Slide 30
Slide 30 text
SSH (3)
30
Server Attacker
$ sudo tail -f /var/log/fail2ban.log
2017-02-10 20:03:11,437 fail2ban.server : INFO Exiting Fail2ban
2017-02-10 20:03:12,166 fail2ban.server : INFO Changed logging target to
/var/log/fail2ban.log for Fail2ban v0.8.11
2017-02-10 20:03:12,167 fail2ban.jail : INFO Creating new jail 'ssh'
2017-02-10 20:03:12,203 fail2ban.jail : INFO Jail 'ssh' uses pyinotify
2017-02-10 20:03:12,239 fail2ban.jail : INFO Initiated 'pyinotify' backend
2017-02-10 20:03:12,241 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2017-02-10 20:03:12,243 fail2ban.filter : INFO Set maxRetry = 6
2017-02-10 20:03:12,245 fail2ban.filter : INFO Set findtime = 600
2017-02-10 20:03:12,246 fail2ban.actions: INFO Set banTime = 600
2017-02-10 20:03:12,319 fail2ban.jail : INFO Jail 'ssh' started
2017-02-10 20:06:28,496 fail2ban.actions: WARNING [ssh] Ban attacker_IP