Analyzing the attacks on my website
dev.to
dev.to
I took all of the data and fed it into a database, then built a web interface so I could see the data better.
It's looking like this:
https://i.imgur.com/8G9GAUp.png
Lots more activity from France than I would have expected compared to other countries. Also lots more people using Amazon's infrastructure to scan the internet than I would have imagined.
Other than that it's about what you'd expect.
So far I don't find this to be overly practical because with the amount of IP addresses in the filter, the firewall takes forever to reload. (firewalld)
The attempts per hour seems to cover more than 24 hours, but the dates aren't labelled. An aggregate chart bucketed by hour of day would be more interesting, since the actual rate is quite low and has a lot of variance - at this zoom level, it's basically noise.
I agree it looks pretty, though I'd take a table with some bar chart columns.
I found it wasn't really worth doing more with the chart, since its purpose was really just comparing the largest offenders.
Regarding the time frames, the buttons in the top right allow choosing the time frame. today, yesterday, 48 hours, week, month, year.
I also slapped this together in half a day.. there is plenty of room for improvement, and more charts and options could easily be added.
I didn't take this very far because this was not my goal, it was just a quick idea to allow me to block others from being able to query my server while still allowing me access from anywhere in the world. The visualizations were just for fun.
Parse your log files. If condition met, insert a line into your database.
Add extra details with a reverse DNS lookup, and IP location check.
I'm using: https://www.geoplugin.com/ at the moment, but feel like there are probably better alternatives.
I then move the data to another log file with a similar name and date so it doesn't get parsed twice, but I keep the data.
Then just make a page to pull the data out of the database.
This is probably what you are looking for:
https://developers.google.com/chart/interactive/docs/gallery
Just do a loop and feed the values into the chart data.
My guess would be the all the cheap server providers there eg. ovh, online.net/scaleway,
Maybe some cross-checking would be welcomed, because it doesn't seem really consistent. Any explaination ?
but be warned that such attribution attempts are utterly useless in the end.
The Routeviews project (https://www.routeviews.org/) provides a reverse-lookup which returns ASN and CIDR for a given IP. For example:
$ host -t txt 240.230.216.209.asn.routeviews.org
240.230.216.209.asn.routeviews.org descriptive text "21581" "209.216.230.0" "24"
That's the ASN (AS21581 -- M5HOSTING / M5 Computer Security) and CIDR block (209.216.230.0/24) for news.ycombinator.com, a/k/a 209.216.230.240.What I've frequently found is that hostile traffic is fairly highly concentrated among bad-actor space, often datacentres with little reason to be generating end-user traffic or HTTP requests. Though that includes a surprisingly large quantity of web crawlers (few of which belong to any organisations you've heard of).
https://www.cvedetails.com/vulnerability-list/vendor_id-5567...
fail2ban is worse than useless.
If you don't trust your users to have strong passwords and are forced to allow passwords, use fail2ban.
Edit: With the prominent pluralsight ads this link feels like an ad overall.
IP Country Block Count 185.81.157.109 France 81 39.100.156.143 China 77 188.163.104.67 Ukraine 32 54.176.188.51 United States 31
Whats interesting is that some are coming from other compromised WordPress sites, which are for dental offices, medical offices, etc. A lot are from tor exit nodes. Its amazing that many don't realize their servers have been compromised and used for nefarious purposes.
Obviously best thing is to also lock ssh access down to a jump host or two, but that’s not always feasible.
I don't understand what awk is accomplishing here. To get the count, just use uniq -c which you are doing (tip, you can also do a sort -rn after that)
the awk command looks like a noop to me, if you've only got the continents in the file
Nice dashboard tho, that's a good idea. I made my data into an html map that you could save.
Thanks to OpenNMS, nfsen and nfsight. Great programs.
Using default passwords and usernames like: admin, support, user, user2, student2, gitlab, git, postgres, cisco, root, ts3user, deploy, vagrant, jenkins, ftptest, 224, 130, dbadmin, sinusbot, mc, daniel, weblogic, guest, redmine, teamspeak, etc.
Checked a random box, lastb | wc -l shows 38k attempts since Feb 1.
Besides, for many use-cases, SSH is not the only service you need to access remotely.
Google, for example, proposes a different school of thought – zero trust network, and strong contextual authentication of each individual request.
Precisely because you need to expose more services to more users, you need to be extremely conscious about treating singular network ingress point as a primary security gateway.
Check out https://beyondcorp.com, it’s a very interesting concept.