Fail2ban: ๋ฌด์‹œ ์ •๊ทœ์‹์ด ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค

์— ๋งŒ๋“  2012๋…„ 12์›” 21์ผ  ยท  3์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: fail2ban/fail2ban

๊ตฌ์„ฑ ํŒŒ์ผ์˜ ignoreregex ์˜ต์…˜์ด ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(v0.8.4).
fail2ban-regex๋กœ ํ…Œ์ŠคํŠธํ•  ๋•Œ "์ •๊ทœ ํ‘œํ˜„์‹์„ ์ปดํŒŒ์ผํ•  ์ˆ˜ ์—†์Œ" ์˜ค๋ฅ˜๋„ ๋ฐœ์ƒํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

fail2ban-regex error.log /etc/fail2ban/filter.d/suhosin.conf

์ผ์น˜ํ•˜๋Š” ํ•ญ๋ชฉ์ด ์—†์Šต๋‹ˆ๋‹ค.

|- Regular expressions:
|
`- Number of matches:

์˜ˆ์‹œ:
suhosin.conf

[Definition]
failregex = suhosin\[\d*\].*\(attacker\s'<HOST>'.*
ignoreregex = suhosin\[\d*\].*(memory_limit).*\(attacker\s'<HOST>'.*

์˜ค๋ฅ˜ ๊ธฐ๋ก

Dec 17 15:51:13 server suhosin[27622]: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable      'action' (attacker '67.210.100.166', file '/bla.php')
Dec 17 15:51:13 server suhosin[27624]: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'board' (attacker '67.210.100.166', file '/bla.php')
Dec 17 15:51:13 server suhosin[27624]: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'topic' (attacker '67.210.100.166', file '/bla.php')
Dec 20 18:58:21 server suhosin[4088]: ALERT - script tried to increase memory_limit to 120000000 bytes which is above the allowed value (attacker '123.123.123.123', file '/bla.php', line 10)
Dec 20 18:58:32 server suhosin[4051]: ALERT - script tried to increase memory_limit to 120000000 bytes which is above the allowed value (attacker '123.123.123.123', file '/bla.php', line 10)

๋‚˜๋Š” ๋ชจ๋“  ์ˆ˜ํ˜ธ์‹  ๊ณต๊ฒฉ์„ ์ผ์น˜์‹œํ‚ค๊ณ  memory_limit๋ฅผ ๋Š˜๋ฆฌ๋ ค๊ณ  ๋ชจ๋“  ๊ณต๊ฒฉ์„ ๋นผ๋ ค๊ณ ํ•ฉ๋‹ˆ๋‹ค.

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

:+1:
์•„, ๋‹น์‹  ๋ง์ด ๋งž์•„. ์˜ฌ๋ฐ”๋ฅธ ์„ธ ๋ฒˆ์งธ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์•Œ๋ ค์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.
์ด๊ฒƒ์„ ๊ฒŒ์‹œํ•˜๊ธฐ ์ „์— ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€๋ฅผ ์ฝ์—ˆ์–ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค.
์–ด์จŒ๋“  ์ด๊ฒƒ์€ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

fail2ban-regex error.log /etc/fail2ban/filter.d/suhosin.conf /etc/fail2ban/filter.d/suhosin.conf

๋ฌธ์ œ๋ฅผ ๋‹ซ์Šต๋‹ˆ๋‹ค. ๋ฉ”๋ฆฌ ํฌ๋ฆฌ์Šค๋งˆ์Šค. ์•ˆ๋…•ํžˆ ๊ณ„์„ธ์š”.

๋ชจ๋“  3 ๋Œ“๊ธ€

์„ค๋ช…ํ•˜๊ธฐ: ignoreregex๋ฅผ ์ „ํ˜€ ์ง€์ •ํ–ˆ์Šต๋‹ˆ๊นŒ?

$> /usr/bin/fail2ban-regex | head
Usage: /usr/bin/fail2ban-regex [OPTIONS] <LOG> <REGEX> [IGNOREREGEX]

๋”ฐ๋ผ์„œ ์˜ˆ๋ฅผ ๋“ค์–ด sshd.conf์— ignoregex๋ฅผ ์ถ”๊ฐ€ํ•˜๋ฉด (ํ”ผํ•  ํ•„์š”๊ฐ€ ์žˆ์ง€๋งŒ
ignoreregex์— ๋Œ€ํ•œ ์ผ์น˜๊ฐ€ ์ „์ฒด์— ์ ์šฉ๋˜๋ฏ€๋กœ ์ „๋ฉด์— ๊ณ ์ •
๋ผ์ธ, ์ŠคํŠธ๋ฆฝ ์‹œ๊ฐ„/๋‚ ์งœ ์—†์Œ) -- ๋ชจ๋‘ ์ข‹์Šต๋‹ˆ๋‹ค.

$> ./fail2ban-regex testcases/files/logs/sshd config/filter.d/sshd.conf config/filter.d/sshd.conf  2>/dev/null | grep -A2 Ignoreregex 
Ignoreregex: 2 total
|- #) [# of hits] regular expression
|  1) [2] \s*(?:\S+ )?(?:kernel: \[\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:)?\s*(?:error: PAM: )?Authentication failure for .* from <HOST>\s*$

$> grep ignoreregex config/filter.d/sshd.conf
# Option:  ignoreregex
ignoreregex = %(__prefix_line)s(?:error: PAM: )?Authentication failure for .* from <HOST>\s*$

2012๋…„ 12์›” 21์ผ ๊ธˆ์š”์ผ Jens-Andrรฉ Koch๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

๊ตฌ์„ฑ ํŒŒ์ผ์˜ ignoreregex ์˜ต์…˜์ด ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(v0.8.4).
fail2ban-regex๋กœ ํ…Œ์ŠคํŠธํ•  ๋•Œ "Unable to compile regular
์‹" ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
์ผ์น˜ํ•˜๋Š” ํ•ญ๋ชฉ์ด ์—†์Šต๋‹ˆ๋‹ค.

์ •๊ทœ์‹ ๋ฌด์‹œ
|- ์ •๊ทœ ํ‘œํ˜„์‹:

`- ์ผ์น˜ ํšŸ์ˆ˜:

์ผ๋ฐ˜ ๊ตฌ์„ฑ ์˜ต์…˜์ด ๋ˆ„๋ฝ๋˜์—ˆ๊ฑฐ๋‚˜ ๋ฒ„๊ทธ์ž…๋‹ˆ๊นŒ?

์•ผ๋กœ์Šฌ๋ผํ”„ O. ํ• ์ฒธ์ฝ”
์‹ฌ๋ฆฌํ•™ ๋ฐ ๋‡Œ๊ณผํ•™๋ถ€ ๋ฐ•์‚ฌํ›„ ์—ฐ๊ตฌ์›
Dartmouth College, 419 Moore Hall, Hinman Box 6207, Hanover, NH 03755
์ „ํ™”: +1 (603) 646-9834 ํŒฉ์Šค: +1 (603) 646-1419
WWW: http://www.linkedin.com/in/yarik

:+1:
์•„, ๋‹น์‹  ๋ง์ด ๋งž์•„. ์˜ฌ๋ฐ”๋ฅธ ์„ธ ๋ฒˆ์งธ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์•Œ๋ ค์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.
์ด๊ฒƒ์„ ๊ฒŒ์‹œํ•˜๊ธฐ ์ „์— ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€๋ฅผ ์ฝ์—ˆ์–ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค.
์–ด์จŒ๋“  ์ด๊ฒƒ์€ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

fail2ban-regex error.log /etc/fail2ban/filter.d/suhosin.conf /etc/fail2ban/filter.d/suhosin.conf

๋ฌธ์ œ๋ฅผ ๋‹ซ์Šต๋‹ˆ๋‹ค. ๋ฉ”๋ฆฌ ํฌ๋ฆฌ์Šค๋งˆ์Šค. ์•ˆ๋…•ํžˆ ๊ณ„์„ธ์š”.

๋ฉ”๋ฆฌ ํฌ๋ฆฌ์Šค๋งˆ์Šค! ;)

2012๋…„ 12์›” 21์ผ ๊ธˆ์š”์ผ Jens-Andrรฉ Koch๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

[1]:+1:
์•„, ๋‹น์‹  ๋ง์ด ๋งž์•„. ์˜ฌ๋ฐ”๋ฅธ ์„ธ ๋ฒˆ์งธ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์•Œ๋ ค์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.
์ด๊ฒƒ์„ ๊ฒŒ์‹œํ•˜๊ธฐ ์ „์— ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€๋ฅผ ์ฝ์—ˆ์–ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค.
์–ด์จŒ๋“  ์ด๊ฒƒ์€ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.
fail2ban-regex error.log /etc/fail2ban/filter.d/suhosin.conf
/etc/fail2ban/filter.d/suhosin.conf

๋ฌธ์ œ๋ฅผ ๋‹ซ์Šต๋‹ˆ๋‹ค. ๋ฉ”๋ฆฌ ํฌ๋ฆฌ์Šค๋งˆ์Šค. ์•ˆ๋…•ํžˆ ๊ณ„์„ธ์š”.

โ€”
์ด ์ด๋ฉ”์ผ์— ์ง์ ‘ ํšŒ์‹ ํ•˜๊ฑฐ๋‚˜ [2]GitHub์—์„œ ํ™•์ธํ•˜์„ธ์š”.

์ฐธ๊ณ ๋ฌธํ—Œ

๋ณด์ด๋Š” ๋งํฌ

  1. https://github.com/fail2ban/fail2ban/issues/100#issuecomment -11623202

์•ผ๋กœ์Šฌ๋ผํ”„ O. ํ• ์ฒธ์ฝ”
์‹ฌ๋ฆฌํ•™ ๋ฐ ๋‡Œ๊ณผํ•™๋ถ€ ๋ฐ•์‚ฌํ›„ ์—ฐ๊ตฌ์›
Dartmouth College, 419 Moore Hall, Hinman Box 6207, Hanover, NH 03755
์ „ํ™”: +1 (603) 646-9834 ํŒฉ์Šค: +1 (603) 646-1419
WWW: http://www.linkedin.com/in/yarik

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