ื”ื’ืŸ ืขืœ Zimbra OSE ืžื›ื•ื— ื’ืก ื•ื”ืชืงืคื•ืช DoS

ืœ-Zimbra Collaboration Suite Edition ืงื•ื“ ืคืชื•ื— ื™ืฉ ื›ืžื” ื›ืœื™ื ืจื‘ื™ ืขื•ืฆืžื” ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืื‘ื˜ื—ืช ืžื™ื“ืข. ื‘ื™ื ื™ื”ื ืคื•ืกื˜ืžืกืš - ืคืชืจื•ืŸ ืœื”ื’ื ื” ืขืœ ืฉืจืช ื“ื•ืืจ ืžืคื ื™ ื”ืชืงืคื•ืช ืžืจืฉืชื•ืช ื‘ื•ื˜ื™ื, ClamAV - ืื ื˜ื™ ื•ื™ืจื•ืก ืฉื™ื›ื•ืœ ืœืกืจื•ืง ืงื‘ืฆื™ื ื•ืžื›ืชื‘ื™ื ื ื›ื ืกื™ื ืœืื™ืชื•ืจ ื”ื“ื‘ืงื” ื‘ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช, ื•ื›ืŸ SpamAssassin - ืื—ื“ ืžืžืกื ื ื™ ื”ืกืคืื ื”ื˜ื•ื‘ื™ื ื‘ื™ื•ืชืจ ื›ื™ื•ื. ืขื ื–ืืช, ื›ืœื™ื ืืœื” ืื™ื ื ืžืกื•ื’ืœื™ื ืœื”ื’ืŸ ืขืœ Zimbra OSE ืžืคื ื™ ื”ืชืงืคื•ืช ื›ื•ื— ื’ืก. ืœื ื”ืกื™ืกืžืื•ืช ื”ืืœื’ื ื˜ื™ื•ืช ื‘ื™ื•ืชืจ, ืืš ืขื“ื™ื™ืŸ ื“ื™ ื™ืขื™ืœื•ืช, ืื›ื™ืคื•ืช ื’ืกื•ืช ื‘ืืžืฆืขื•ืช ืžื™ืœื•ืŸ ืžื™ื•ื—ื“ ื˜ื•ืžื ื•ืช ื‘ื—ื•ื‘ืŸ ืœื ืจืง ืืช ื”ืกื‘ื™ืจื•ืช ืฉืœ ืคืจื™ืฆื” ืžื•ืฆืœื—ืช ืขื ื›ืœ ื”ื”ืฉืœื›ื•ืช ื”ื ื•ื‘ืขื•ืช ืžื›ืš, ืืœื ื’ื ื‘ื™ืฆื™ืจืช ืขื•ืžืก ืžืฉืžืขื•ืชื™ ืขืœ ื”ืฉืจืช, ืฉืžืขื‘ื“ ืืช ื›ืœ ื ื™ืกื™ื•ื ื•ืช ืœื ืžื•ืฆืœื—ื™ื ืœืคืจื•ืฅ ืฉืจืช ืขื Zimbra OSE.

ื”ื’ืŸ ืขืœ Zimbra OSE ืžื›ื•ื— ื’ืก ื•ื”ืชืงืคื•ืช DoS

ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ืืชื” ื™ื›ื•ืœ ืœื”ื’ืŸ ืขืœ ืขืฆืžืš ืžืคื ื™ ื›ื•ื— ื’ืก ื‘ืืžืฆืขื•ืช ื›ืœื™ Zimbra OSE ืกื˜ื ื“ืจื˜ื™ื™ื. ื”ื’ื“ืจื•ืช ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ืช ื”ืกื™ืกืžื” ืžืืคืฉืจื•ืช ืœืš ืœื”ื’ื“ื™ืจ ืืช ืžืกืคืจ ื ื™ืกื™ื•ื ื•ืช ื”ื–ื ืช ื”ืกื™ืกืžื” ื”ืœื ืžื•ืฆืœื—ื™ื, ืฉืœืื—ืจื™ื”ื ื”ื—ืฉื‘ื•ืŸ ืฉืขืœื•ืœ ืœื”ื™ื•ืช ืžื•ืชืงืฃ ื ื—ืกื. ื”ื‘ืขื™ื” ื”ืขื™ืงืจื™ืช ื‘ื’ื™ืฉื” ื–ื• ื”ื™ื ืฉื ื•ืฆืจื™ื ืžืฆื‘ื™ื ืฉื‘ื”ื ื—ืฉื‘ื•ื ื•ืช ืฉืœ ืขื•ื‘ื“ ืื—ื“ ืื• ื™ื•ืชืจ ืขืœื•ืœื™ื ืœื”ื™ื—ืกื ืขืงื‘ ืžืชืงืคืช ื›ื•ื— ืื›ื–ืจื™ ืฉืื™ืŸ ืœื”ื ืžื” ืœืขืฉื•ืช ืืœื™ื”, ื•ื”ื”ืฉื‘ืชื” ื”ื ื•ื‘ืขืช ืžื”ืขื‘ื•ื“ื” ืฉืœ ื”ืขื•ื‘ื“ื™ื ืขืœื•ืœื” ืœื”ื‘ื™ื ืœื”ืคืกื“ื™ื ื’ื“ื•ืœื™ื. ื”ื—ื‘ืจื”. ืœื›ืŸ ืขื“ื™ืฃ ืœื ืœื”ืฉืชืžืฉ ื‘ืืคืฉืจื•ืช ื–ื• ืฉืœ ื”ื’ื ื” ืžืคื ื™ ื›ื•ื— ื’ืก.

