>>157760Was die Frage aufwirft, was denn wohl so die sinnvollste Sicherheitspolitik ist. Aktuell habe ich auf allen Ports, auf denen potentiell was geht (HTTP, SSH) ein Fail2Ban laufen, die restlichen Ports sind in der nftables einfach zu.
Ich überleg ja ein wenig, ob ich nicht den externen SSH-Port auf einen Incus-Container lenken sollte, in welchem man sich als root ohne Passwort oder mit saudummen Kindergartenpasswort anmelden kann, nur, dass der root-Account gar nichts darf und die einzige Funktion des Containers ist, zu loggen, was der Angreifer da so versucht zu machen (eventuell sogar vortäuscht, dass das alles erfolgreich sei). Wäre bestimmt mal interessant zu sehen, was die da so vorhaben - oder ob die überhaupt irgendwas machen.
Mich kotzt sowas halt schon irgendwie an (und ja, das geht den ganzen Tag so...):
45.131.155.254 123.456.789.0 - [11/Jun/2025:17:07:33 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
91.238.181.96 - - [11/Jun/2025:17:08:37 +0200] " " 400 345 "-" "-"
144.172.114.36 123.456.789.0 - [11/Jun/2025:17:15:15 +0200] "GET / HTTP/1.1" 200 1147 "-" "Linux Gnu (cow)"
209.46.127.36 123.456.789.0 - [11/Jun/2025:17:18:05 +0200] "GET / HTTP/1.0" 200 1147 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0"
74.82.47.3 - - [11/Jun/2025:17:19:22 +0200] " " 400 345 "-" "-"
79.124.8.120 123.456.789.0 - [11/Jun/2025:17:21:21 +0200] "GET / HTTP/1.1" 200 1147 "http://123.456.789.0:80/" "Mozilla/5.0"
80.82.77.202 - - [11/Jun/2025:17:43:56 +0200] "GET / HTTP/1.0" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36"
124.121.190.187 123.456.789.0 - [11/Jun/2025:17:44:25 +0200] "GET / HTTP/1.1" 200 1147 "-" "Hello-World/1.0"
124.121.190.187 123.456.789.0 - [11/Jun/2025:17:44:25 +0200] " / " 400 345 "-" "-"
79.124.8.120 123.456.789.0 - [11/Jun/2025:17:44:25 +0200] "GET / HTTP/1.1" 200 1147 "http://123.456.789.0:80/" "Mozilla/5.0"
89.42.231.140 123.456.789.0 - [11/Jun/2025:17:56:35 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 341 "-" "-"
141.98.10.162 123.456.789.0 - [11/Jun/2025:18:05:32 +0200] "GET / HTTP/1.1" 200 1147 "-" "-"
93.174.93.12 - - [11/Jun/2025:18:14:03 +0200] "GET / HTTP/1.0" 200 1147 "-" "Mozilla/5.0 (X11; Linux i686; rv:25.0) Gecko/20100101 Firefox/25.0"
149.50.103.48 123.456.789.0 - [11/Jun/2025:18:15:46 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
185.242.226.99 - - [11/Jun/2025:18:26:32 +0200] " " 400 345 "-" "-"
204.76.203.206 123.456.789.0 - [11/Jun/2025:18:45:05 +0200] "GET / HTTP/1.1" 200 1147 "-" "-"
204.76.203.206 123.456.789.0 - [11/Jun/2025:18:45:06 +0200] "GET /set_safety.shtml?r=52300 HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
204.76.203.206 123.456.789.0 - [11/Jun/2025:18:45:12 +0200] "GET /sysinit.shtml HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
185.218.84.178 123.456.789.0 - [11/Jun/2025:18:47:51 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
5.183.209.244 123.456.789.0 - [11/Jun/2025:19:15:29 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
89.42.231.140 123.456.789.0 - [11/Jun/2025:19:28:56 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 341 "-" "-"
93.174.93.12 - - [11/Jun/2025:19:30:51 +0200] " " 400 345 "-" "-"
52.180.146.167 123.456.789.0 - [11/Jun/2025:19:44:23 +0200] "GET /actuator/health HTTP/1.1" 404 341 "-" "Mozilla/5.0 zgrab/0.x"
89.248.167.131 123.456.789.0 - [11/Jun/2025:20:01:37 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36"
89.248.167.131 123.456.789.0 - [11/Jun/2025:20:01:37 +0200] "GET /robots.txt HTTP/1.1" 404 341 "-" "-"
89.248.167.131 123.456.789.0 - [11/Jun/2025:20:01:37 +0200] "GET /sitemap.xml HTTP/1.1" 404 341 "-" "-"
89.248.167.131 123.456.789.0 - [11/Jun/2025:20:01:37 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 341 "-" "-"
89.248.167.131 123.456.789.0 - [11/Jun/2025:20:01:37 +0200] "GET /favicon.ico HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36"
114.7.160.74 123.456.789.0 - [11/Jun/2025:20:07:52 +0200] "GET / HTTP/1.0" 200 1147 "-" "-"
195.3.221.137 123.456.789.0 - [11/Jun/2025:20:12:55 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.140 Safari/537.36"
149.50.103.48 123.456.789.0 - [11/Jun/2025:20:31:27 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
87.255.194.135 123.456.789.0 - [11/Jun/2025:20:38:55 +0200] "GET /admin/assets/js/views/login.js HTTP/1.0" 404 341 "-" "xfa1"
185.218.84.178 123.456.789.0 - [11/Jun/2025:20:46:34 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
185.218.84.178 123.456.789.0 - [11/Jun/2025:20:50:59 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
204.76.203.206 123.456.789.0 - [11/Jun/2025:21:05:37 +0200] "GET / HTTP/1.1" 200 1147 "-" "-"
204.76.203.206 123.456.789.0 - [11/Jun/2025:21:05:37 +0200] "GET /set_safety.shtml?r=52300 HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
204.76.203.206 123.456.789.0 - [11/Jun/2025:21:05:43 +0200] "GET /sysinit.shtml HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
93.174.93.12 - - [11/Jun/2025:21:09:31 +0200] "GET / HTTP/1.0" 200 1147 "-" "Lynx/2.8.5rel.1 libwww-FM/2.14 SSL-MM/1.4.1 GNUTLS/0.8.12"
45.135.193.65 123.456.789.0 - [11/Jun/2025:21:20:46 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Linux; Android 4.2.2; WX10K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.99 Mobile Safari/537.36"
196.251.71.232 123.456.789.0 - [11/Jun/2025:21:32:13 +0200] "GET /.env HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
185.218.84.178 123.456.789.0 - [11/Jun/2025:21:40:51 +0200] "GET / HTTP/1.1" 200 1147 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46"
164.90.233.210 - - [11/Jun/2025:21:41:01 +0200] " " 400 345 "-" "-"