store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 11:42 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 37 posts ]  Go to page Previous  1, 2, 3  Next
Author Message
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue Apr 19, 2011 4:38 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Set level 7 for rule 60903 and for rule 60910, frequency was set to 5 (timeframe left at 60). The IP addresses used were not found in the ossec active-responses.log. There were several more prolonged attempts overnight from 4 different IP addresses, non were blocked, they all attempted more than 5 times in 60 seconds.
Can supply more specific log info if required.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue Apr 19, 2011 8:15 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
yeah that would be awesome, shoot it to support@atomicorp.com (or anything else like this) and I'll see what we can come up with.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue May 31, 2011 3:44 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Hi, any update on rules to stop checkmailpasswd/LOGIN FAILED? Am manually adding IP's to blacklist, but attempts are filling up logs every other day as they are not detected.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue May 31, 2011 9:18 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yes, its implemented in the 3.0 branch now


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue May 31, 2011 9:45 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Great! Thanks for update: 3.0 still in testing repo?


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue May 31, 2011 9:55 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yeah still in the testing repo, we're wrapping up on some rule management code right now.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Tue May 31, 2011 1:24 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
3.0 is actually pretty stable if you want to give it a try. We are running it on all our system now.

Its still in testing because we are still adding/finishing up a whole new feature, the rule manager. You will be able to change all the rules from the GUI, their action, enable/disable (per vhost too), etc. etc. The rule manager will expand in the 3.x tree as well.

But all the 2.x features work now in 3.x.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 2:20 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
Hello all,

have been following this thread closely.

Sorry if this seems a stupid question but after getting a constant spate of these checkmailpasswd attempts I would like to do something about this.

Can anyone give me simple pointers on how to create a rule to ban an IP thats fails password say 3 times for a password ?

This is from the person who just discovered that if you double click on some items you can get more information ;0)

Thanks


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 3:24 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yeah its fully implemented in ASL 3.0 now. Release candidate should be out very soon


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 3:26 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
scott wrote:
Yeah its fully implemented in ASL 3.0 now. Release candidate should be out very soon


Ah good stuff, when you say release candidate - would this be suitable for putting on a production server ?


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 4:20 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yeah this is the last phase before it goes GA. A release candidate is generally something being evaluated for a final release as is.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 4:29 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
scott wrote:
Yeah this is the last phase before it goes GA. A release candidate is generally something being evaluated for a final release as is.


Sounds good - sorry not wanting to take this off topic but on the this new version will there be an option to ban anything that tries to connect as "UNKNOWN"

I get this in my block list on occasion and Im not sure if asl is handling this or not as I dont think its can add "UNKNOWN" to the block list.

Sorry apologies if I am veering away from the beaten track ;0)


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 6:02 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yes it should, but if it doesnt there is now a "Report False Negative" button that sends us exactly what we need to craft a rule update. What I do is search for all the 1002 event ids (this is a generic rule that catches things like failure, or unknown; and report those. This is just like the report false positive system we use for the WAF, but expanded to let you report the anomalies to us for rule updates.


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Fri Jun 24, 2011 6:06 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
scott wrote:
Yes it should, but if it doesnt there is now a "Report False Negative" button that sends us exactly what we need to craft a rule update. What I do is search for all the 1002 event ids (this is a generic rule that catches things like failure, or unknown; and report those. This is just like the report false positive system we use for the WAF, but expanded to let you report the anomalies to us for rule updates.


Right thats sounds very useful indeed - I presume someone / thing connecting as UNKNOWN should be blocked off ?

This new release is sounding good - anything I can just install and set is fine by me - takes alot of the hassle away by an infinite amount!!

Cheers Scott looking forward to the new release!!


Top
 Profile  
 
 Post subject: Re: block many checkmailpasswd attempts?
Unread postPosted: Sat Jun 25, 2011 10:42 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yup, and if it doesnt hit that Report False Negative button and we'll have an update out probably the same day.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 37 posts ]  Go to page Previous  1, 2, 3  Next

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group