ื”ื’ืŸ ืขืœ Zimbra OSE ืžื›ื•ื— ื’ืก ื•ื”ืชืงืคื•ืช DoS

ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ ื›ื•ื— ื’ืก, ืžืชืื™ื ื”ืจื‘ื” ื™ื•ืชืจ ื›ืœื™ ืžื™ื•ื—ื“ ื‘ืฉื DoSFilter, ื”ืžื•ื‘ื ื” ื‘-Zimbra OSE ื•ื™ื›ื•ืœ ืœืกื™ื™ื ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ื—ื™ื‘ื•ืจ ืœ-Zimbra OSE ื‘ืืžืฆืขื•ืช HTTP. ื‘ืžื™ืœื™ื ืื—ืจื•ืช, ืขืงืจื•ืŸ ื”ืคืขื•ืœื” ืฉืœ DoSFilter ื“ื•ืžื” ืœืขืงืจื•ืŸ ื”ืคืขื•ืœื” ืฉืœ PostScreen, ืจืง ืฉื”ื•ื ืžืฉืžืฉ ืœืคืจื•ื˜ื•ืงื•ืœ ืื—ืจ. ืชื•ื›ื ืŸ ื‘ืžืงื•ืจ ืœื”ื’ื‘ื™ืœ ืืช ืžืกืคืจ ื”ืคืขื•ืœื•ืช ืฉืžืฉืชืžืฉ ื‘ื•ื“ื“ ื™ื›ื•ืœ ืœื‘ืฆืข, DoSFilter ื™ื›ื•ืœ ื’ื ืœืกืคืง ื”ื’ื ื” ืžื›ื•ื— ื’ืก. ื”ื”ื‘ื“ืœ ื”ืขื™ืงืจื™ ืฉืœื• ืžื”ื›ืœื™ ื”ืžื•ื‘ื ื” ื‘-Zimbra ื”ื•ื ืฉืื—ืจื™ ืžืกืคืจ ืžืกื•ื™ื ืฉืœ ื ื™ืกื™ื•ื ื•ืช ืœื ืžื•ืฆืœื—ื™ื, ื”ื•ื ืœื ื—ื•ืกื ืืช ื”ืžืฉืชืžืฉ ืขืฆืžื•, ืืœื ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืžืžื ื” ื ืขืฉื™ื ื ื™ืกื™ื•ื ื•ืช ืžืจื•ื‘ื™ื ืœื”ื™ื›ื ืก ืœื—ืฉื‘ื•ืŸ ืžืกื•ื™ื. ื”ื•ื“ื•ืช ืœื›ืš, ืžื ื”ืœ ืžืขืจื›ืช ื™ื›ื•ืœ ืœื ืจืง ืœื”ื’ืŸ ืžืคื ื™ ื›ื•ื— ื’ืก, ืืœื ื’ื ืœื”ื™ืžื ืข ืžื—ืกื™ืžืช ืขื•ื‘ื“ื™ ื”ื—ื‘ืจื” ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืจืฉืช ื”ืคื ื™ืžื™ืช ืฉืœ ื”ื—ื‘ืจื” ืฉืœื• ืœืจืฉื™ืžืช ื›ืชื•ื‘ื•ืช ื”-IP ื•ืจืฉืชื•ืช ื”ืžืฉื ื” ื”ืžื”ื™ืžื ื•ืช.

