chadrt Posted September 26, 2015 Share Posted September 26, 2015 I have a small linux server setup with FreePBX on it. I have it locked down with Fail2Ban and for some odd reason I keep getting major hack attempts. I have the settings set to a pretty restrictive set 3 bad attempts in 30 minutes and you get banned for 1 hour. This has helped knock down a ton of attempts on the system but there are a few who get way beyond the threshold I have setup. I get emails from Fail2Ban that say things like "banned after 146 attempts, banned after 138 attempts, etc" so why is it allowing that many attempts before banning the ip's. Now if I notice many blocks to the same ip over the course of a few hours I will go in and permanently add that ip to the iptables drop list. But that is not my concern, my concern is that Fail2Ban is allowing so many before dumping them into the abyss. My passwords are super strong and not anything remotely available in any dictionary in the world and are notoriously 12-18 characters long with uppers, lowers, numbers and special characters all jumbled up in a fashion that I have laid out in my head and never written down. Has anyone else gone thru this as well? Quote Link to comment https://forums.phpfreaks.com/topic/298315-fail2ban-not-acting-on-attempts-fast-enough/ Share on other sites More sharing options...
QuickOldCar Posted September 26, 2015 Share Posted September 26, 2015 Could be added up attempts until is logged your server or max attempts that session. Ban them longer than an hour would probably help as well. Quote Link to comment https://forums.phpfreaks.com/topic/298315-fail2ban-not-acting-on-attempts-fast-enough/#findComment-1521562 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.