store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 7:15 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 25 posts ]  Go to page Previous  1, 2
Author Message
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 05, 2009 7:24 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
LOL! I love it!

One thing about attracting more attacks is that you get more data about the sources, methods and sometimes even the real source of the attacks (proxy leaks, browser leaks, etc.) which you can use to protect your systems. Always a plus.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 05, 2009 7:56 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Does modsec has a rule to use this jpg everytime a 406 is triggered?

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 05, 2009 8:51 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
One way you can do this is by setting apache up to use a custom error page for that type of error (in your case 406), and formatting that page to your liking.

Another is with redirect, basically send the attacker to a specific page, just change the action from drop to redirect:http://www.whatver.com/block.html.

You can also use the proxy action, which requires you to setup the proxy backend in apache to support (and really not necessary unless you are setting up a full blown honeypot) - same thing, change the drop action to proxy:http://www.someothersystem.com/.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Fri Sep 11, 2009 10:41 am 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Finally I got the sign to work and is doing a good job, lol. Now I show the sign to any one that has triggered a 403 or 406 error.

I have a really nice block of SPAMMER IPs, in case you want it. I will like to share this list with anyone that is interested in blocking them, the list now is more than 1K IPs and growing, lol.


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Fri Sep 11, 2009 6:06 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Yes. please send on any data you have. We're cooking the honeypot data we have collected over the past few years into the RBL, so if you have anything you want to contrbiute please email it to us. (put a password on it so our collective AV/AS systems dont block it)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 12, 2009 1:39 am 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
I will be sending you a list of all the spammers that the guestbook collected.

On the other hand, I saw that the new rules on the 50, included the rules for the malware-scripts.txt, but unfortunately they are not working neither of them.

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 12, 2009 2:31 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
The malware_scripts rule isnt active yet in the ASL rules, its commented out as we do more testing.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Sat Sep 12, 2009 4:23 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
mikeshinn wrote:
The malware_scripts rule isnt active yet in the ASL rules, its commented out as we do more testing.

Sorry, I am anxious on having that rule working, lol.

I will wait until you say it is in production.

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Thu Sep 24, 2009 9:13 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Any idea when the rule to block script names will be available?

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: Rule for blocking name of scripts?
Unread postPosted: Wed Jun 06, 2012 11:38 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
I forgot to mention, it was added to the realtime rules a few months ago.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 25 posts ]  Go to page Previous  1, 2

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group