ื”ื™ืชืจื•ืŸ ื”ื’ื“ื•ืœ ืฉืœ DoSFilter ื”ื•ื ืฉื‘ื ื•ืกืฃ ืœืžืกืคืจ ื ื™ืกื™ื•ื ื•ืช ืœื”ืชื—ื‘ืจ ืœื—ืฉื‘ื•ืŸ ืžืกื•ื™ื, ื‘ืืžืฆืขื•ืช ื›ืœื™ ื–ื” ื ื™ืชืŸ ืœื—ืกื•ื ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ืชื•ืงืคื™ื ืฉื”ืฉืชืœื˜ื• ืขืœ ื ืชื•ื ื™ ื”ืื™ืžื•ืช ืฉืœ ืขื•ื‘ื“, ื•ืœืื—ืจ ืžื›ืŸ ื”ืชื—ื‘ืจื• ื‘ื”ืฆืœื—ื” ืœื—ืฉื‘ื•ืŸ ืฉืœื• ื•ื”ื—ืœื• ืœืฉืœื•ื— ืžืื•ืช ื‘ืงืฉื•ืช ืœืฉืจืช.

ืืชื” ื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ืืช DoSFilter ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื•ืช ื”ืžืกื•ืฃ ื”ื‘ืื•ืช:

  • zimbraHttpDosFilterMaxRequestsPerSec โ€” ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ื–ื•, ืชื•ื›ืœ ืœื”ื’ื“ื™ืจ ืืช ืžืกืคืจ ื”ื—ื™ื‘ื•ืจื™ื ื”ืžืจื‘ื™ ื”ืžื•ืชืจ ืœืžืฉืชืžืฉ ืื—ื“. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขืจืš ื–ื” ื”ื•ื 30 ื—ื™ื‘ื•ืจื™ื.
  • zimbraHttpDosFilterDelayMillis - ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ื–ื•, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื”ืฉื”ื™ื™ื” ื‘ืืœืคื™ื•ืช ืฉื ื™ื•ืช ืœื—ื™ื‘ื•ืจื™ื ืฉื™ื—ืจื’ื• ืžื”ืžื’ื‘ืœื” ืฉืฆื•ื™ื ื” ื‘ืคืงื•ื“ื” ื”ืงื•ื“ืžืช. ื‘ื ื•ืกืฃ ืœืขืจื›ื™ ืžืกืคืจ ืฉืœืžื™ื, ื”ืžื ื”ืœ ื™ื›ื•ืœ ืœืฆื™ื™ืŸ 0, ื›ืš ืฉืœื ื™ื”ื™ื” ื”ืฉื”ื™ื™ื” ื›ืœืœ, ื•-1, ื›ืš ืฉื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ื”ื—ื•ืจื’ื™ื ืžื”ืžื’ื‘ืœื” ืฉืฆื•ื™ื ื” ืคืฉื•ื˜ ื ืงื˜ืขื•. ืขืจืš ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื•ื -1.
  • zimbraHttpThrottleSafeIPs โ€” ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ื–ื•, ืžื ื”ืœ ื”ืžืขืจื›ืช ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ื›ืชื•ื‘ื•ืช IP ืžื”ื™ืžื ื•ืช ื•ืจืฉืชื•ืช ืžืฉื ื” ืฉืœื ื™ื”ื™ื• ื›ืคื•ืคื•ืช ืœื”ื’ื‘ืœื•ืช ื”ืžืคื•ืจื˜ื•ืช ืœืขื™ืœ. ืฉื™ืžื• ืœื‘ ืฉื”ืชื—ื‘ื™ืจ ืฉืœ ืคืงื•ื“ื” ื–ื• ืขืฉื•ื™ ืœื”ืฉืชื ื•ืช ื‘ื”ืชืื ืœืชื•ืฆืื” ื”ืจืฆื•ื™ื”. ื›ืš, ืœืžืฉืœ, ืขืœ ื™ื“ื™ ื”ื–ื ืช ื”ืคืงื•ื“ื” zmprov mcf zimbraHttpThrottleSafeIPs 127.0.0.1, ืชื“ืจื•ืก ืœื—ืœื•ื˜ื™ืŸ ืืช ื›ืœ ื”ืจืฉื™ืžื” ื•ืชืฉืื™ืจ ื‘ื” ื›ืชื•ื‘ืช IP ืื—ืช ื‘ืœื‘ื“. ืื ืชื–ื™ืŸ ืืช ื”ืคืงื•ื“ื” zmprov mcf +zimbraHttpThrottleSafeIPs 127.0.0.1, ื›ืชื•ื‘ืช ื”-IP ืฉื”ื–ื ืช ืชืชื•ื•ืกืฃ ืœืจืฉื™ืžื” ื”ืœื‘ื ื”. ื‘ืื•ืคืŸ ื“ื•ืžื”, ื‘ืืžืฆืขื•ืช ืกื™ืžืŸ ื”ื—ื™ืกื•ืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืกื™ืจ ื›ืœ IP ืžื”ืจืฉื™ืžื” ื”ืžื•ืชืจืช.

