Fail2ban vsftpd

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

Hydra installieren

  • apt install hydra

brute Force auf den Rechner

  • hydra -l xinux -P bad-passwords 10.88.201.21 ftp

sshd in fail2ban aktivieren

  • echo -e "[vstpd]\nenabled = true\n" >> /etc/fail2ban/jail.local

fail2ban neustarten

  • systemctl restart fail2ban

Status checken

  • fail2ban-client status vsftpd
Status for the jail: vsftpd
|- Filter
|  |- Currently failed:	0
|  |- Total failed:	15
|  `- File list:	/var/log/vsftpd.log
`- Actions
   |- Currently banned:	1
   |- Total banned:	1
   `- Banned IP list:	172.31.31.1

Alles unbannen

  • fail2ban-client unban --all