linux利用CSF防火墙屏蔽恶意请求
<p><strong>问题</strong><br>
最近不知道为什么,恶意代理的请求数越来越多,明明我返回的都是403Forbidden,但是由于数量实在庞大,还是消耗了我大量的带宽和资源。之前的方法已经没有用了,想了半天还是研究研究防火墙吧,虽然仅仅靠Apache也能对某些IP进行黑名单设置,但是感觉还是有点麻烦的。比如最常见的用iptables,或者是ufw,虽然都能很好的做到管理,但是他们基本都需要一条一条的加,十分麻烦。</p>
<p>
网上搜索了下,找到了一个挺方便的小工具–CSF(ConfigServer & Security Firewall),这个工具据说除了能够方便的管理IP blacklist,而且也能稍加配置抵御一定量的DDOS攻击。</p>
<p>
<strong>安装</strong><br>
工具本身可以在csf工具的官网上下载。</p>
<p>
下载并解压后可以参考其中的<code>install.txt</code>的说明进行安装,讲的简洁而且详细,注意给权限就行。需要说明的是,这个工具其实也是基于iptables,只是简化了命令而已。</p>
<p>
<strong>关于ddos的防护</strong></p>
<p>
根据readme.txt的描述,进行ddos防护的功能主要是靠/etc/csf/csf.conf中的配置进行控制的,尤其是当中的PORTFLOOD参数,一般都进行如下设置:</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterplain" id="highlighter_402019">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="plain plain">#Syntax for the PORTFLOOD setting:</code>
</div>
<div class="line number2 index1 alt1">
<code class="plain plain">#PORTFLOOD is a comma separated list of:</code>
</div>
<div class="line number3 index2 alt2">
<code class="plain plain">port;protocol;hit count*;interval seconds</code>
</div>
<div class="line number4 index3 alt1">
<code class="plain plain">#So, a setting of PORTFLOOD = "22;tcp;5;300,80;tcp;20;5" means:</code>
</div>
<div class="line number5 index4 alt2">
<code class="plain plain">#1. If more than 5 connections to tcp port 22 within 300 seconds, then block</code>
</div>
<div class="line number6 index5 alt1">
<code class="plain plain">#that IP address from port 22 for at least 300 seconds after the last packet is</code>
</div>
<div class="line number7 index6 alt2">
<code class="plain plain">#seen, i.e. there must be a "quiet" period of 300 seconds before the block is</code>
</div>
<div class="line number8 index7 alt1">
<code class="plain plain">#lifted</code>
</div>
<div class="line number9 index8 alt2">
<code class="plain plain">#2. If more than 20 connections to tcp port 80 within 5 seconds, then block</code>
</div>
<div class="line number10 index9 alt1">
<code class="plain plain">#that IP address from port 80 for at least 5 seconds after the last packet is</code>
</div>
<div class="line number11 index10 alt2">
<code class="plain plain">#seen, i.e. there must be a "quiet" period of 5 seconds before the block is</code>
</div>
<div class="line number12 index11 alt1">
<code class="plain plain">#lifted</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
这个可以根据个人需要修改。</p>
<p>
<strong>关于black list</strong></p>
<p>
blacklist 就在/etc/csf/csf.deny里,可以有多种书写方式,在该文件的顶部描述的十分清楚:</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterplain" id="highlighter_300167">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
<div class="line number13 index12 alt2">
13</div>
<div class="line number14 index13 alt1">
14</div>
<div class="line number15 index14 alt2">
15</div>
<div class="line number16 index15 alt1">
16</div>
<div class="line number17 index16 alt2">
17</div>
<div class="line number18 index17 alt1">
18</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="plain plain">###############################################################################</code>
</div>
<div class="line number2 index1 alt1">
<code class="plain plain"># Copyright 2006-2017, Way to the Web Limited</code>
</div>
<div class="line number3 index2 alt2">
<code class="plain plain"># URL: http://www.configserver.com</code>
</div>
<div class="line number4 index3 alt1">
<code class="plain plain"># Email: sales@waytotheweb.com</code>
</div>
<div class="line number5 index4 alt2">
<code class="plain plain">###############################################################################</code>
</div>
<div class="line number6 index5 alt1">
<code class="plain plain"># The following IP addresses will be blocked in iptables</code>
</div>
<div class="line number7 index6 alt2">
<code class="plain plain"># One IP address per line</code>
</div>
<div class="line number8 index7 alt1">
<code class="plain plain"># CIDR addressing allowed with a quaded IP (e.g. 192.168.254.0/24)</code>
</div>
<div class="line number9 index8 alt2">
<code class="plain plain"># Only list IP addresses, not domain names (they will be ignored)</code>
</div>
<div class="line number10 index9 alt1">
<code class="plain plain">#</code>
</div>
<div class="line number11 index10 alt2">
<code class="plain plain"># Note: If you add the text "do not delete" to the comments of an entry then</code>
</div>
<div class="line number12 index11 alt1">
<code class="plain plain"># DENY_IP_LIMIT will ignore those entries and not remove them</code>
</div>
<div class="line number13 index12 alt2">
<code class="plain plain">#</code>
</div>
<div class="line number14 index13 alt1">
<code class="plain plain"># Advanced port+ip filtering allowed with the following format</code>
</div>
<div class="line number15 index14 alt2">
<code class="plain plain"># tcp/udp|in/out|s/d=port|s/d=ip</code>
</div>
<div class="line number16 index15 alt1">
<code class="plain plain">#</code>
</div>
<div class="line number17 index16 alt2">
<code class="plain plain"># See readme.txt for more information regarding advanced port filtering</code>
</div>
<div class="line number18 index17 alt1">
<code class="plain plain">#</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
简要概括就是每一行代表一个ip,也可以代表一个ip段(CIDR),而且我们也可以加注释,甚至可以指定端口和协议。<br>
最后,在做出修改后想要生效记得用<code>csf -r</code>命令。</p>
<p>
<strong>针对恶意代理请求的防护方案</strong></p>
<p>
当然,我用这个的目的是为了根本解决之前的恶意代理占用带宽的问题。有了这个工具,就可以十分轻松的进行控制了,思路如下:</p>
<ol>
<li>
首先,搜索Apache的log(/var/log/apache2/access.log),查找所有应被屏蔽的log条目(我这里指的是所有被403的请求)。</li>
<li>
然后,提取每条Log记录对应的ip地址。</li>
<li>
对结果进行排序去重,生成black list。</li>
<li>
blacklist 写入csf.deny</li>
<li>
重启csf防护服务。</li>
</ol>
<p>
实现起来超级简单:</p>
<p>
</p>
<div class="codetitle">
<span><u>复制代码</u></span> 代码如下:</div>
<div class="codebody" id="code15839">
<br>
root@server:~# cat /var/log/apache2/access.log |grep \ 403\ |awk '{print $1}'|sort|uniq >> /etc/csf/csf.deny</div>
<p>
</p>
<p>
可以手动查看下结果是否正确,确认之后既可以<code>csf -r</code>重启服务了。</p>
<p>
以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持。</p>
<p>
原文链接:https://blog.mythsman.com/2017/03/20/1/</p>
頁:
[1]