A recent abrupt change in Internet SSH brute force attacks against us
utcc.utoronto.ca
utcc.utoronto.ca
https://therecord.media/china-run-botnet-takedown-fbi-doj-ro...
Activity we previously attributed to the Russians didn't flicker when Russia invaded Ukraine-- but did stop very quickly into Israel's invasion of Gaza.
https://www.bsdly.net/~peter/Predicting_developments_in_real...
If there’s one thing I learned from working in this space, it’s how there’s just massive amounts of “history” playing out every day that will never be written down or acknowledged. In particular, cyber/electronic warfare is a very active space, and quite a few nation states regularly commit what many of us would imagine would be considered acts of war against each other, without a word said to the public.
We have a "special" relationship with Israel so I can't go too much into detail, but suffice to say it was password spraying attacks that originated from domestic residential IPs that dropped off. Normally foreign agencies use datacenters and a known set of VPN ASNs. Israel happens to have their own onion routing network in the form of Hola/Luminati, but that isn't a discrete ASN-- it's a botnet of residential proxies.
https://news.ycombinator.com/item?id=18161706
I don't know if Luminati is even still a thing but this is the sort of footprint I'd expect from it. They'd find residential proxies useful for their astroturfing campaigns so I assume it's still up. Attribution is a game of educated guesses.
Now, I'm not implying the Israeli government is the actor here. For all I know it's some bored teenager fucking with us. The timing is what's suspect. Either the operator was compelled to stop when war broke out or the infrastructure they were using was somehow impacted by the Gaza offensive.
What's your conclusion here, though? Who do you believe now was the actual bad actor and why did they stop? You're just leaving it open.
It looks like it's related to Israel's offensive, but even that is subject to interpretation. It remains an open question to me too. The most I'd feel comfortable speculating on is that the attacks were possibly leveraging Israeli infrastructure (Luminati?), which says little about the actors involved.
There's a secondary insider event that occurred coincidental to the beginning of the attacks against us that makes me particularly suspicious of our "friends" but I absolutely cannot discuss that here.
But I'm still amused with their wasted efforts by not checking error messages; my servers only accept keys
As of this month, I only received 17 attempts. All from the same IP range.
Can't say I can complain about this.
Really think port knocking could help thwart this entire category of attacks too.
Parsing log files not intended to be read by automation (eg. questionable or nonexistent escaping) to then take actions as root is with great remote injection vector is not a good idea.
Using fail2ban with SSH is very widely done and is thoroughly recommended. It increases security and is objectively a good idea.
They are schoolboy errors in a relatively trivial piece of software that very well demonstrate the fundamental security flaw in its design.
> is thoroughly recommended
Recommended by whom? The Internet, or prominent experts in the field?
I read through the CVEs and they're not 'schoolboy errors' at all - in fact, the first one doesn't even refer to fail2ban itself but to a program being called by fail2ban.
There's no fundamental security flaw in its design.
> Recommended by whom? The Internet, or prominent experts in the field?
It's recommended in several linux/unix books - physical books, written by experts - and in many blogs. So, both.
The knocker says "password123" and you say "Wrong, go away." But one second later they come back and knock and you have to get up and go to the door again. And again. And again.
The bad guys never get in because they only try stupid passwords, but the constant getting up and going to the door gets pretty tiresome.
So you get a dog, you put it outside your door and you train it to keep away for one minute any stranger who knocks but fails to get in.
Now you have a lot more peace because you're not getting out of your chair every second to ask the pass phrase from some rando.
Fail2ban is the dog.