{"id":26,"date":"2009-05-27T13:23:47","date_gmt":"2009-05-27T01:23:47","guid":{"rendered":"http:\/\/eion.robbmob.com\/blog\/?p=26"},"modified":"2009-05-27T13:23:47","modified_gmt":"2009-05-27T01:23:47","slug":"ssh-security-with-fail2ban-on-gentoo","status":"publish","type":"post","link":"https:\/\/eion.robbmob.com\/blog\/2009\/05\/27\/ssh-security-with-fail2ban-on-gentoo\/","title":{"rendered":"SSH Security with Fail2Ban on Gentoo"},"content":{"rendered":"<p>I accidentally looked at my syslog messages on my home (Gentoo) Linux server and found that there were thousands of SSH connection attempts from all over the world: people trying to brute-force my root password.  The worst bit was that it was filling up my logs and causing lots of things to die when the computer ran out of disk-space.  It needed a bit of playing around to get this to stop, but in case you run across the same situation, I&#8217;ve documented what I did:<\/p>\n<ul>\n<li> Make sure you have the tcpd USE-flag on net-misc\/openssh.  If you don&#8217;t, the easiest way to add it is with the command <code>echo \"net-misc\/openssh tcpd\" >> \/etc\/portage\/package.use<\/code>\n<\/li>\n<li>Emerge fail2ban\n<\/li>\n<li>If you&#8217;re using syslog-ng, you need to configure it to log sshd logs to a different place (reduces load on the server) by adding the following lines to \/etc\/syslog-ng\/syslog-ng.conf<br \/>\n<code>filter f_sshd {match('^sshd\\[[0-9]+\\]:'); };<br \/>\ndestination sshd { file(\"\/var\/log\/sshd.log\"); };<br \/>\nlog { source(src); filter(f_sshd); destination(sshd); flags(final); }<\/code>\n<\/li>\n<li>Enable the ssh-tcpwrapper setting in \/etc\/fail2ban\/jail.conf, checking that the logpath is pointing to your log file.  It should end up looking something like<br \/>\n<code><br \/>\n[ssh-tcpwrapper]<br \/>\nenabled = true<br \/>\nfilter = sshd<br \/>\naction = hostsdeny<br \/>\nlogpath = \/var\/log\/sshd.log<br \/>\n<\/code>\n<\/li>\n<li>Set up the hosts allow\/deny files (if you don&#8217;t have them) by pumping out the following commands to bash<br \/>\n<code><br \/>\ntouch \/etc\/hosts.allow<br \/>\ntouch \/etc\/hosts.deny<br \/>\nchmod 644 \/etc\/hosts.allow<br \/>\nchmod 644 \/etc\/hosts.deny<br \/>\n<\/code>\n<\/li>\n<li>Reload syslog-ng <code>\/etc\/init.d\/syslog-ng reload<\/code>, restart openssh <code>\/etc\/init.d\/sshd restart<\/code>, and start fail2ban <code>\/etc\/init.d\/fail2ban start && rc-update add fail2ban default<\/code>\n<\/li>\n<\/ul>\n<p>That should do it.  I also recommend disabling the root account and disabling password authentication in your \/etc\/ssh\/sshd_config file.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I accidentally looked at my syslog messages on my home (Gentoo) Linux server and found that there were thousands of SSH connection attempts from all over the world: people trying to brute-force my root password. The worst bit was that it was filling up my logs and causing lots of things to die when the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[1],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p3CEsE-q","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/posts\/26"}],"collection":[{"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/comments?post=26"}],"version-history":[{"count":0,"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/posts\/26\/revisions"}],"wp:attachment":[{"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/media?parent=26"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/categories?post=26"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eion.robbmob.com\/blog\/wp-json\/wp\/v2\/tags?post=26"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}