ProFTPD on our server was under attack last week, filling up gigabytes of logfiles (/var/log/secure, /var/log/proftpd/sftp.log and /var/log/proftpd/auth.log). What confuses me, is why CSF/LFD is not picking up these attacks, they were from the same IP address and logged to /var/log/secure. In CSF/LFD we have FTPD_LOG = /var/log/secure configured, and many attacks on ProFTPD are successfully blocked. But this one seems to be different.
The rate of the attack is tremendous, making ProFTPD log 64 lines per second (hence the huge logfiles). The attack is done on all three IP addresses of the server, and is pretty ridiculous, trying loads of different usernames over and over again. FYI, ProFTPD is configured to only accept passwordless authentication over SSH, so these attempts are futile. Still, the log files grow immensely and have to be cleaned up manually. I'm not sure log rotation will process them correctly.
Why isn't CSF/LFD picking this up? Can it pick up attacks at this rate?
Here's one second of attack attempts (obfuscated our IP addresses and non-standard port number):
The rate of the attack is tremendous, making ProFTPD log 64 lines per second (hence the huge logfiles). The attack is done on all three IP addresses of the server, and is pretty ridiculous, trying loads of different usernames over and over again. FYI, ProFTPD is configured to only accept passwordless authentication over SSH, so these attempts are futile. Still, the log files grow immensely and have to be cleaned up manually. I'm not sure log rotation will process them correctly.
Why isn't CSF/LFD picking this up? Can it pick up attacks at this rate?
Here's one second of attack attempts (obfuscated our IP addresses and non-standard port number):
Code:
Oct 14 04:15:25 server proftpd[2046]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2046]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2051]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2049]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2050]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2054]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2053]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2052]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2055]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2055]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2055]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2055]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2055]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.92.223.217:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.32.238.97:1234
Oct 14 04:15:25 server proftpd[2057]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - USER user: no such user found from 185.91.127.114 [185.91.127.114] to ::ffff:XXX.141.219.37:1234
Oct 14 04:15:25 server proftpd[2056]: 0.0.0.0 (185.91.127.114[185.91.127.114]) - Maximum login attempts (6) exceeded, connection refused