Community Forums
Connect with us on LinkedIn
  
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Oct 2005
    Posts
    9

    Post block IP

    if i see in /var/log/secure for example that some ips are trying to log in in my ssh how can i block these IP?

    thankz

  2. #2
    Member
    Join Date
    Jul 2005
    Location
    Sticky On Internet
    Posts
    555

    Default

    best is change the ssh port to a higher value.

    see ya,
    mohit
    Learn atleast A word Daily

    7+1 Dedicated Boxes with cPanel...

  3. #3
    Member
    Join Date
    Oct 2005
    Posts
    9

    Default

    i did that...

    but back into my question


    if i see in /var/log/secure for example that some ips are trying to log in in my ssh how can i block these IP?

  4. #4
    Member
    Join Date
    Jul 2005
    Location
    Sticky On Internet
    Posts
    555

    Default

    try another port, check if the IP is of a person who know's about your new port.

    see ya,
    mohit
    Learn atleast A word Daily

    7+1 Dedicated Boxes with cPanel...

  5. #5
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by danielldf
    i did that...

    but back into my question
    I would install apf firewall. Apf uses iptables to block ips. You can then just edit the conf file and block whatever ip's you wish. You can use iptables directly without apf, something like iptables -I INPUT -p tcp -s 00.00.00.00 -j DROP where the 00.00.00.00 is the ip address. You can google iptables blocking ip's and get tons of examples.

    You might also look at bfd (Instructions here http://www.webhostgear.com/index.php?art/id:60 ) to auto block Brute force attempts to login.
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  6. #6
    Member
    Join Date
    May 2005
    Posts
    99

    Default

    yeap .. install APF to add ip to the firewall system.
    using apf -d ip you will add the ip to the deny list.

    if you have freebsd .. you can block the guy with more options. like block the mac adreess of the guy.

    but if you use linux.. apf is a good solution.


    i recommend you install BFD .. Brute Force Detect ... is a nice tool .. use APF to block ssh fails access..
    an excample:--- one guy try to access your SSh server.. and try 3 times.. when the guy try to login the 4 time.. the BFD block the ip guy to access to your box.

  7. #7
    Member sitekeeper's Avatar
    Join Date
    Aug 2001
    Location
    Troy, Mo
    Posts
    60

    Default Firewall

    I have been using cPanel's Moderator "chirpy" firewall since it's first beta and like it far better then APF + BFD. It is quicker too lock out these things then APF + BFD. It also has a nice and easy to use WHM interface to setup and view logs.

    Download: http://www.configserver.com/cp/csf.html

    Some more info: http://forums.cpanel.net/showthread....erver+firewall

  8. #8
    Member
    Join Date
    May 2003
    Posts
    208

    Default

    Quote Originally Posted by sitekeeper
    I have been using cPanel's Moderator "chirpy" firewall since it's first beta and like it far better then APF + BFD. It is quicker too lock out these things then APF + BFD. It also has a nice and easy to use WHM interface to setup and view logs.

    Download: http://www.configserver.com/cp/csf.html

    Some more info: http://forums.cpanel.net/showthread....erver+firewall
    I already use just the BFD (not APF), and would like to try chirpy's firewall.

    What is the best way to 'uninstall' BFD before installing this ?

    Thanks in advance,
    Daniel

  9. #9
    Member sitekeeper's Avatar
    Join Date
    Aug 2001
    Location
    Troy, Mo
    Posts
    60

    Default

    This script comes with a tool to remove it, just read the docs....

  10. #10
    Member
    Join Date
    May 2003
    Posts
    208

    Default

    So, to uninstall BFD, all I would need to do is:

    sh disable_apf_bfd.sh

    before installing Chirpy's version ?

    Thanks in advance,
    Daniel

  11. #11
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Yes, just follow the instructions in the install.txt of csf. You'll also see two options in the WHM > ConfigServer Firewall > page after installation where you can completely remove APF and BFD if you wish.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  12. #12
    Member
    Join Date
    May 2003
    Posts
    208

    Default

    Thanks Chirpy

    Daniel

Similar Threads & Tags
Similar threads

  1. How to block an IP
    By varshann2006 in forum New User Questions
    Replies: 3
    Last Post: 02-26-2009, 08:58 AM
  2. Block IP
    By shimmy in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 05-13-2005, 09:18 AM
  3. a way to block a certain IP
    By netvistun in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-11-2005, 07:57 AM
  4. Block IP
    By allenhui in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 03-11-2004, 09:27 AM
  5. IP Block
    By c4host in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-26-2003, 08:58 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube