Page 1 of 2

12_aslbrute not banning IP's

Posted: Sun Mar 30, 2014 7:27 pm
by webjive
We purchased a yearly subscription for the ASL rules and our system is being hit hard daily by bots trying to brute force the Joomla admin. What's bothersome is that your rules aren't banning those ip's and they just keep pounding away.

Is there a way to tweak that rule to ban IP's for 30 days?

Re: 12_aslbrute not banning IP's

Posted: Mon Mar 31, 2014 5:37 pm
by hostingg
sure just change the shun time in asl to 30 days

Re: 12_aslbrute not banning IP's

Posted: Mon Mar 31, 2014 5:42 pm
by webjive
OK where do you do that?

Re: 12_aslbrute not banning IP's

Posted: Mon Mar 31, 2014 5:48 pm
by mikeshinn
Thank you for the question, please see the documentation for this configuration setting in ASL:

https://www.atomicorp.com/wiki/index.ph ... _SHUN_TIME

The value is seconds, so 30 days would be 2592000.

Re: 12_aslbrute not banning IP's

Posted: Mon Mar 31, 2014 5:55 pm
by webjive
OK, where are these settings for SHUN time? We're running the rules only with mod security. Thx

Re: 12_aslbrute not banning IP's

Posted: Mon Mar 31, 2014 6:00 pm
by mikeshinn
Those settings are part of Atomic Secured Linux (ASL). Those rules require ASL to detect and block brute force attacks, as documented here:

https://www.atomicorp.com/wiki/index.ph ... brute.conf

Re: 12_aslbrute not banning IP's

Posted: Tue Apr 01, 2014 12:07 am
by webjive
Got it. The mod sec rules are limited without the full ASL?

Re: 12_aslbrute not banning IP's

Posted: Tue Apr 01, 2014 10:07 am
by mikeshinn
Its not a limitation in the rules, modsecurity just doesnt do this. Event tracking capabilities in modsecurity are very poor (and have performance issues), so we use an high speed engine to do this in ASL.

Re: 12_aslbrute not banning IP's

Posted: Tue Apr 01, 2014 10:28 am
by webjive
Thanks! What has kept us from going full ASL is when we tried to install it in the past, it made our production machine un-bootable and we had to perform an OS reload so, we're VERY skiddish on attempting to install ASL ourselves.

Re: 12_aslbrute not banning IP's

Posted: Tue Apr 01, 2014 11:24 am
by mikeshinn
We'd be happy to install ASL for you.

Re: 12_aslbrute not banning IP's

Posted: Thu Apr 03, 2014 11:17 am
by webjive
Getting close to a decision here on the full ASL suite. The attacks are coming in waves with peaks and valleys. Looks like its a low level DDOS on WP and Joomla for admin and some scraping to check for vulnerable files. Would the full ASL help with this? See attached image.

Re: 12_aslbrute not banning IP's

Posted: Thu Apr 03, 2014 6:21 pm
by mikeshinn
Thank you for the question, ASL sure does protect against this. If you'd like help installing ASL, just shoot support an email.

Re: 12_aslbrute not banning IP's

Posted: Thu Apr 03, 2014 6:26 pm
by webjive
Well, it's time to to the deed then! I need a pro to install and get this rolling. My only fear is for our large Joomla install base and what might get caught in the ASL rules. Good news is I'm sure there will be a way to exclude some domains from those rules like CSF mod_sec control? That's our environment now, lots of CSF tools. Modsec Control, CSF, etc. Has worked well until now but, the hackers of the world have found us.

I purchased the annual ASL rules for $99. Is this an upgrade to full ASL or an upgrade?

Re: 12_aslbrute not banning IP's

Posted: Thu Apr 03, 2014 7:39 pm
by mikeshinn
My only fear is for our large Joomla install base and what might get caught in the ASL rules.
We use Joomla, so its very unlikely any of our rules you cause any issues with Joomla. If you havent had an issue with the modsec rules from us, then you'll be fine with ASL.
Good news is I'm sure there will be a way to exclude some domains from those rules like CSF mod_sec control?
Oh yeah, and then some. You can tweak each rule, its behavior, thresholds and more.
I purchased the annual ASL rules for $99. Is this an upgrade to full ASL or an upgrade?
If you purchased a rules license, thats just a license for the rules. Rules licenses do not include ASL. You can upgrade from a rules annual license to an ASL annual license for only $99.96.

Re: 12_aslbrute not banning IP's

Posted: Fri Apr 04, 2014 1:31 pm
by webjive
Thanks! Once I pay that, will I get access to the support ticket system? Right now, I can't login to that.