preventing brute force attacks with iptables?

Anything regarding SSL/SSH and other security questions may go here
Forum rules
Please note the disclaimer before modifying your Synology Product.

preventing brute force attacks with iptables?

Postby mischaq » Fri Feb 08, 2008 4:58 pm

Might this be an idea to realize for syno-DS?

Blocks hosts trying to connect more than 3 times to the synology SSH server within 60 seconds?

I got inspirded by Sébastien Wains idea: here (including CODE) - but can this be done on a Diskstation and if yes, are there any adaptions necessary to the CODE?

I find this a geat thing if this could be done!

cheers, mischaq
mischaq
Versed
Versed
 
Posts: 276
Joined: Mon Jul 16, 2007 7:37 pm

Re: preventing brute force attacks with iptables?

Postby mischaq » Sun Feb 10, 2008 10:46 pm

Sébastien has answered in shis blog...

"well simply pass the commands beginning by iptables :
iptables -A INPUT -m state –state RELATED,ESTABLISHED -j ACCEPT


and see if it accepts the module “recent”.

If it does you just need to create a script and call it at boot"

...great, but i'm far to much a linux-newbie to make head or tail of these explanations. can someone help out in creating this superbe security feature?

cheers, mischaq
mischaq
Versed
Versed
 
Posts: 276
Joined: Mon Jul 16, 2007 7:37 pm

Re: preventing brute force attacks with iptables?

Postby Toxic » Sun Feb 10, 2008 11:38 pm

afaik synology does not support iptables. iptables are for network devices that support NAT.
Regards Simon
http://www.linksysinfo.org
Synology CS407 - DSM 3.0-1354
Cisco ASA5505 v8.3(4)2 - ASDM v6.3(4)53 512Mb/512Mb
User avatar
Toxic
Knowledgeable
Knowledgeable
 
Posts: 305
Joined: Wed Jun 06, 2007 6:19 pm
Location: Belfast

Re: preventing brute force attacks with iptables?

Postby mischaq » Mon Feb 11, 2008 5:10 pm

bad luck - but thanks a lot for the info!

cheers, mischaq
mischaq
Versed
Versed
 
Posts: 276
Joined: Mon Jul 16, 2007 7:37 pm


Return to Security/Secured Mods

Who is online

Users browsing this forum: Google [Bot] and 1 guest