{"id":1724,"date":"2011-10-08T12:00:49","date_gmt":"2011-10-08T12:00:49","guid":{"rendered":"http:\/\/www.tom-nan.com\/?p=1724"},"modified":"2011-10-08T12:00:49","modified_gmt":"2011-10-08T12:00:49","slug":"more-iptables-fun","status":"publish","type":"post","link":"https:\/\/tom-nan.com\/index.php\/2011\/10\/08\/more-iptables-fun\/","title":{"rendered":"More iptables fun"},"content":{"rendered":"<p>When I was making rules for the firewall earlier this week, I set up logging for when people attempted to connect to our network using automated tools.\u00a0 Many times people who know nothing about the underlying ports and protocols will use automated tools to try and break into a computer on the Internet; they&#8217;re called &#8220;script kiddies&#8221;\u00a0 They connect to a machine that has a Secure Shell server running and repeatedly connect to it trying different passwords hundreds if not thousands of times hoping to guess the password.\u00a0 I have the rules set up so that I connect in case I need to connect from the outside, but if someone uses one of these tools the packets get dropped on the floor.\u00a0 This is what this set of rules looks like:<\/p>\n<blockquote><p>###\u00a0 ALLOW SSH FROM RED INTERNET<br \/>\n# Limit external attempts to connect to SSH to 3 per minute<br \/>\n$IPT -A INPUT -p tcp -i $RED &#8211;dport 22 -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT<br \/>\n$IPT -A INPUT -p tcp -i $RED &#8211;dport 22 -m tcp &#8211;syn -m recent &#8211;set<br \/>\n$IPT -A INPUT -p tcp -i $RED &#8211;dport 22 -m tcp &#8211;syn -m recent &#8211;update &#8211;seconds 600 &#8211;hitcount 4 \\<br \/>\n-j LOG &#8211;log-prefix &#8220;SSH_EXT_GT3PKTS: &#8221;<br \/>\n$IPT -A INPUT -p tcp -i $RED &#8211;dport 22 -m tcp &#8211;syn -m recent &#8211;update &#8211;seconds 600 &#8211;hitcount 4 -j DROP<br \/>\n$IPT -A INPUT -p tcp -i $RED &#8211;dport 22 -m tcp &#8211;syn -j ACCEPT<\/p><\/blockquote>\n<p>I chopped stuff out of the log file but kept stuff for analysis. There are some interesting things in this log excerpt that can be further used to create rules for the firewall.\u00a0 I&#8217;ll explain after:<\/p>\n<blockquote><p>Oct 6 01:35:06 SRC=61.158.99.224 TTL=43 SPT=47787 DPT=22 SYN URGP=0<br \/>\nOct 6 01:35:09 SRC=61.158.99.224 TTL=43 SPT=47787 DPT=22 SYN URGP=0<br \/>\nOct 6 01:35:15 SRC=61.158.99.224 TTL=43 SPT=47787 DPT=22 SYN URGP=0<br \/>\nOct 6 18:14:22 SRC=218.108.0.68 TTL=43 SPT=3091 DPT=22 SYN URGP=0<br \/>\nOct 6 18:14:25 SRC=218.108.0.68 TTL=43 SPT=3091 DPT=22 SYN URGP=0<br \/>\nOct 6 18:14:31 SRC=218.108.0.68 TTL=43 SPT=3091 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:34 SRC=206.172.28.171 TTL=55 SPT=60242 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:34 SRC=206.172.28.171 TTL=55 SPT=60340 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:37 SRC=206.172.28.171 TTL=55 SPT=60242 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:37 SRC=206.172.28.171 TTL=55 SPT=60340 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:38 SRC=206.172.28.171 TTL=55 SPT=36291 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:41 SRC=206.172.28.171 TTL=55 SPT=36291 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:43 SRC=206.172.28.171 TTL=55 SPT=60242 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:43 SRC=206.172.28.171 TTL=55 SPT=60340 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:45 SRC=206.172.28.171 TTL=55 SPT=44009 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:47 SRC=206.172.28.171 TTL=55 SPT=36291 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:48 SRC=206.172.28.171 TTL=55 SPT=44009 