosts.deny entries Firebar Linux - Security 10 07-10-2007 04:38 PM
/etc/hosts.deny/hosts.allow have no effect on sshd access bganesh Linux - Security 4 05-04-2006 08:06 PM
updating the change of /etc/hosts.deny in AIX 4.3.3 zepplin611 AIX 7 07-18-2004 02:31 PM
Adding shell commands to hosts.deny and hosts.allow ridertech Linux - Security 3 12-29-2003 03:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration