- Registriert
- 17. März 2009
- Beiträge
- 29.409
- Lösungen
- 9
- Reaktionspunkte
- 18.436
- Punkte
- 1.083
- Ort
- Unter ne Brücke
AW: fail2ban für CCcam installieren
ok , jungs und medels , ich bin auch jetzt mit ilegalen user unterwegs die mir langsam auf den sack gehen und ich will sie banen , habe so weit fail2ban instaliert , und configuriert , aber bin mir nicht 100% sicher ob es auch richtig funktioniert
ah so , nutze cccam 2.1.1
hier mal die fail2ban log
ergend wie kommen zu viele errors und ich weis nicht ob es auch richtig so ist
wer kann helfen ??
PS.
wie bekomme ich das die fail2ban auch automatisch nach server rebot startet ??
hab server rebot gemacht und 2 dateien wider hergestelt die ich bearbeitet habe und das kommt jetzt heraus
itables -L
fail2ban log
und es pasiert mehr aber nichts
ok , jungs und medels , ich bin auch jetzt mit ilegalen user unterwegs die mir langsam auf den sack gehen und ich will sie banen , habe so weit fail2ban instaliert , und configuriert , aber bin mir nicht 100% sicher ob es auch richtig funktioniert
ah so , nutze cccam 2.1.1
hier mal die fail2ban log
2012-11-24 12:11:52,915 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_badcmd
iptables -F fail2ban-cccam_badcmd
iptables -X fail2ban-cccam_badcmd returned 100
2012-11-24 12:11:53,263 fail2ban.jail : INFO Jail 'cccam_badcmd' stopped
2012-11-24 12:11:53,918 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_2login
iptables -F fail2ban-cccam_2login
iptables -X fail2ban-cccam_2login returned 100
2012-11-24 12:11:54,265 fail2ban.jail : INFO Jail 'cccam_2login' stopped
2012-11-24 12:11:54,922 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_sign
iptables -F fail2ban-cccam_sign
iptables -X fail2ban-cccam_sign returned 100
2012-11-24 12:11:54,923 fail2ban.jail : INFO Jail 'cccam_sign' stopped
2012-11-24 12:11:55,924 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_illegal
iptables -F fail2ban-cccam_illegal
iptables -X fail2ban-cccam_illegal returned 100
2012-11-24 12:11:55,925 fail2ban.jail : INFO Jail 'cccam_illegal' stopped
2012-11-24 12:11:56,926 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports ssh -j fail2ban-ssh
iptables -F fail2ban-ssh
iptables -X fail2ban-ssh returned 100
2012-11-24 12:11:56,927 fail2ban.jail : INFO Jail 'ssh' stopped
2012-11-24 12:11:56,934 fail2ban.server : INFO Exiting Fail2ban
2012-11-24 12:11:58,190 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.4
2012-11-24 12:11:58,193 fail2ban.jail : INFO Creating new jail 'cccam_badcmd'
2012-11-24 12:11:58,193 fail2ban.jail : INFO Jail 'cccam_badcmd' uses poller
2012-11-24 12:11:58,242 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,245 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,250 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,253 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,282 fail2ban.jail : INFO Creating new jail 'ssh'
2012-11-24 12:11:58,282 fail2ban.jail : INFO Jail 'ssh' uses poller
2012-11-24 12:11:58,286 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2012-11-24 12:11:58,289 fail2ban.filter : INFO Set maxRetry = 6
2012-11-24 12:11:58,294 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,297 fail2ban.actions: INFO Set banTime = 600
2012-11-24 12:11:58,495 fail2ban.jail : INFO Creating new jail 'cccam_2login'
2012-11-24 12:11:58,496 fail2ban.jail : INFO Jail 'cccam_2login' uses poller
2012-11-24 12:11:58,499 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,502 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,506 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,509 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,532 fail2ban.jail : INFO Creating new jail 'cccam_sign'
2012-11-24 12:11:58,533 fail2ban.jail : INFO Jail 'cccam_sign' uses poller
2012-11-24 12:11:58,536 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,539 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,543 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,546 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,569 fail2ban.jail : INFO Creating new jail 'cccam_illegal'
2012-11-24 12:11:58,570 fail2ban.jail : INFO Jail 'cccam_illegal' uses poller
2012-11-24 12:11:58,573 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,576 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,580 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,583 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,608 fail2ban.jail : INFO Jail 'cccam_badcmd' started
2012-11-24 12:11:58,617 fail2ban.jail : INFO Jail 'ssh' started
2012-11-24 12:11:58,636 fail2ban.jail : INFO Jail 'cccam_2login' started
2012-11-24 12:11:58,660 fail2ban.jail : INFO Jail 'cccam_sign' started
2012-11-24 12:11:58,677 fail2ban.jail : INFO Jail 'cccam_illegal' started
iptables -F fail2ban-cccam_badcmd
iptables -X fail2ban-cccam_badcmd returned 100
2012-11-24 12:11:53,263 fail2ban.jail : INFO Jail 'cccam_badcmd' stopped
2012-11-24 12:11:53,918 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_2login
iptables -F fail2ban-cccam_2login
iptables -X fail2ban-cccam_2login returned 100
2012-11-24 12:11:54,265 fail2ban.jail : INFO Jail 'cccam_2login' stopped
2012-11-24 12:11:54,922 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_sign
iptables -F fail2ban-cccam_sign
iptables -X fail2ban-cccam_sign returned 100
2012-11-24 12:11:54,923 fail2ban.jail : INFO Jail 'cccam_sign' stopped
2012-11-24 12:11:55,924 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports 54321 -j fail2ban-cccam_illegal
iptables -F fail2ban-cccam_illegal
iptables -X fail2ban-cccam_illegal returned 100
2012-11-24 12:11:55,925 fail2ban.jail : INFO Jail 'cccam_illegal' stopped
2012-11-24 12:11:56,926 fail2ban.actions.action: ERROR iptables -D INPUT -p tcp -m multiport --dports ssh -j fail2ban-ssh
iptables -F fail2ban-ssh
iptables -X fail2ban-ssh returned 100
2012-11-24 12:11:56,927 fail2ban.jail : INFO Jail 'ssh' stopped
2012-11-24 12:11:56,934 fail2ban.server : INFO Exiting Fail2ban
2012-11-24 12:11:58,190 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.4
2012-11-24 12:11:58,193 fail2ban.jail : INFO Creating new jail 'cccam_badcmd'
2012-11-24 12:11:58,193 fail2ban.jail : INFO Jail 'cccam_badcmd' uses poller
2012-11-24 12:11:58,242 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,245 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,250 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,253 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,282 fail2ban.jail : INFO Creating new jail 'ssh'
2012-11-24 12:11:58,282 fail2ban.jail : INFO Jail 'ssh' uses poller
2012-11-24 12:11:58,286 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2012-11-24 12:11:58,289 fail2ban.filter : INFO Set maxRetry = 6
2012-11-24 12:11:58,294 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,297 fail2ban.actions: INFO Set banTime = 600
2012-11-24 12:11:58,495 fail2ban.jail : INFO Creating new jail 'cccam_2login'
2012-11-24 12:11:58,496 fail2ban.jail : INFO Jail 'cccam_2login' uses poller
2012-11-24 12:11:58,499 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,502 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,506 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,509 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,532 fail2ban.jail : INFO Creating new jail 'cccam_sign'
2012-11-24 12:11:58,533 fail2ban.jail : INFO Jail 'cccam_sign' uses poller
2012-11-24 12:11:58,536 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,539 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,543 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,546 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,569 fail2ban.jail : INFO Creating new jail 'cccam_illegal'
2012-11-24 12:11:58,570 fail2ban.jail : INFO Jail 'cccam_illegal' uses poller
2012-11-24 12:11:58,573 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:11:58,576 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:11:58,580 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:11:58,583 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:11:58,608 fail2ban.jail : INFO Jail 'cccam_badcmd' started
2012-11-24 12:11:58,617 fail2ban.jail : INFO Jail 'ssh' started
2012-11-24 12:11:58,636 fail2ban.jail : INFO Jail 'cccam_2login' started
2012-11-24 12:11:58,660 fail2ban.jail : INFO Jail 'cccam_sign' started
2012-11-24 12:11:58,677 fail2ban.jail : INFO Jail 'cccam_illegal' started
ergend wie kommen zu viele errors und ich weis nicht ob es auch richtig so ist
wer kann helfen ??
PS.
wie bekomme ich das die fail2ban auch automatisch nach server rebot startet ??
hab server rebot gemacht und 2 dateien wider hergestelt die ich bearbeitet habe und das kommt jetzt heraus
itables -L
root@S-400:~# /etc/init.d/fail2ban restart
* Restarting authentication failure monitor fail2ban [ OK ]
root@S-400:~# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
fail2ban-cccam_2login tcp -- anywhere anywhere multiport dports 54321
fail2ban-cccam_illegal tcp -- anywhere anywhere multiport dports 54321
fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
fail2ban-cccam_sigfail tcp -- anywhere anywhere multiport dports 54321
fail2ban-cccam_badcmd tcp -- anywhere anywhere multiport dports 54321
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain fail2ban-cccam_2login (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_badcmd (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_illegal (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_sigfail (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-ssh (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
root@S-400:~#
* Restarting authentication failure monitor fail2ban [ OK ]
root@S-400:~# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
fail2ban-cccam_2login tcp -- anywhere anywhere multiport dports 54321
fail2ban-cccam_illegal tcp -- anywhere anywhere multiport dports 54321
fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
fail2ban-cccam_sigfail tcp -- anywhere anywhere multiport dports 54321
fail2ban-cccam_badcmd tcp -- anywhere anywhere multiport dports 54321
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain fail2ban-cccam_2login (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_badcmd (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_illegal (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-cccam_sigfail (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-ssh (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
root@S-400:~#
fail2ban log
2012-11-24 12:32:57,748 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.4
2012-11-24 12:32:57,751 fail2ban.jail : INFO Creating new jail 'cccam_badcmd'
2012-11-24 12:32:57,752 fail2ban.jail : INFO Jail 'cccam_badcmd' uses poller
2012-11-24 12:32:57,799 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:57,802 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:57,806 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,809 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:57,834 fail2ban.jail : INFO Creating new jail 'cccam_sigfail'
2012-11-24 12:32:57,835 fail2ban.jail : INFO Jail 'cccam_sigfail' uses poller
2012-11-24 12:32:57,839 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:57,842 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:57,847 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,850 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:57,876 fail2ban.jail : INFO Creating new jail 'ssh'
2012-11-24 12:32:57,877 fail2ban.jail : INFO Jail 'ssh' uses poller
2012-11-24 12:32:57,881 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2012-11-24 12:32:57,884 fail2ban.filter : INFO Set maxRetry = 6
2012-11-24 12:32:57,889 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,892 fail2ban.actions: INFO Set banTime = 600
2012-11-24 12:32:58,085 fail2ban.jail : INFO Creating new jail 'cccam_2login'
2012-11-24 12:32:58,086 fail2ban.jail : INFO Jail 'cccam_2login' uses poller
2012-11-24 12:32:58,090 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:58,092 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:58,096 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:58,099 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:58,124 fail2ban.jail : INFO Creating new jail 'cccam_illegal'
2012-11-24 12:32:58,124 fail2ban.jail : INFO Jail 'cccam_illegal' uses poller
2012-11-24 12:32:58,128 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:58,131 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:58,135 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:58,137 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:58,164 fail2ban.jail : INFO Jail 'cccam_badcmd' started
2012-11-24 12:32:58,173 fail2ban.jail : INFO Jail 'cccam_sigfail' started
2012-11-24 12:32:58,190 fail2ban.jail : INFO Jail 'ssh' started
2012-11-24 12:32:58,209 fail2ban.jail : INFO Jail 'cccam_2login' started
2012-11-24 12:32:58,227 fail2ban.jail : INFO Jail 'cccam_illegal' started
2012-11-24 12:32:57,751 fail2ban.jail : INFO Creating new jail 'cccam_badcmd'
2012-11-24 12:32:57,752 fail2ban.jail : INFO Jail 'cccam_badcmd' uses poller
2012-11-24 12:32:57,799 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:57,802 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:57,806 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,809 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:57,834 fail2ban.jail : INFO Creating new jail 'cccam_sigfail'
2012-11-24 12:32:57,835 fail2ban.jail : INFO Jail 'cccam_sigfail' uses poller
2012-11-24 12:32:57,839 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:57,842 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:57,847 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,850 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:57,876 fail2ban.jail : INFO Creating new jail 'ssh'
2012-11-24 12:32:57,877 fail2ban.jail : INFO Jail 'ssh' uses poller
2012-11-24 12:32:57,881 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2012-11-24 12:32:57,884 fail2ban.filter : INFO Set maxRetry = 6
2012-11-24 12:32:57,889 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:57,892 fail2ban.actions: INFO Set banTime = 600
2012-11-24 12:32:58,085 fail2ban.jail : INFO Creating new jail 'cccam_2login'
2012-11-24 12:32:58,086 fail2ban.jail : INFO Jail 'cccam_2login' uses poller
2012-11-24 12:32:58,090 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:58,092 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:58,096 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:58,099 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:58,124 fail2ban.jail : INFO Creating new jail 'cccam_illegal'
2012-11-24 12:32:58,124 fail2ban.jail : INFO Jail 'cccam_illegal' uses poller
2012-11-24 12:32:58,128 fail2ban.filter : INFO Added logfile = /var/log/syslog
2012-11-24 12:32:58,131 fail2ban.filter : INFO Set maxRetry = 10
2012-11-24 12:32:58,135 fail2ban.filter : INFO Set findtime = 600
2012-11-24 12:32:58,137 fail2ban.actions: INFO Set banTime = 86400
2012-11-24 12:32:58,164 fail2ban.jail : INFO Jail 'cccam_badcmd' started
2012-11-24 12:32:58,173 fail2ban.jail : INFO Jail 'cccam_sigfail' started
2012-11-24 12:32:58,190 fail2ban.jail : INFO Jail 'ssh' started
2012-11-24 12:32:58,209 fail2ban.jail : INFO Jail 'cccam_2login' started
2012-11-24 12:32:58,227 fail2ban.jail : INFO Jail 'cccam_illegal' started
und es pasiert mehr aber nichts
Zuletzt bearbeitet: