LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-09-2009, 02:02 PM   #1
jlumpkins
LQ Newbie
 
Registered: Jun 2007
Posts: 2

Rep: Reputation: 0
Fedora 11; Missing a day in /var/log/secure Puzzled, and concerned...


Hi,

I have a Fedora 11 server exposed to the Internet through the DMZ in my Astaro security box. Every morning I get an email listing all of the bad attempts to gain ssh access. Most days I get one or two IP addresses that have tried hundreds of times to log in as root, unknown, and/or other well known users. As to date, none have been successful. Every time I find an IP address that has tried this, I look up the network that the IP belongs to, and send them an email along with log entries showing when the foreign host tried to break in. I then add an extra line to iptables blocking the entire class C network around the IP in question. I've been doing this for a few months now, and hopefully, I've helped eliminate at least one or two hackers. (I would love to see footage of an F-16 rolling in on their home, and dropping napalm, but, I would settle for just knowing that they lost their ISP.

My question is that last week when I was checking my logs (/var/log/secure), I noticed that I have an entire day missing. I don't know that this is indicative of a successful break in because nothing appears to be wrong, but, I'm a little concerned. Has anybody else noticed Nov 6th missing from /var/log/secure*?

I know the server was up, and that iptables was active.

Also, I've added some additional lines to iptables after reading an article on security that was supposed to disable a given host for 5 minutes after 5 bad attempts within 5 minutes as a way to automatically block attempts without having to block the IP addresses, and this doesn't seem to be working:

Chain SSH (1 references)
target prot opt source destination
REJECT all -- 0.0.0.0/0 0.0.0.0/0 recent: UPDATE seconds: 300 name: SSH_COUNTER side: source reject-with icmp-port-unreachable
SSH_BLACKLIST all -- 0.0.0.0/0 0.0.0.0/0 recent: CHECK seconds: 60 hit_count: 5 name: SSH side: source
LOG all -- 0.0.0.0/0 0.0.0.0/0 recent: CHECK seconds: 2 name: SSH side: source LOG flags 0 level 4 prefix `Added: '
REJECT all -- 0.0.0.0/0 0.0.0.0/0 recent: UPDATE seconds: 2 name: SSH side: source reject-with icmp-port-unreachable
LOG all -- 0.0.0.0/0 0.0.0.0/0 recent: REMOVE name: SSH_COUNTER side: source LOG flags 0 level 4 prefix `Removed: '
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 recent: SET name: SSH side: source

Chain SSH_BLACKLIST (1 references)
target prot opt source destination
LOG all -- 0.0.0.0/0 0.0.0.0/0 recent: SET name: SSH_COUNTER side: source LOG flags 0 level 4 prefix `Blocked: '
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable


If anybody has any idea why this is failing, I would appreciate your thoughts.

One other question... Is there any global authority that one should report attempted break ins to? I would love to contribute in a meaningful way to putting some hackers away.


Regards,


Jerry Lumpkins
 
Old 11-09-2009, 05:45 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by jlumpkins View Post
Every time I find an IP address that has tried this, I look up the network that the IP belongs to, and send them an email along with log entries showing when the foreign host tried to break in. (..) they lost their ISP.
+1 for effort and not to temper your enthusiasm but unfortunately most SOHO ISPs don't have the manpower to deal with it adequately. Often these well-meaning reports will get filed in the bit bucket.


Quote:
Originally Posted by jlumpkins View Post
I've been doing this for a few months now, and hopefully, I've helped eliminate at least one or two hackers.
Also a cracker may use any set of intermediaries so this may be an already compromised server or home machine. A cracker may or may not be interested in recovering or compromising it again and just move on. Economics of cracking and such.


Quote:
Originally Posted by jlumpkins View Post
I noticed that I have an entire day missing. (..) Has anybody else noticed Nov 6th missing from /var/log/secure*?
Does this also apply to your other logs? Any other indication of system changes on or leading up to that day?


Quote:
Originally Posted by jlumpkins View Post
this doesn't seem to be working
I don't know about others but I don't read 'iptables -L' well: I'd rather see actual iptables rules instead.


Quote:
Originally Posted by jlumpkins View Post
Is there any global authority that one should report attempted break ins to?
With the amount of machines getting scanned (all) versus the amount of damage done (none) the only parties I know would be interested in data for trending purposes would be Dshield (http://www.dshield.org) and Mywatchmen (http://www.mynetwatchman.com/).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can Samhain log my entries in /var/log/secure and /var/log/mesage to a central server abefroman Linux - Software 2 04-13-2008 04:13 PM
/var/log/procmail.log.1 being mailed every day soylentgreen Linux - Server 3 07-10-2007 02:47 PM
/var/log/secure ??? MikeFoo1 Linux - Security 2 06-22-2005 03:42 AM
/var/log/messages full of these messages. Should I be concerned? mdavis Linux - Security 5 04-16-2004 10:08 AM
/var/log/secure dragon Linux - Security 6 12-02-2003 08:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration