Web Hosting Forum | Lunarpages
News: April 3, 2008 - New Contest! - Win 5 Years of Hosting and $1,000!
May 5, 2008 - May 08 Web Site of the Month? - Submit your LINKS!!!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 16, 2008, 12:10:38 PM


Login with username, password and session length


Pages: 1 [2]   Go Down
  Print  
Author Topic: brute force attack and plesk  (Read 2599 times)
jetx
Intergalactic Cowboy
*****
Offline Offline

Posts: 59


« Reply #15 on: April 15, 2008, 09:52:07 PM »

What you're saying could be one of the current issues in fact. With denyhosts installed and apparently working everytime I SSH the server after a while disconnects, then the VPS goes down. This has happened several times today. The support tech has advised: There was issue with iptables firewall and denyhosts. Now we have corrected the issue with these. However, I still cannot SSH. As denyhosts uses tcpwrappers, or has been set up that way by support, this then must be conflicting with iptables.

Logged
jetx
Intergalactic Cowboy
*****
Offline Offline

Posts: 59


« Reply #16 on: April 15, 2008, 10:54:05 PM »

Note: in addition to this. As I was relying on plesk firewall and I suppose iptables, I had set the firewall to limit SSH to two specific ip addresses.

What confuses me here is why the messages log the next day showed hundreds of attempted log in attempts? Surely this indicates something was not working?? This was the only reason I bothered with denyhosts.
« Last Edit: April 15, 2008, 10:55:53 PM by jetx » Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 896



« Reply #17 on: April 16, 2008, 08:37:56 PM »

Hi Jetx,

If you setup restrictions for SSH in firewall (which is indeed IPTables in Linux) but they don't work, more than likely there is another permissive rule in firewall that intersected with the restriction or firewall is not running at all.
Logged

Kind Regards,
Vlad Artamonov
jetx
Intergalactic Cowboy
*****
Offline Offline

Posts: 59


« Reply #18 on: April 16, 2008, 10:45:52 PM »

The thing is I had the firewall on full blast and it wasn't working. If you saw my thread last week regarding the cock-up with my ip addresses, where the delegated addresses in fact belonged to other people. What happened there is that all my sites were down as I don't use lunar DNS services at all. I wake up check the sites, nothing.

So after they allocated me new ip addresses (4 new, one was ok), I looked at the logs to see that hackers were blasting away at me on SSH, ftp, SMTP, etc. Everything was open, only thing saving me SSH was the password.

The first thing I did when I was allocated this VPS was enable tight controls in firewall- SSH was off completely (after it wasn't stopping attacks when set to allow only my own ips). I had SMTP and POP off, FTP, etc.

This was the whole reason for denyhosts, I was being attacked.

Now why didn't support@lunar take a look at the ip tables to begin with. Finally yesterday the support admin advised the ip tables had been flushed and there was a problem with them.

All I know is I paid support $75 (assistance with deny hosts) for nothing. Support did not admit it was their mistake.

I'm quite pissed off about this, really I've spent over 60 hours of my time and about a dozen tickets on this problem! Everytime they said it was fixed my logs showed hack city (message log was over 1m in about 2 days).

Who should I contact to look into this? I retained the logs.

Now deny hosts has no work to do as the firewall is working.. as it bloody should.
Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 896



« Reply #19 on: April 17, 2008, 04:11:06 AM »

Hello,

Please PM me with the ticket numbers concerning this issue and I'll check them.
Logged

Kind Regards,
Vlad Artamonov
jetx
Intergalactic Cowboy
*****
Offline Offline

Posts: 59


« Reply #20 on: April 17, 2008, 10:43:27 PM »

perestrelka. I really appreciate the help you've given here but I can't seem to get past one line responses from support. This one just in: I had talk to our VPS expert and there should be no issue with denyhosts and iptables firewall. We cant keep monitoring your account at our server monitoring area if you sets such rules in firewall. Because our monitoring servers always watch your server services.

Even though they set up denyhosts for me.

So, I'm moving to another hosting company. I've emailed billing, I trust they'll honor the 30 day money back guarantee. Pity, I've used you guys for 8 years.

Screwed up IP tables created by this same person which required the installation of an application (denyhosts) which has made things worse. And I was happy to pay this guy to sort it out, which he hasn't. The logs I just sent you clearly show problems continue.

Anyway, enough. Thanks for your feedback.

Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 896



« Reply #21 on: April 18, 2008, 03:26:48 AM »

Hi Jetx,

I am really sorry to hear about that. I can understand your frustration after reviewing your tickets and I'll be happy to get the setup sorted out for you if you decide to change your mind.
Logged

Kind Regards,
Vlad Artamonov
jetx
Intergalactic Cowboy
*****
Offline Offline

Posts: 59


« Reply #22 on: April 19, 2008, 12:55:08 AM »

No thanks anyway. I've fully moved. I'll will details to billing however, they can do with it what they like.
Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 896



« Reply #23 on: April 19, 2008, 03:08:28 AM »


I wish you good luck! Wink
Logged

Kind Regards,
Vlad Artamonov
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.3 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM