<rdf:RDF
    xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#'
    xmlns:s='http://snipsnap.org/rdf/snip-schema#'
    xml:base='http://bliki.rimuhosting.com/rdf'>
    <s:Snip rdf:about='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/networking/null+route+an+attackers+ip'
         s:cUser='retep'
         s:oUser=''
         s:mUser='retep'>
        <s:name>knowledgebase/linux/networking/null route an attackers ip</s:name>
        <s:content>1 Unwelcome Guests&#xD;&#xA;&#xD;&#xA;Sometimes servers receive unwanted traffic from an unwelcome source.&#xD;&#xA;&#xD;&#xA;One of the many compromised servers out there may be launching a brute force SSH attack on your server.  Or some bot may be wreaking havoc on your server while it tries to crawl your site.&#xD;&#xA;&#xD;&#xA;1 So Who Are These People?&#xD;&#xA;&#xD;&#xA;The first step to determining the source of the problem is to get the IP address.  &#xD;&#xA;&#xD;&#xA;Typically you can see the IP address in the sshd log (/var/log/messages or /var/log/secure or /var/log/auth typically output failed log in attempts).  &#xD;&#xA;&#xD;&#xA;For http requests you can often find the IP in the access logs.  e.g. in /var/log/httpd/access_log&#xD;&#xA;&#xD;&#xA;Finally, run netstat.  That will report all the connections to your server.&#xD;&#xA;&#xD;&#xA;1 How To Stop Them&#xD;&#xA;&#xD;&#xA;{code:none}&#xD;&#xA;IP=theattackersIP&#xD;&#xA;iptables --append INPUT --source $IP -j DROP&#xD;&#xA;{code}&#xD;&#xA;&#xD;&#xA;This appends a rule on the &apos;input&apos; chain to drop packets coming from $IP.&#xD;&#xA;&#xD;&#xA;If you get an error about iptables not being loaded you may also need to run:&#xD;&#xA;{code}modprobe iptable_filter{code}&#xD;&#xA;&#xD;&#xA;Be careful about that IP address and who you block.  It would be a shame if you blocked a valid user (or, worse, yourself).&#xD;&#xA;&#xD;&#xA;If you do block yourself out then you can have someone restart your server (the iptable command will be cleared out after a restart unless you run iptables save).  Or you can access your server via the console (RimuHosting VPS&apos;s all have console access over SSH.  Just enable it in the RimuHosting control panel)&#xD;&#xA;&#xD;&#xA;1 Following up with the Authorities&#xD;&#xA;&#xD;&#xA;If you wish you can report misuse to the person responsible for the IP (typically an ISP or data center).  &#xD;&#xA;&#xD;&#xA;This is ofen a good idea since the server attacking you is often under the control of some malware (trojan, virus, compromised user account, etc).  And someone needs to alert the IP address owner so they can resolve the problem with their user.&#xD;&#xA;&#xD;&#xA;You can go to http://whois.sc/ then enter the IP.  It will come back with information about who owns that IP.  And often an email to use for reporting abuse.  &#xD;&#xA;&#xD;&#xA;Use one of those email addresses and email them that your server is being attacked by an IP in their address space.  Include log snippets if you can.&#xD;&#xA;&#xD;&#xA;Every now and then you may get a reply or some action taken on your behalf.  But it is also quite common for your request to be ignored.&#xD;&#xA;</s:content>
        <s:mTime>2005-12-01 19:49:17.0</s:mTime>
        <s:cTime>2005-09-02 22:27:53.0</s:cTime>
        <s:comments
             rdf:type='http://www.w3.org/1999/02/22-rdf-syntax-ns#Bag'/>
        <s:snipLinks>
            <rdf:Bag>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux'/>
                <rdf:li rdf:resource='#snipsnap-search'/>
                <rdf:li rdf:resource='#knowledgebase'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/networking'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/postfixadmin on debian sarge'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/misc/ajax autocomplete'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/miscapplications/ruby on rails'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/postfix with amavis and mysql'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/misc/disk quotas'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/apache/installing and using mod_fastcgi'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/mass emailing best practices'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/moving imap folders between hosts'/>
                <rdf:li rdf:resource='#snipsnap-index'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/postfix notes'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/noexec tmp'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/tomcat on plesk'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/misc/bash'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/squrrelmail notes'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/mysql php connection error'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/miscapplications/moinmoin'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/setting up plone'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/misc/quick and dirty memory checker'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/qmail per-user spam filtering'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#SnipSnap/config'/>
                <rdf:li>
                    <s:Snip rdf:about='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/networking/null+route+an+attackers+ip'>
                        <s:attachments
                             rdf:type='http://www.w3.org/1999/02/22-rdf-syntax-ns#Bag'/>
                    </s:Snip>
                </rdf:li>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#l2tpns - high volume L2TP tunnel termination'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/accessing postgres via jdbc'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/miscapplications/rpm based mysql5 install'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/misc/accessing a vnc server behind a firewall'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/qmail notes'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/miscapplications/mysql notes'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#Virtual servers using Linux vServer'/>
                <rdf:li rdf:resource='#retep'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/working with different character encodings'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#A sysadmin&apos;s view of VoIP'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/ant install'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/miscapplications/grub boot cd'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/mailman notes'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail/postfixadmin+on+debian+sarge'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/apache/mod_rewrite'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/gridsphere install'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/webserver/apache/webdav'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/java/liferay install on tomcat 5.5'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#linux.conf.au 2006'/>
                <rdf:li rdf:resource='http://bliki.rimuhosting.com/rdf#knowledgebase/linux/mail'/>
            </rdf:Bag>
        </s:snipLinks>
    </s:Snip>
</rdf:RDF>
