fail2ban + dns = failTrackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
I guess I should take all the blame for this:
commit 042e160eeb3d7a09b0bb8dcda92f284bc3889f1d Author: lostcontrol Date: Wed Aug 8 22:21:15 2007 +0000 - Added filter file for named (bind9). Thanks to Yaroslav Halchenko But I wonder why for "bad ... idea why this filter is shipped in a default fail2ban installation" I see no new bug report among http://bugs.debian.org/cgi-bin/pkgreport.cgi?archive=both;src=fail2ban;submitter=nion%40debian.org This one indeed should be highly unadvised (and removed from jails.conf shipped with Debian) unless ignoreip can cover the range of valuable not-to-DoS for sure IPs ... or may be there is another precaution (matching incoming IPs based on interfaces on gateways etc) you have in mind? anyways, awaiting for a bug report P.S. I still consider 'rm' to be the most dangerous command of all times... god bless zsh and its protective powers
excuse my lazyness, I was too lazy to report this as a bug. Imho the whole fail2ban package should ship with a big fat warning for unexperienced users. anyway, I filed one now.
@zsh, I do agree
"for unexperienced users" I bet noone really would run a serious targetted DoS attack, but some automated script junkies looking looking for easy targets and doing dictionary attacks. And that is where (and thus for whom) fail2ban shines. DNS issue though is a bit closer to the reality of admins, and they better be experienced, and if they are not, such DoS would be the gentle lesson... may be I should advocate it as an educational tool then
but point is taken -- I might add some warning (thought about it myself as well)
yes i agree on that though in the case of dns providing a filter for udp really doesn't make sense
Add Comment
|
Calendar
QuicksearchSupportRecent EntriesWill my Phone Show An Unencrypted Connection?
Wednesday, September 8 2010 smpCTF 2010 quals writeups Sunday, August 8 2010 protocol design fail: MMS notification Wednesday, July 28 2010 acrobat reader stealing my passwords Tuesday, June 29 2010 UnrealIRCd backdoored Saturday, June 12 2010 fail of the day: opera Wednesday, June 9 2010 fail2ban + dns = fail Wednesday, May 26 2010 evolution of spam or WTF is this! Friday, March 19 2010 if you type google into google... Wednesday, March 17 2010 Two weeks with the n900 Monday, February 8 2010 ArchivesCategoriesTag cloud23c3 acpi advertising annouce announce april argh art awards bash blogging browser bugs cli code config configuration copyright data mining debconf debian dns documentation email errm? events fail fail2ban filesharing films flame fun gcc google graphs grml hacking hacks hardware heise images information installation internet irc knowledge libacpi links linux mail monitoring network networking news newsbeuter nonsense openoffice open source opera passwords php phrack piratebay power privacy programming qa random blurb rant release releases rss scripts security service setup shell software spam ssh stuff terminal tests text mode tip tips tools troubleshooting unix user video vim.editing web websites wikipedia wordpress wtf www youtube zsh
|
|||||||||||||||||||||||||||||||||||||||||||||||||