12_aslbrute not banning IP's

Customer support forums for the modsecurity rules feed. There is no such thing as a bad question here as long as it pertains to using the real time modsecurity rules feed. Newbies feel free to get help getting started or asking questions that may be obvious.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

12_aslbrute not banning IP's

Unread post by webjive »

We purchased a yearly subscription for the ASL rules and our system is being hit hard daily by bots trying to brute force the Joomla admin. What's bothersome is that your rules aren't banning those ip's and they just keep pounding away.

Is there a way to tweak that rule to ban IP's for 30 days?
User avatar
hostingg
Forum User
Forum User
Posts: 63
Joined: Mon Mar 18, 2013 6:26 pm
Location: Earth

Re: 12_aslbrute not banning IP's

Unread post by hostingg »

sure just change the shun time in asl to 30 days
If everything was easy, then the world wouldn't need engineers.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

OK where do you do that?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

Thank you for the question, please see the documentation for this configuration setting in ASL:

https://www.atomicorp.com/wiki/index.ph ... _SHUN_TIME

The value is seconds, so 30 days would be 2592000.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

OK, where are these settings for SHUN time? We're running the rules only with mod security. Thx
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

Those settings are part of Atomic Secured Linux (ASL). Those rules require ASL to detect and block brute force attacks, as documented here:

https://www.atomicorp.com/wiki/index.ph ... brute.conf
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

Got it. The mod sec rules are limited without the full ASL?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

Its not a limitation in the rules, modsecurity just doesnt do this. Event tracking capabilities in modsecurity are very poor (and have performance issues), so we use an high speed engine to do this in ASL.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

Thanks! What has kept us from going full ASL is when we tried to install it in the past, it made our production machine un-bootable and we had to perform an OS reload so, we're VERY skiddish on attempting to install ASL ourselves.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

We'd be happy to install ASL for you.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

Getting close to a decision here on the full ASL suite. The attacks are coming in waves with peaks and valleys. Looks like its a low level DDOS on WP and Joomla for admin and some scraping to check for vulnerable files. Would the full ASL help with this? See attached image.
Attachments
Screen Shot 2014-04-03 at 10.21.00 AM.jpg
Screen Shot 2014-04-03 at 10.21.00 AM.jpg (83.37 KiB) Viewed 13814 times
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

Thank you for the question, ASL sure does protect against this. If you'd like help installing ASL, just shoot support an email.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

Well, it's time to to the deed then! I need a pro to install and get this rolling. My only fear is for our large Joomla install base and what might get caught in the ASL rules. Good news is I'm sure there will be a way to exclude some domains from those rules like CSF mod_sec control? That's our environment now, lots of CSF tools. Modsec Control, CSF, etc. Has worked well until now but, the hackers of the world have found us.

I purchased the annual ASL rules for $99. Is this an upgrade to full ASL or an upgrade?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: 12_aslbrute not banning IP's

Unread post by mikeshinn »

My only fear is for our large Joomla install base and what might get caught in the ASL rules.
We use Joomla, so its very unlikely any of our rules you cause any issues with Joomla. If you havent had an issue with the modsec rules from us, then you'll be fine with ASL.
Good news is I'm sure there will be a way to exclude some domains from those rules like CSF mod_sec control?
Oh yeah, and then some. You can tweak each rule, its behavior, thresholds and more.
I purchased the annual ASL rules for $99. Is this an upgrade to full ASL or an upgrade?
If you purchased a rules license, thats just a license for the rules. Rules licenses do not include ASL. You can upgrade from a rules annual license to an ASL annual license for only $99.96.
webjive
Forum User
Forum User
Posts: 22
Joined: Wed Nov 09, 2011 3:22 am
Location: US

Re: 12_aslbrute not banning IP's

Unread post by webjive »

Thanks! Once I pay that, will I get access to the support ticket system? Right now, I can't login to that.
Post Reply