Showing posts with label trick. Show all posts
Showing posts with label trick. Show all posts

Sunday, 30 April 2017

Saturday, 3 September 2016

LINUX HOWTO: Limiting SSH access to specific IP addresses

Intro:

This is a simple way to permit a select few IP addresses to access your raspberry pi though SSH and deny any others. By white listing certain IP addresses from networks you know you are adding a layer of security helping prevent others from accessing your machine. This is handy if you only access your machine from a few set locations, such as on the LAN and at work.

There are a few methods you could go about doing this, but i find this the most easy to implement, allowing you do accomplish basic permit and deny without iptables.

The two files needed to be edited are /etc/hosts.allow and /etc/hosts.deny

Step 1) 

Enter:
sudo nano /etc/hosts.allow

The file should be empty. At this point just add the ip addresses or subnets which you want to permit, for example:
sshd: 10.0.0.0/255.255.255.0 
sshd: 192.168.0.0/255.255.255.0
TIP: For specific IP addresses, just enter the address without the subnet.

Step 2)

Enter:
sudo nano /etc/hosts.deny

By entering the following you will deny all other addresses which were not explicitly defined before (everyone else).
sshd: ALL

Conclusion:

Now only those ip addresses or subnets defined will be able to get ssh access to your ssh server, others will not be able to connect.

LINUX HOWTO: Adding SSH login messages


This will display a message to those who connect to you ssh server before logging on.

Steps:

sudo nano /etc/ssh/sshd_config
- Open this file in terminal. Then find the line "#Banner /etc/issue.net" and remove comment so that it reads "Banner /etc/issue.net". Then save.

sudo nano /etc/issue.net
- Secondly open this file and enter your message in this file, then save. ASCII looks good here.


sudo service ssh restart
- Restart ssh, and then the message will be displayed to users.


                  _==|
             _==|   )__)  |
               )_)  )___) ))
              )___) )____))_)
         _    )____)_____))__)\
          \---__|____/|___|___-\\---
  ^^^^^^^^^\   oo oo oo oo     /~~^^^^^^^
    ~^^^^ ~~~~^^~~~~^^~~^^~~~~~
      ~~^^      ~^^~     ~^~ ~^ ~^
           ~^~~        ~~~^^~


For ascii art like this check out:

RASPI: Installing and configuring fail2ban on the RaspberryPi

Wikipedia:
Fail2ban operates by monitoring log files (e.g. /var/log/auth.log, /var/log/apache/access.log, etc.) for selected entries and running scripts based on them. Most commonly this is used to block selected IP addresses that may belong to hosts that are trying to breach the system's security. It can ban any host IP address that makes too many login attempts or performs any other unwanted action within a time frame defined by the administrator. Fail2ban is typically set up to unban a blocked host within a certain period, so as to not "lock out" any genuine connections that may have been temporarily misconfigured. However, an unban time of several minutes is usually enough to stop a network connection being flooded by malicious connections, as well as reducing the likelihood of a successful dictionary attack.
Fail2ban is an intrusion protection software which will prevent brute force attempts from accessing your ssh service. This is accomplished by logging the failed attempts and banning the offending ip addresses in iptables.


In this short tutorial i will show you how to install and configure fail2ban on Raspbian in four easy steps.



Step 1) Update

First thing to do is update your repositories...
sudo apt-get update

Step 2) Install

Secondly install fail2ban...
sudo apt-get install fail2ban

After installing, fail2ban will now protect ssh with default settings, so it will work after installing. Section three will show you how to customize these configurations.

Step 3) Configure

3.1)

Now take a look in this file at the default configurations, focusing on the defaults at the top and those under [ssh]. Don't change anything, just take a look around as our configurations will not be added here.
sudo nano /etc/fail2ban/jail.conf


The default configurations are stored in the jail.conf file, however changes should not be directly  here, instead they should be added to the jail.local file. - By adding our amendments to the .local, we can avoid adding everything and just those that we want to override.

Now open up jail.local:
sudo nano /etc/fail2ban/jail.local

3.2)

Here are my settings. You can paste these directly in to the empty jail.local file in if you want and use them as a template.

[ssh]
enabled  = true
port     = ssh
filter   = sshd
logpath  = /var/log/auth.log
bantime = 600
banaction = iptables-allports
maxretry = 3
ignoreip = 127.0.0.1/8 192.168.1.0/24

What they mean: 
  • 'enabled' is set to true so that fail2ban operates for ssh. 
  • 'port' is what port to monitor, the default will be ssh (port 22). You may want to change this if you are running ssh on a different port than 22, but most users will use 22 however.
  • 'logpath' is the default log file used by fail2ban to track login attempts.
  • 'bantime' is measured in seconds and is the amount of time an offender will have to wait until attempting to connect again. The default is 600 seconds (10 minutes). To add permanent bans set this to -1 or bellow. 
  • 'maxretry' is the amount of login attempts until the offender will be locked out.
  • 'ignoreip' can be set to define ip addresses or subnets which the rules do not apply to. In the example i have added the loopback address and the private address space for my LAN. Change appropriately to suite your private addressing on your LAN.
In nano: ctrl+o saves, and ctrl+x exists.


Step 4) Restart fail2ban to take effect

Once the configurations are added to jail.local and saved, you can restart the fail2ban service for changes to take effect..
sudo service fail2ban restart



View banned ip addresses

sudo iptables -L INPUT -v -n | less

Note: keep in mind, whenever fail2ban is restarted, all the previous bans will be removed.

Tuesday, 5 April 2016

Blocking spotify ads with Spotify-AdKiller (LINUX)



 This is the latest and greatest spotify ad stopping script available at the moment. Been trailing it out and its good. It doest remove the ads per-say, however plays a track of your choice over the ads. This is for testing purposes and the developers suggest buying premium. Try it out yourself.

We all love Spotify, but sometimes people (like us) want to throw a party without having to listen to interrupting ads before having bought Spotify Premium. Well, with this killer project, now you can!

View project on github

Saturday, 24 October 2015

FIX: Getting the R.A.T. 3 mouse to work on Ubuntu

This is a problem I am faced with every time I install Ubuntu and want yo use my R.A.T. 3 mouse. I found a solution though googling and it linked me to this youtube video.

In the description is a simple guide, so you don’t have to watch the video. I have included in the post bellow.

First type in the command to find out which product you have:

xinput -list

Once you find out what mouse you have:

sudo gedit /etc/X11/xorg.conf

For me I have the Madcatz Mad Catz R.A.T.3; type in:

Section "InputClass"
Identifier "Mouse Remap"
MatchProduct "Madcatz Mad Catz R.A.T.3 Mouse"
MatchDevicePath "/dev/input/event*"
Option "ButtonMapping" "1 2 3 4 5 0 0 8 9 0 0 0 0 0"
EndSection

For Madcatz Saitek Cyborg R.A.T.3; type in:

Section "InputClass"
Identifier "Mouse Remap"
MatchProduct "Saitek Cyborg R.A.T.3 Mouse"
MatchDevicePath "/dev/input/event*"
Option "ButtonMapping" "1 2 3 4 5 0 0 8 9 0 0 0 13 14"
EndSection

Enjoy.