Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

forgot password?


Reply


Old
  Post #16 (permalink)   12-29-2008, 01:10 PM
HD Newbie
 
Join Date: Dec 2008
Posts: 26

Status: webspacedepotcm is offline
I am pretty sure you can have BFD block failed POP3 logins as well. It can be configured to block failed logins from nearly every service that logs it.

But unless they are logging in from a different IP every time, BFD should pretty much stop brute forcing in its tracks.
__________________
WebSpaceDepot.com
"Hosting Unleashed"
 
 
 


Old
  Post #17 (permalink)   12-29-2008, 07:06 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,003

Status: handsonhosting is offline
dump APF and BFD - these are outdated scripts.

Download CSF from www.configserver.com. You can ratelimit the number of connections allowed etc. We stand by this script on hundreds of our servers.

We set our limits at 5 seccessive login failures, and it then temporarily blocks the IP number for 15 minutes (long enough for most Bruteforce attempts to move to a new server). If they get temporary blocked 4 times in a row, it permanently blocks the IP from further accesses to the server in question.
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #18 (permalink)   01-01-2009, 11:18 PM
HD Amateur
 
Join Date: Oct 2008
Posts: 66

Status: hzSari is offline
CSF is a strong recommendation for server firewall, actually the APF, BFD and CSF all installed together would be the best choice.
__________________
hzSari | HostingZoom.com
ModVPS.com | ResellerZoom.com
Power Speed Reliability
 
 
 


Old
  Post #19 (permalink)   01-01-2009, 11:27 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,003

Status: handsonhosting is offline
You CAN NOT run APF and BFD in conjunction with CSF. When you install CSF it will prompt you to uninstall APF & BFD. If you do not, you can end up with a highly crippled machine (if it will even function).

Have you ever tried to run all 3 together? It doesn't work
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #20 (permalink)   01-20-2009, 07:08 AM
HD Newbie
 
Join Date: Jan 2009
Posts: 46

Status: TopQHost is offline
This kind of brute force attempt is pretty normal to expect. The best method is to change the ssh port entirely and install CSF. If you install csf however, be sure to go through each and every setting. Leaving it as-is will probably lead to locking yourself out of the server. If you really want to go secure, allow ssh access only from certain ips or using ssh keys only.

When it comes to other services such as email, hackers will use random emails and passwords also. Again, this is expected from a site that becomes popular on the internet. CSF does a good job of monitoring the logs under /var/log for any invalid attempts and blocking as necessary.
__________________
TopQHost - We Provide Affordable Web Hosting with Top Quality Service
 
 
 


Old
  Post #21 (permalink)   01-21-2009, 03:38 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
Quote:
Originally Posted by TopQHost View Post
This kind of brute force attempt is pretty normal to expect. The best method is to change the ssh port entirely and install CSF. If you install csf however, be sure to go through each and every setting. Leaving it as-is will probably lead to locking yourself out of the server. If you really want to go secure, allow ssh access only from certain ips or using ssh keys only.

When it comes to other services such as email, hackers will use random emails and passwords also. Again, this is expected from a site that becomes popular on the internet. CSF does a good job of monitoring the logs under /var/log for any invalid attempts and blocking as necessary.
After these attacks I chose SSH Keys. I couldn't believe how easy it was to set them up and get cpanel to verify the user.

Spot on!
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #22 (permalink)   01-27-2009, 11:28 AM
HD Addict
 
Join Date: Dec 2008
Location: Florida,Tampa
Posts: 101
Send a message via MSN to HivelocityLB

Status: HivelocityLB is offline
I Highly recommend installing APF and BFD.
This should help in preventing such attacks in the future.
__________________
Dedicated Servers - sales@hivelocity.net - 1-888-869-HOST(4678)
Viva Hivelocity "THE SERVER STUD" - Award Winning Hosting
Managed Dedicated Servers. Reseller Discounts. 24/7 Impressive Tech Support.
 
 
 
Reply
Previous Thread Next Thread


Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: