Fail2ban ssh: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
| Zeile 19: | Zeile 19: | ||
*systemctl restart fail2ban | *systemctl restart fail2ban | ||
=Status checken= | =Status checken= | ||
| − | *fail2ban-client status sshd | + | *'''fail2ban-client status sshd''' |
<pre> | <pre> | ||
Status for the jail: sshd | Status for the jail: sshd | ||
| Zeile 29: | Zeile 29: | ||
|- Currently banned: 1 | |- Currently banned: 1 | ||
|- Total banned: 1 | |- Total banned: 1 | ||
| − | `- Banned IP list: | + | `- Banned IP list: 10.0.1''xx''.2 |
</pre> | </pre> | ||
| + | |||
=Alles unbannen= | =Alles unbannen= | ||
*fail2ban-client unban --all | *fail2ban-client unban --all | ||
Version vom 7. August 2023, 21:16 Uhr
Hydra installieren (Hacking & Security Seite 136)
- apt update
- apt install hydra
Passwordliste laden
Brute Force auf den SFTP Server vom DNS Server aus
- hydra -l gast -s 2222 -P bad-passwords sftp.lab1xx.sec sftp
sshd in fail2ban aktivieren
- vim /etc/fail2ban/jail.local
[sshd] enable = true port = 2222
fail2ban neustarten
- systemctl restart fail2ban
Status checken
- fail2ban-client status sshd
Status for the jail: sshd |- Filter | |- Currently failed: 1 | |- Total failed: 14 | `- File list: /var/log/auth.log `- Actions |- Currently banned: 1 |- Total banned: 1 `- Banned IP list: 10.0.1''xx''.2
Alles unbannen
- fail2ban-client unban --all