Feel free to file issues on github and consider that the "source of truth" for my code, and please ignore my site. I don't have time to throw together a web presence, too busy at work ;-)
Feel free to file issues on github and consider that the "source of truth" for my code, and please ignore my site. I don't have time to throw together a web presence, too busy at work ;-)
Welp, 221.192.143.73/24 is going in the firewall config.
I've never heard of dropboxd doing anything like that. My inclination would be to nuke the box.
Basic:
1. SSH - security related - modify sshd config - no password auth, only key based, no root login, other than that the default sshd config for Ubuntu 12.04 is pretty ok.
PermitRootLogin no
If you do not use IPv6, you can disable sshd to use it.
#ListenAddress ::
ListenAddress 0.0.0.0
2. SSH - ease of maintenance related - change default port from 22 to smth else. This will not help against targeted attacks, but this will reduce the noise in the logs and will allow better visibility of attack attempts.
#Port 22
Port 63777 (or whatever)
Don't forget to reload ssh for changes to take effect and check with netstat what's running where.
If you are concerned with getting locked out you can do this:
2.1. enable sshd to listen on multiple ports simultaneously
Port 22
Port 63777 (or whatever)
2.2. Login through Port 63777, and only then disable Port 22.
3. The PRC thing - fail2ban and hosts is simple but not the best tools for the job.
3.1. You can disable access to your site for all China (or any other country for this matter) using ipset. Much better speed and ease of maintenance, it's even better then using iptables itself [ipset is iptables module], one set can contain/block up to 65000+ IPs.
3.2. If you want smth more targeted, then consider either sshguard or psad. They can be configured to block inline and dynamically add rules [perm/temp] to iptables.
Edit: forgot to mention another cute recipe. see below
If you are on AWS and are using security groups (you should), after you are done on the server, you can go to the security group in AWS Mgt Console and remove ingress for ssh ports. Now your server is accessible only on 80/443 and ssh is NOT accessible to anyone. Later, when you need to access the server - enable ingress for the ssh ports, do your job and disable again.
I don't really think that security-by-obscurity alone is a good enough solution. I already disable both root logins and passwords on my shell, and have something that tails logs to firewall IPs that are doing nasty things that show up in my logs. It's cute that you assume I'm running Linux though ;-)
I ended up firewalling the entire /14 that /24 was assigned from, because, well, China bothers me...