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:53 SRC=206.172.28.171 TTL=55 SPT=53125 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:54 SRC=206.172.28.171 TTL=55 SPT=44009 DPT=22 SYN URGP=0<br \/>\nOct 6 20:46:56 SRC=206.172.28.171 TTL=55 SPT=53125 DPT=22 SYN URGP=0<br \/>\nOct 6 20:47:02 SRC=206.172.28.171 TTL=55 SPT=53125 DPT=22 SYN URGP=0<br \/>\nOct 6 20:47:06 SRC=206.172.28.171 TTL=55 SPT=38358 DPT=22 SYN URGP=0<br \/>\nOct 6 20:47:09 SRC=206.172.28.171 TTL=55 SPT=38358 DPT=22 SYN URGP=0<br \/>\nOct 6 20:47:15 SRC=206.172.28.171 TTL=55 PT=38358 DPT=22 SYN URGP=0<br \/>\nOct 7 06:19:15 SRC=212.150.184.184 TTL=51 SPT=36483 DPT=22 SYN URGP=0<br \/>\nOct 7 06:19:18 SRC=212.150.184.184 TTL=51 SPT=36483 DPT=22 SYN URGP=0<br \/>\nOct 7 06:19:24 SRC=212.150.184.184 TTL=51 SPT=36483 DPT=22 SYN URGP=0<br \/>\nOct 7 07:28:50 SRC=211.118.104.11 TTL=53 SPT=38767 DPT=22 SYN URGP=0<br \/>\nOct 7 07:28:53 SRC=211.118.104.11 TTL=53 SPT=38767 DPT=22 SYN URGP=0<br \/>\nOct 7 07:28:59 SRC=211.118.104.11 TTL=53 SPT=38767 DPT=22 SYN URGP=0<br \/>\nOct 8 09:20:54 SRC=60.191.222.84 TTL=52 SPT=39716 DPT=22 SYN URGP=0<br \/>\nOct 8 09:20:57 SRC=60.191.222.84 TTL=52 SPT=39716 DPT=22 SYN URGP=0<br \/>\nOct 8 09:21:03 SRC=60.191.222.84 TTL=52 SPT=39716 DPT=22 SYN URGP=0<\/p><\/blockquote>\n<p>If you look at the timing:<\/p>\n<blockquote><p>Packet 1, 2, and 3 are received before logging occurs<br \/>\nPacket 4 is dropped, the tool waits 2 or 3 seconds and sends another packet from the same source port<br \/>\nPacket 5 is dropped, the tool waits 5 or 6 seconds and sends another packet from the same source port<br \/>\nPacket 6 is dropped, the tool gives up<\/p><\/blockquote>\n<p>I don&#8217;t know how long the network stack on the far end waits before clearing the dropped attempts from their network queues but it&#8217;s pretty effective at reducing the number of brute force password guesses on my machine. Also if you look at the log you notice that 206.172.28.171 made numerous attempts from numerous source ports.\u00a0 Looks to me like 6 attempts from 6 different source ports;\u00a0 I think my rule treats attempts from an address on different source ports as separate entities.\u00a0 Will keep things posted here as I learn more on how this stuff works.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When I was making rules for the firewall earlier this week, I set up logging for when people attempted to connect to our network using automated tools.\u00a0 Many times people who know nothing about the underlying ports and protocols will use automated tools to try and break into a computer on the Internet; they&#8217;re called &#8230; <a title=\"More iptables fun\" class=\"read-more\" href=\"https:\/\/tom-nan.com\/index.php\/2011\/10\/08\/more-iptables-fun\/\" aria-label=\"Read more about More iptables fun\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[6,28],"tags":[],"class_list":["post-1724","post","type-post","status-publish","format-standard","hentry","category-computer-help","category-technology"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/posts\/1724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/comments?post=1724"}],"version-history":[{"count":0,"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/posts\/1724\/revisions"}],"wp:attachment":[{"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/media?parent=1724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/categories?post=1724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tom-nan.com\/index.php\/wp-json\/wp\/v2\/tags?post=1724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}