I used iptables to restrict hackers. It worked well. You can try it.
Generally, SSH is used for management on Linux servers. However, some boring and rogue hackers in the world can use the dictionary to crack your password, looking at the ever-increasing strange usernames in the log, I can't help but admire these tireless cainiao.
Now, I don't want to play with Xiaocai. Today I will introduce how to use the recent module of iptables to prevent brute force password cracking.
The default port of the SSH service is 22, but since it is managed by yourself, you can change the port number. For example, in this example, change the SSH port to 44322, generally, cainiao hackers who use tools only scan ports lower than 1000. However, a computer has 65536 ports and you can change your port to the lowest possible port, this greatly increases the costs of attackers.
The following code directly modifies the/etc/sysconfig/iptables file. Of course, you can also use a script. You only need to add iptables before each sentence.
View sourceprint? 01 # SSH Login log Note: first, record who wants to log on to my SSH service, you can use tail/var/log/iptables-n 100 | grep "SSH Login" to check who is logged on recently. iptables is the log file name. You need to set the log name in syslog.
02-A INPUT-p tcp -- dport 44322 -- tcp-flags all syn-m state -- state NEW-j LOG -- log-prefix "[SSH Login]:" -- log-level debug
03 #1 Hour allow 5 SSH Login Note: only five connections to my SSH service are allowed every 3600 seconds (every Hour). You can change the time and number of connections by yourself, here you can use-j DROP to replace-j REJECT.-j REJECT -- reject-with tcp-reset is a packet explicitly returned to the client to reset the TCP connection, tell the other party that I have closed the connection. If you feel that you do not need to be so kind to the attacker, use-j DROP to directly discard the package and let the other party Wait for the package to return.
04-A INPUT-p tcp -- dport 44322 -- tcp-flags all syn-m state -- state NEW-m recent -- name SSH-SYN -- update -- seconds 3600 -- hitcount 5 -- rttl-j REJECT -- reject-with tcp-reset
05-A INPUT-p tcp -- dport 44322 -- tcp-flags all syn-m state -- state NEW-m recent -- name SSH-SYN -- set-j ACCEPT
06 # SSH Service back data filter Note: filter packets received after a TCP connection is established
07-A INPUT-p tcp -- dport 44322 -- tcp-flags all ack-m state -- state ESTABLISHED-j ACCEPT
08-A INPUT-p tcp -- dport 44322 -- tcp-flags all ack, PSH-m state -- state ESTABLISHED-j ACCEPT
09-A INPUT-p tcp -- dport 44322 -- tcp-flags all ack, FIN-m state -- state ESTABLISHED-j ACCEPT
10-A INPUT-p tcp -- dport 44322 -- tcp-flags all rst-m state -- state ESTABLISHED-j ACCEPT
11-A INPUT-p tcp -- dport 44322 -- tcp-flags all ack, RST-m state -- state ESTABLISHED-j ACCEPT
12-A INPUT-p tcp -- dport 44322 -- tcp-flags all ack, URG-m state -- state ESTABLISHED-j ACCEPT
The connection tracking function of iptables is used here, that is,-m state -- state, because the first packet of a TCP connection can only be a SYN packet, therefore, lines 2nd, 4, and 5 only allow access to SYN packets, which prevents other types of packets from being confused. Lines 4th and 5 can also prevent SYN FLood attacks without forging the source IP address. Lines 7 to 12 indicate to filter the type of the packet after the TCP connection has been established. Note: tcp-flags ALL is followed by a normal package, for example, the SYN/FIN package, FIN/RST package, SYN/FIN/PSH package, SYN/FIN/RST package, and SYN/FIN/RST/PSH package cannot appear at all, once such a package appears, it means you are under attack.
Note that if the server administrator successfully logs on five times within one hour, he cannot log on. Because iptables calculates the number of SSH connections established per hour, whether you guess the password or log on normally. Therefore, it is best for the Administrator to make a configuration plan.
This code has been tested by iptables 1.3.5 and ipt_recent 0.3.1.
After reading this article, we learned how to use the iptables recent module to prevent brute force password cracking. It works very well. Please share it with your friends!
This article is from "Jerry"