store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 1:11 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: Looking for the best modsec results...
Unread postPosted: Mon Jan 11, 2010 12:55 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Hi everybody, HAPPY NEW YEAR!

Well it is me again trying to find the best way to manage my server, lol.

I have been using modsec rules for a time now and found that all the rules does a great job blocking a lot of injections or spammer attempts, it has been so great that I have refined a personal project:

I have tabulated data from 5 months and decided to block all the IPs that triggered the spam or injection rules, so, after depuring all the info I have about 7,000 IPs. I have divided them in two files: Hackers and Spammers. that two rules search and blocks this IPs.

I really like this project because now my server blocks the recurring IPs and no time is wasted checking what is wrong, of course if new IPs arrive the other great modsec rules will be stop them and in a few days I will be adding them to the lists.

Regards,
Sergio


Top
 Profile  
 
 Post subject: Re: Looking for the best modsec results...
Unread postPosted: Mon Jan 11, 2010 2:56 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
That sounds like a great project. Would you be willing to share the data with me? I'm working on the RBL we will be adding to ASL in the future and data on attacks is exactly what I need to add to our honeypot data, particularly if you have done your own analysis and have some results to share.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Looking for the best modsec results...
Unread postPosted: Mon Jan 11, 2010 4:12 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
For sure, I will be sending you the data via email to support.

By the way I know that I could have just one file with all the IPs in there, but I separated spammers from injection coders (hack attempts) just to have a track on them.

If you want, I can send you the IPs with the ID CODES that modsec assigned to them.

Regards,

Sergio


Top
 Profile  
 
 Post subject: Re: Looking for the best modsec results...
Unread postPosted: Tue Jan 12, 2010 5:43 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
That would be great.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Looking for the best modsec results...
Unread postPosted: Fri Feb 19, 2010 6:53 pm 
Offline
Forum User
Forum User

Joined: Sat Jan 17, 2009 2:19 pm
Posts: 99
Hello Mike,
sorry for the delay, I will add the file on another post so anyone can use it, hope you don't mind.

Sergio.


Top
 Profile  
 
 Post subject: Re: Looking for the best modsec results...
Unread postPosted: Fri Feb 19, 2010 8:23 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Not at all. Please do.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group