PDA

View Full Version : Ban an IP after *** login attempts



blaszlo
08-01-2008, 09:56 AM
Hey guys,

I keep getting people trying to brute-force their way into one of my servers via proftpd... Now, I'm not too concerned about them gaining access, but it's becoming a huge thorn in my side and it bothers me because they are allowed about 25,000 attempts before their IP is banned. How do I make it so their IP is banned after... say... 50 failed attempts? Any help would be appreciated! And while we're on the topic, is there any other type of security I could put in place on my servers for not only ftp but other attacks as well? Thanks guys!

littleoak
08-01-2008, 12:02 PM
You may want to use CSF and LFD on your server. LFD will handle the bans for you.

blaszlo
08-01-2008, 12:09 PM
Okay, is there some documentation on LFD that I can read up on? Where do I get it?

proHSP
08-01-2008, 12:24 PM
csf+lfd documentation and downloads are on configserver.com

blaszlo
08-01-2008, 12:36 PM
Thanks! Any more help/suggestions would be appreciated.

nobaloney
08-01-2008, 01:17 PM
We use, and can install, APT+BFD.

Jeff

Dravu
08-01-2008, 04:47 PM
We use, and can install, APT+BFD.

Jeff
I also use APF+BFD and it works very nice. :)

blaszlo
08-01-2008, 04:58 PM
BFD is brute force detection right? I've heard of it and I think I'll give it a try... Thanks!

nobaloney
08-02-2008, 09:47 AM
Yep. APF+BFD is:

Advanced Policy Firewall + Brute Force Detection

Jeff

xciso
02-08-2009, 03:59 AM
Yep. APF+BFD is:

Advanced Policy Firewall + Brute Force Detection

Jeff

How can I install this?
The easy way plz :)

smtalk
02-08-2009, 04:07 AM
http://directadmin.com/forum/showthread.php?t=14500 just use "cd apf-*" instead of "cd apf-0.*".