You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to securit...@googlegroups.com
I haven't installed any other packages outside of what is shipped with SO and after one failed SSH login attempt, the host is added to hosts.deny and iptables -L -n shows the IP address and indicates that all traffic is to be dropped for that host.
I'm aware of fail2ban and DenyHosts but neither are installed. I'm not real sure what is causing this and it occurs even if I disable ufw altogether so I don't believe it is ufw/iptables.
When ufw is not active, nothing shows up when iptables -L -n is ran until a failed login and then it only shows that host for a period of time. Is there a script that I'm not aware of that would be monitoring /var/log/secure for failed attempts?
Doug Burks
unread,
Dec 10, 2014, 4:56:14 PM12/10/14
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
--
Doug Burks
Need Security Onion Training or Commercial Support?
http://securityonionsolutions.com Last day to register for 3-Day Training Class in Augusta GA is 12/11!
Ric Woodard
unread,
Dec 10, 2014, 5:05:19 PM12/10/14
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to securit...@googlegroups.com
Thanks, that was it. You can see the shell scripts that it launches from /var/ossec/active-response/bin/ in the .conf file. I'll have to adjust it so it doesn't lock out after one attempt.