LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-20-2012, 10:00 PM   #1
agriz
Member
 
Registered: Nov 2011
Posts: 197

Rep: Reputation: Disabled
new server got attacked before launching


I tried to track to which url they are targeting.
But i am surprised to see that

Code:
ip            url
180.76.6.37   externalwebsites.com
How is it possible. How to secure this?
 
Old 07-21-2012, 12:37 AM   #2
UndiFineD
LQ Newbie
 
Registered: Jun 2004
Location: Netherlands
Distribution: adistro
Posts: 24

Rep: Reputation: 0
hello agriz,
what makes you think it is an attack ?
is this new server replacing a previous setup ?
are you using an ip address that belonged to someone else before ?

that server could have been setup to probe for the ip address you are using now
from previous usage. My firewall reports blocked traffic all day.
and your server is going to be a lot more attractive once 1 or more services may be running.
Blocked traffic does not mean cracking attempts perse.

however the ip address used can be traced
http://whatismyipaddress.com/ip/180.76.6.37
which shows that it is from china
and many cracks may seem to originate from china.

To prevent such from happening you could block ip regions that are often used to originate attacks from.
that means large blocks of addresses are being prevented from accessing your server.
The downside is that potential customers from those areas cannot reach you.
but if you do not have any intentions doing business with them this makes life a lot eassier.

Blocking ranges does have the downside that it takes up memory and performance to connect to your server.
 
Old 07-21-2012, 03:25 AM   #3
agriz
Member
 
Registered: Nov 2011
Posts: 197

Original Poster
Rep: Reputation: Disabled
just spoke with the host.
someone who used it before i buy was using that ip range 180.76.
 
Old 07-21-2012, 07:33 AM   #4
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Any server connected to a public network WILL get bombarded with attempts to probe it. The probes are looking for vulnerabilities to exploit with the ultimate goal of obtaining root level control over your system. Your objective is to not give them any.

An important part of the process is developing an awareness of these "attacks" and it looks like you may have picked up evidence of one. What you need to do to protect against these probes and attacks depends upon what server processes you are running as each one has unique weaknesses and methods to secure it.

I would recommend that you start by reading through the security references section here, especially the introductory parts to start getting an understanding of how to approach server security.

If you need help with this particular case, please post actual data, such as portions of log files, and describe the symptoms, problems, etc and be verbose in your descriptions.
 
Old 07-21-2012, 04:57 PM   #5
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
If it was a used system then it can't be secure at all. What do you mean the person you got it from used the 180.x.x.x ip number?
 
Old 07-21-2012, 05:08 PM   #6
Jc61990
LQ Newbie
 
Registered: Dec 2008
Location: New York
Distribution: Arch
Posts: 18

Rep: Reputation: 0
there are a couple of things you could install to help keep some of the attackers out, but wont do it 100%

a few i use are
Fail2Ban http://www.fail2ban.org - scans log files and bans IPs that show the malicious signs; too many password failures, seeking for exploits, etc
Aide http://aide.sourceforge.net/ - Advanced Intrusion Detection Environment - basically a file integrity checker
Jailkit http://olivier.sessink.nl/jailkit/ - is another good one this will chroot your SSH users to certain folders and commands

theres many others but look into a few of these they might be able to help out a bit

Last edited by Jc61990; 07-21-2012 at 05:10 PM.
 
Old 07-23-2012, 08:38 AM   #7
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Well, of course you start by wiping the system clean and doing a "minimal" install. Of course you don't use systems like Plesk ...
 
Old 07-23-2012, 08:50 AM   #8
agriz
Member
 
Registered: Nov 2011
Posts: 197

Original Poster
Rep: Reputation: Disabled
Bind is keep banning those IPs. I can see it from system messages.
Also, They are just targeting the IP. So i just sent those banned ip to null page.
 
Old 07-23-2012, 08:52 AM   #9
agriz
Member
 
Registered: Nov 2011
Posts: 197

Original Poster
Rep: Reputation: Disabled
query (cache) 'some-external-site.com' denied

this is system log message
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Nintendo server attacked by hacking group Lulz Security Jeebizz Linux - News 0 06-06-2011 08:32 AM
[SOLVED] Apache server being attacked, strange requests. miragej Linux - Server 9 10-17-2010 07:44 PM
Has my linux server been hacked/cracked/attacked? jsalelle Linux - Security 11 12-31-2009 03:11 AM
Help me. My server is attacked DDoS ndduy Linux - Security 12 11-29-2009 02:47 PM
qmail server getting attacked lsimon4180 Linux - Software 41 10-15-2004 03:44 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration