+ Reply to Thread
Results 1 to 4 of 4




  

Thread: What is BFD (Brute Force Detection)?

      
  1. #1
    sandy
    Forum Guest

    Thumbs up What is BFD (Brute Force Detection)?

    Hi,



    What is BFD (Brute Force Detection)?
    BFD is a modular shell script for parsing applicable logs and checking for authentication failures. There is not much complexity or detail to BFD yet and likewise it is very straight-forward in its installation, configuration and usage. The reason behind BFD is very simple; the fact there is little to no authentication and brute force auditing programs in the linux community that work in conjunction with a firewall or real-time facility to place bans. BFD is available at: http://www.rfxnetworks.com/bfd.php

    This guide will show you how to install and configure BFD to protect your system from brute force hack attempts.

    Requirements:
    - You MUST have APF Firewall Installed before installing BFD - it works with APF and requires some APF files to operate.
    - Root SSH access to your server

    Login to your server through SSH and su to the root user.

    1. cd /root/downloads or another temporary folder where you store your files.

    2. wget http://www.rfxnetworks.com/downloads/bfd-current.tar.gz

    3. tar -xvzf bfd-current.tar.gz

    4. cd bfd-0.7

    5. Run the install file: ./install.sh
    You will receive a message saying it has been installed

    .: BFD installed
    Install path: /usr/local/bfd
    Config path: /usr/local/bfd/conf.bfd
    Executable path: /usr/local/sbin/bfd

    6. Lets edit the configuration file: pico /usr/local/bfd/conf.bfd

    7. Enable brute force hack attempt alerts:
    Find: ALERT_USR=”0″ CHANGE TO: ALERT_USR=”1″

    Find: EMAIL_USR=”root” CHANGE TO: EMAIL_USR=”your@yourdomain.com”

    Save the changes: Ctrl+X then Y

    8. Prevent locking yourself out!
    pico -w /usr/local/bfd/ignore.hosts and add your own trusted IPs
    Eg: 192.168.1.1

    Save the changes: Ctrl+X then Y

    BFD uses APF’ cli insert feature
    and as such will override any allow_hosts.rules entries users have in-place.
    So be sure to add your trusted ip addresses to the ignore file to prevent
    locking yourself out.

    9. Run the program!
    /usr/local/sbin/bfd -s

  2. #2
    I'm New! scotty is on a distinguished road
    Join Date
    February 19, 2008
    Posts
    2
    Rep Power
    0
    Feedback Score
    0

    Default

    Thanks for the effort you have made

  3. #3
    WTF Pit Boss WikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond reputeWikicyloN has a reputation beyond repute WikicyloN's Avatar
    Join Date
    September 20, 2007
    Location
    sideways
    Posts
    3,162
    Rep Power
    8
    Feedback Score
    0

    Default

    can you show me how to make a brute force attack?

    I have to be able to test my detection, don't I?
    funny pictures and videos available at Unicorn Vomit

  4. #4
    Grand Masters grim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond reputegrim has a reputation beyond repute grim's Avatar
    Join Date
    September 22, 2006
    Posts
    10,060
    Rep Power
    25
    Feedback Score
    0

    Default

    Quote Originally Posted by WikicyloN View Post
    can you show me how to make a brute force attack?

    I have to be able to test my detection, don't I?
    Simple.
    Just try logging in a few times using bogus info on your server

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Does anyone force password changes for staff?
    By Big Dan in forum Forum Management
    Replies: 5
    Last Post: Feb 24th, 2008, 11:16 pm
  2. Force Max Chars?
    By Captain Tycoon in forum Blogging
    Replies: 8
    Last Post: Dec 22nd, 2007, 1:23 am
  3. Pay Pal Disputes to force your hand
    By grim in forum Directories
    Replies: 18
    Last Post: Aug 5th, 2007, 7:16 pm

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
WebTalkForums
WebTalkForums
Recent Forum Threads