Go Back   Linux Forums by TotalPenguin! Get linux Help! > Linux > Linux Security

Linux Security Make your Linux box more secure - Learn How

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-22-2008, 02:07 PM
Member
 
Join Date: Jun 2008
Posts: 67
EugenS is on a distinguished road
Default How to protect against brute force?

Is it enough to just make the passwords lenghty, with no meaning, with lower and uppercase letters? Or do you have to take more measures.
Reply With Quote

Sponsored Links
  #2 (permalink)  
Old 06-22-2008, 02:22 PM
Member
 
Join Date: Jan 2007
Posts: 59
Crop is on a distinguished road
Default

No. If you run a public webserver you should also use login detection software. The software will allow you to specify when to ban someone based on how many times they attempted to login. For example, if you set it at 5 and I tried (and failed) 5 times to login as root then the software would ban me.

There are two that I know of BFD (Brute Force Detection) and LFD (Logon Failure Daemon). Both work well.
Reply With Quote
  #3 (permalink)  
Old 06-22-2008, 05:01 PM
Member
 
Join Date: Jun 2008
Posts: 54
LissaValerian is on a distinguished road
Post Advanced Firewall Policy against Brute Force

I would also suggest AFP here:

R-fx Networks - Internet Security Solutions - Projects » APF

It's one of the tools I use:

From their website:

Advanced Policy Firewall (APF) is an iptables(netfilter) based firewall system designed around the essential needs of today's Internet deployed servers and the unique needs of custom deployed Linux installations. The configuration of APF is designed to be very informative and present the user with an easy to follow process, from top to bottom of the configuration file. The management of APF on a day-to-day basis is conducted from the command line with the 'apf' command, which includes detailed usage information and all the features one would expect from a current and forward thinking firewall solution.
Reply With Quote
  #4 (permalink)  
Old 06-23-2008, 05:11 PM
Member
 
Join Date: Jan 2007
Posts: 92
Prog is on a distinguished road
Default

I've used AFP before, excellent firewall.
Reply With Quote
  #5 (permalink)  
Old 06-24-2008, 02:03 PM
Member
 
Join Date: Jun 2008
Posts: 67
EugenS is on a distinguished road
Default

Thanks a lot guys. I'll check the APF and the brute force detectors...
Reply With Quote

Sponsored Links
  #6 (permalink)  
Old 06-24-2008, 02:29 PM
Member
 
Join Date: Jun 2008
Posts: 54
LissaValerian is on a distinguished road
Post

Quote:
Originally Posted by EugenS View Post
Thanks a lot guys. I'll check the APF and the brute force detectors...
Good luck! There are how-to's out there that describe a joint APF+BFD install, they work well in combo. It's what I use.

Good luck!

~Lissa Valerian
Reply With Quote
  #7 (permalink)  
Old 06-24-2008, 05:58 PM
Senior Member
 
Join Date: Jun 2008
Posts: 110
rumen is on a distinguished road
Default

Quote:
Originally Posted by LissaValerian View Post
I would also suggest AFP here:

R-fx Networks - Internet Security Solutions - Projects » APF

It's one of the tools I use:

From their website:

Advanced Policy Firewall (APF) is an iptables(netfilter) based firewall system designed around the essential needs of today's Internet deployed servers and the unique needs of custom deployed Linux installations. The configuration of APF is designed to be very informative and present the user with an easy to follow process, from top to bottom of the configuration file. The management of APF on a day-to-day basis is conducted from the command line with the 'apf' command, which includes detailed usage information and all the features one would expect from a current and forward thinking firewall solution.
Hey, thank you a lot for this valuable info It looks really promising.
Reply With Quote
  #8 (permalink)  
Old 06-27-2008, 09:34 PM
Member
 
Join Date: Jun 2008
Posts: 67
EugenS is on a distinguished road
Default

I tried and, what would you know, I've broken my fingers, heh. Might wanna call that friend of mine that's good with computers
Reply With Quote
  #9 (permalink)  
Old 06-30-2008, 08:58 PM
Member
 
Join Date: Jun 2008
Posts: 54
LissaValerian is on a distinguished road
Default

Quote:
Originally Posted by EugenS View Post
I tried and, what would you know, I've broken my fingers, heh. Might wanna call that friend of mine that's good with computers
Well, good luck with that!
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Force an RPM install Prog Linux Applications 2 10-31-2007 01:03 PM
Brute Force Attacks Wanch Linux Security 5 10-18-2007 12:39 AM
I tried to sell Linux Laptops with Paypal but they refuse to protect me! kernel Linux News 0 09-20-2007 02:55 PM


All times are GMT. The time now is 02:03 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.