LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-06-2009, 09:40 PM   #1
tiger.woods
Member
 
Registered: Mar 2006
Posts: 122

Rep: Reputation: 15
ProFTPd 1.31 and mod_ban...


I'm noticing my server is getting hit pretty hard by what I assume is a brute force attack on my FTP server. I noticed that the mod_ban that proFTPd has in 1.32 isn't installed on 1.31. Can I implement something on 1.31 that will help with the attack? will mod_ban work or MaxLoginAttempts 1.31?

I could use some help implementing...

Thanks.

TW,
 
Old 12-07-2009, 12:27 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

mod_ban is available since proftpd-1.2.x, so I guess it's not compiled in the proftpd package you're using. You can try to find a proftpd package with mod_ban compiled-in, or you can compile proftpd yourself and add the modules you want.
As an alternative consider using fail2ban that already contains a module to support proftpd.

Regards
 
Old 12-07-2009, 06:32 PM   #3
tiger.woods
Member
 
Registered: Mar 2006
Posts: 122

Original Poster
Rep: Reputation: 15
Thanks for the reply bathroy,

After doing some looking I found in /usr/lib/proftpd

mod_ban.so
mod_ban.a
mod_ban.la

So I think the mod_ban is compiled in but I don't see a config file? should I simply create a config file similar to the installation instructions (http://www.castaglia.org/proftpd/mod...Installation)?

Last edited by tiger.woods; 12-07-2009 at 07:14 PM.
 
Old 12-08-2009, 12:36 AM   #4
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
So I think the mod_ban is compiled in but I don't see a config file? should I simply create a config file similar to the installation instructions (http://www.castaglia.org/proftpd/mod...Installation)?
It looks like mod_ban is compiled as a dso, while the instructions are talking for the case the module is compiled in proftpd.
Reading the proftpd dso documentation, it looks like you have to add
Code:
LoadModule mod_ban.c
, before using the module.

Regards
 
Old 12-08-2009, 05:50 AM   #5
tiger.woods
Member
 
Registered: Mar 2006
Posts: 122

Original Poster
Rep: Reputation: 15
Ah, thanks for the help I hot it going.

TW,
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
proftpd: proftpd startup failed tumana Linux - Newbie 14 06-17-2012 11:06 AM
ProFTPd - Change proftpd.conf location ('not found' error) varney Linux - Newbie 1 02-22-2008 01:51 AM
[PROFTPD] Ldap and proftpd authentication wesleywest Linux - Software 1 02-22-2005 09:51 AM
Disabling the chroot in proftpd and enabling root logins on ssh/proftpd jon_k Linux - Software 1 06-16-2004 10:27 AM
proftpd --- need help? could someone post a working proftpd.conf i could look at ZooRoPa Linux - Networking 1 04-02-2003 06:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration