|
jetx
|
 |
« Reply #15 on: April 15, 2008, 09:52:07 PM » |
|
What you're saying could be one of the current issues in fact. With denyhosts installed and apparently working everytime I SSH the server after a while disconnects, then the VPS goes down. This has happened several times today. The support tech has advised: There was issue with iptables firewall and denyhosts. Now we have corrected the issue with these. However, I still cannot SSH. As denyhosts uses tcpwrappers, or has been set up that way by support, this then must be conflicting with iptables.
|
|
|
|
|
Logged
|
|
|
|
|
jetx
|
 |
« Reply #16 on: April 15, 2008, 10:54:05 PM » |
|
Note: in addition to this. As I was relying on plesk firewall and I suppose iptables, I had set the firewall to limit SSH to two specific ip addresses.
What confuses me here is why the messages log the next day showed hundreds of attempted log in attempts? Surely this indicates something was not working?? This was the only reason I bothered with denyhosts.
|
|
|
|
« Last Edit: April 15, 2008, 10:55:53 PM by jetx »
|
Logged
|
|
|
|
|
perestrelka
|
 |
« Reply #17 on: April 16, 2008, 08:37:56 PM » |
|
Hi Jetx,
If you setup restrictions for SSH in firewall (which is indeed IPTables in Linux) but they don't work, more than likely there is another permissive rule in firewall that intersected with the restriction or firewall is not running at all.
|
|
|
|
|
Logged
|
Kind Regards, Vlad Artamonov
|
|
|
|
jetx
|
 |
« Reply #18 on: April 16, 2008, 10:45:52 PM » |
|
The thing is I had the firewall on full blast and it wasn't working. If you saw my thread last week regarding the cock-up with my ip addresses, where the delegated addresses in fact belonged to other people. What happened there is that all my sites were down as I don't use lunar DNS services at all. I wake up check the sites, nothing.
So after they allocated me new ip addresses (4 new, one was ok), I looked at the logs to see that hackers were blasting away at me on SSH, ftp, SMTP, etc. Everything was open, only thing saving me SSH was the password.
The first thing I did when I was allocated this VPS was enable tight controls in firewall- SSH was off completely (after it wasn't stopping attacks when set to allow only my own ips). I had SMTP and POP off, FTP, etc.
This was the whole reason for denyhosts, I was being attacked.
Now why didn't support@lunar take a look at the ip tables to begin with. Finally yesterday the support admin advised the ip tables had been flushed and there was a problem with them.
All I know is I paid support $75 (assistance with deny hosts) for nothing. Support did not admit it was their mistake.
I'm quite pissed off about this, really I've spent over 60 hours of my time and about a dozen tickets on this problem! Everytime they said it was fixed my logs showed hack city (message log was over 1m in about 2 days).
Who should I contact to look into this? I retained the logs.
Now deny hosts has no work to do as the firewall is working.. as it bloody should.
|
|
|
|
|
Logged
|
|
|
|
|
perestrelka
|
 |
« Reply #19 on: April 17, 2008, 04:11:06 AM » |
|
Hello,
Please PM me with the ticket numbers concerning this issue and I'll check them.
|
|
|
|
|
Logged
|
Kind Regards, Vlad Artamonov
|
|
|
|
jetx
|
 |
« Reply #20 on: April 17, 2008, 10:43:27 PM » |
|
perestrelka. I really appreciate the help you've given here but I can't seem to get past one line responses from support. This one just in: I had talk to our VPS expert and there should be no issue with denyhosts and iptables firewall. We cant keep monitoring your account at our server monitoring area if you sets such rules in firewall. Because our monitoring servers always watch your server services.
Even though they set up denyhosts for me.
So, I'm moving to another hosting company. I've emailed billing, I trust they'll honor the 30 day money back guarantee. Pity, I've used you guys for 8 years.
Screwed up IP tables created by this same person which required the installation of an application (denyhosts) which has made things worse. And I was happy to pay this guy to sort it out, which he hasn't. The logs I just sent you clearly show problems continue.
Anyway, enough. Thanks for your feedback.
|
|
|
|
|
Logged
|
|
|
|
|
perestrelka
|
 |
« Reply #21 on: April 18, 2008, 03:26:48 AM » |
|
Hi Jetx,
I am really sorry to hear about that. I can understand your frustration after reviewing your tickets and I'll be happy to get the setup sorted out for you if you decide to change your mind.
|
|
|
|
|
Logged
|
Kind Regards, Vlad Artamonov
|
|
|
|
jetx
|
 |
« Reply #22 on: April 19, 2008, 12:55:08 AM » |
|
No thanks anyway. I've fully moved. I'll will details to billing however, they can do with it what they like.
|
|
|
|
|
Logged
|
|
|
|
|
perestrelka
|
 |
« Reply #23 on: April 19, 2008, 03:08:28 AM » |
|
I wish you good luck! 
|
|
|
|
|
Logged
|
Kind Regards, Vlad Artamonov
|
|
|
|