Finally iptables works the same on every Linux distro
nico.schottelius.org
nico.schottelius.org
To solve such problems elegantly I designed my "NCD programming language" (link: https://code.google.com/p/badvpn/wiki/NCD ). The language has built-in backtracking, so in the case of iptables, the language itself makes sure any iptables rule that was added is also removed when that is necessary, in a manner not unlike exception handling in C++ etc. Link to iptables module: https://code.google.com/p/badvpn/source/browse/trunk/ncd/mod...
Oh, and it also runs in the browser ;) http://badvpn.googlecode.com/svn/wiki/emncd.html
And yes, real men use iptables directly. I never understood the need for wrappers, just makes it harder to debug and see whats really going on.
Since iptables comes from upstream (and is closely linked to the kernel), distros running the same version of the kernel already have the same iptables quirks. (There aren't many.) The article discusses distributing an iptables config file and having it run on startup, a task which can be equally well handled by the other config management systems.
The amount of toxic traffic hitting that port is scary.
Even if fail2ban and others were perfect, all it would take is the sysadmin customizing the log format to include some random field and all the sudden it's possible for an attacker to block every IP address with one request.
Source: http://seclists.org/fulldisclosure/2007/Jun/138
A better alternative is something like pam_abl which only protects logins to a user on the system but with it ssh is essentially unbruteforceable.
I believe this is the problem with using pam_tally2. Then again, if you're only allowing PubkeyAuthentication then maybe you don't care about brute force login attempts so much.
Yes, moving ports helps, but it's not a real defense. It just lowers bandwidth costs and prevents some not-so-harmful attacks (from people who don't know whether what they've compromised has any value.)
At the very least, use public-key authentication instead of password authentication for SSH.
So in the majority of cases, traffic will get through? :P
I get a kick out of viewing all the failed attempts in /var/log/auth
Added bonus is adding all those bad guy addresses to my blacklists.
https://github.com/bulletproofnetworks/ript
So long as you can write Ruby, this works in Chef, Puppet, or whatever.