Ubuntuda Xampp Kendiliğinden Kapanıyor
-
Sürekli bir ssh ile sunucuya erişim yapmak isteyenler var. Ben bu ipleri banlıyorum ama haddi hesabı yok sürekli bir giriş denemesi var normalmidir bu.
root@ubuntu:~# sudo tail -f /var/log/fail2ban.log 2024-05-21 10:07:14,868 fail2ban.filter [29198]: INFO [sshd] Found 62.152.32.102 - 2024-05-21 10:07:14 2024-05-21 10:07:50,621 fail2ban.filter [29198]: INFO [sshd] Found 139.59.120.249 - 2024-05-21 10:07:50 2024-05-21 10:07:52,391 fail2ban.filter [29198]: INFO [sshd] Found 139.59.120.249 - 2024-05-21 10:07:52 2024-05-21 10:07:54,492 fail2ban.filter [29198]: INFO [sshd] Found 107.172.29.228 - 2024-05-21 10:07:54 2024-05-21 10:07:56,479 fail2ban.filter [29198]: INFO [sshd] Found 107.172.29.228 - 2024-05-21 10:07:56 2024-05-21 10:07:56,622 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:07:56 2024-05-21 10:07:58,548 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:07:58 2024-05-21 10:08:19,406 fail2ban.filter [29198]: INFO [sshd] Found 43.153.38.187 - 2024-05-21 10:08:19 2024-05-21 10:10:10,232 fail2ban.filter [29198]: INFO [sshd] Found 43.153.38.187 - 2024-05-21 10:10:09 2024-05-21 10:10:11,836 fail2ban.filter [29198]: INFO [sshd] Found 43.153.38.187 - 2024-05-21 10:10:11 2024-05-21 10:10:31,028 fail2ban.filter [29198]: INFO [sshd] Found 107.172.29.228 - 2024-05-21 10:10:31 2024-05-21 10:10:50,675 fail2ban.filter [29198]: INFO [sshd] Found 43.153.199.39 - 2024-05-21 10:10:50 2024-05-21 10:10:59,699 fail2ban.filter [29198]: INFO [sshd] Found 43.153.38.187 - 2024-05-21 10:10:59 2024-05-21 10:11:01,750 fail2ban.filter [29198]: INFO [sshd] Found 43.153.38.187 - 2024-05-21 10:11:01 2024-05-21 10:11:01,857 fail2ban.actions [29198]: NOTICE [sshd] Ban 43.153.38.187 2024-05-21 10:11:03,680 fail2ban.filter [29198]: INFO [sshd] Found 43.134.20.231 - 2024-05-21 10:11:03 2024-05-21 10:11:05,611 fail2ban.filter [29198]: INFO [sshd] Found 43.134.20.231 - 2024-05-21 10:11:05 2024-05-21 10:11:18,221 fail2ban.filter [29198]: INFO [sshd] Found 107.172.29.228 - 2024-05-21 10:11:17 2024-05-21 10:11:20,292 fail2ban.filter [29198]: INFO [sshd] Found 107.172.29.228 - 2024-05-21 10:11:20 2024-05-21 10:11:20,495 fail2ban.actions [29198]: NOTICE [sshd] Ban 107.172.29.228 2024-05-21 10:11:24,433 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:11:24 2024-05-21 10:11:27,142 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:11:26 2024-05-21 10:11:40,813 fail2ban.filter [29198]: INFO [sshd] Found 43.163.214.132 - 2024-05-21 10:11:40 2024-05-21 10:11:43,520 fail2ban.filter [29198]: INFO [sshd] Found 43.163.214.132 - 2024-05-21 10:11:43 2024-05-21 10:11:44,794 fail2ban.filter [29198]: INFO [sshd] Found 43.153.199.39 - 2024-05-21 10:11:44 2024-05-21 10:11:46,689 fail2ban.filter [29198]: INFO [sshd] Found 43.153.199.39 - 2024-05-21 10:11:46 2024-05-21 10:11:46,749 fail2ban.actions [29198]: NOTICE [sshd] Ban 43.153.199.39 2024-05-21 10:12:05,766 fail2ban.filter [29198]: INFO [sshd] Found 43.134.20.231 - 2024-05-21 10:12:05 2024-05-21 10:12:05,992 fail2ban.actions [29198]: NOTICE [sshd] Ban 43.134.20.231 2024-05-21 10:12:08,473 fail2ban.filter [29198]: INFO [sshd] Found 43.134.20.231 - 2024-05-21 10:12:07 2024-05-21 10:12:25,675 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:12:25 2024-05-21 10:12:26,032 fail2ban.actions [29198]: NOTICE [sshd] Ban 43.163.226.88 2024-05-21 10:12:28,383 fail2ban.filter [29198]: INFO [sshd] Found 43.163.226.88 - 2024-05-21 10:12:27
Farklı bir yöntem deneye n var mı. Fail2Ban ile ipleri banlıyorum. Ban sürelerini uzatacam. Niye süreli ban tutuyorsun diyenler için; bir bakarsın yanlış şifreg irince yanlışlıkla kendimizide banlarız diye sorun olmaması için süreli tutuyorum.
-
cloudflare arkasında ise makine bu sorun oluyor bu giriş denemelerini engellemek için gelen ip bloklarını engelle htaccess ile yapabilirsin
-
Örnek 43.153 ile başlayan ipler sunucuya erişemez
<RequireAll> Require all granted Require not ip 43.153 </RequireAll>
https://httpd.apache.org/docs/2.4/howto/access.html -
EcHoLL bunu yazdı
Örnek 43.153 ile başlayan ipler sunucuya erişemez
Require all granted Require not ip 43.153
https://httpd.apache.org/docs/2.4/howto/access.html43 ve 153 ipler http protokolünden engeller bu. Burda 22 portundan deneyorlar. En kötü ihtimal 22 portunu değiştirecem artık.