ืฉื™ืžื• ืœื‘ ืฉ-DoSFilter ืขืฉื•ื™ ืœื™ืฆื•ืจ ืžืกืคืจ ื‘ืขื™ื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืชื•ืกืคื™ Zextras Suite Pro. ืขืœ ืžื ืช ืœื”ื™ืžื ืข ืžื”ื, ืื ื• ืžืžืœื™ืฆื™ื ืœื”ื’ื“ื™ืœ ืืช ืžืกืคืจ ื”ื—ื™ื‘ื•ืจื™ื ื‘ื•-ื–ืžื ื™ืช ืž-30 ืœ-100 ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” zmprov mcf zimbraHttpDosFilterMaxRequestsPerSec 100. ื‘ื ื•ืกืฃ, ืื ื• ืžืžืœื™ืฆื™ื ืœื”ื•ืกื™ืฃ ืืช ื”ืจืฉืช ื”ืคื ื™ืžื™ืช ื”ืืจื’ื•ื ื™ืช ืœืจืฉื™ืžืช ื”ืžื•ืชืจื•ืช. ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” zmprov mcf +zimbraHttpThrottleSafeIPs 192.168.0.0/24. ืœืื—ืจ ื‘ื™ืฆื•ืข ืฉื™ื ื•ื™ื™ื ื›ืœืฉื”ื ื‘-DoSFilter, ื”ืงืคื“ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ืฉืจืช ื”ื“ื•ืืจ ืฉืœืš ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ zmmailboxdctl.

ื”ื—ื™ืกืจื•ืŸ ื”ืขื™ืงืจื™ ืฉืœ DoSFilter ื”ื•ื ืฉื”ื•ื ืขื•ื‘ื“ ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื” ื•ืœื›ืŸ ื™ื›ื•ืœ ืจืง ืœื”ื’ื‘ื™ืœ ืืช ื™ื›ื•ืœืช ื”ืชื•ืงืคื™ื ืœื‘ืฆืข ืคืขื•ืœื•ืช ืฉื•ื ื•ืช ื‘ืฉืจืช, ืžื‘ืœื™ ืœื”ื’ื‘ื™ืœ ืืช ื™ื›ื•ืœืช ื”ื—ื™ื‘ื•ืจ ืœืฆืคื•ืŸ. ื‘ืฉืœ ื›ืš, ื‘ืงืฉื•ืช ืฉื ืฉืœื—ื•ืช ืœืฉืจืช ืœืฆื•ืจืš ืื™ืžื•ืช ืื• ืฉืœื™ื—ืช ืžื›ืชื‘ื™ื, ืœืžืจื•ืช ืฉื”ืŸ ื›ืžื•ื‘ืŸ ื™ื™ื›ืฉืœื•, ืขื“ื™ื™ืŸ ื™ื™ืฆื’ื• ืžืชืงืคืช DoS ื™ืฉื ื” ื•ื˜ื•ื‘ื”, ืฉืœื ื ื™ืชืŸ ืœืขืฆื•ืจ ืื•ืชื” ื‘ืจืžื” ื›ื” ื’ื‘ื•ื”ื”.

ืขืœ ืžื ืช ืœืื‘ื˜ื— ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ืฉืจืช ื”ืืจื’ื•ื ื™ ืฉืœื›ื ืขื Zimbra OSE, ืชื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ืคืชืจื•ืŸ ื›ืžื• Fail2ban, ืฉื”ื™ื ืžืกื’ืจืช ืฉื™ื›ื•ืœื” ืœื ื˜ืจ ื›ืœ ื”ื–ืžืŸ ื™ื•ืžื ื™ ืžืขืจื›ืช ืžื™ื“ืข ืœืคืขื•ืœื•ืช ื—ื•ื–ืจื•ืช ื•ื ืฉื ื•ืช ื•ืœื—ืกื•ื ืืช ื”ืคื•ืจืฅ ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ื—ื•ืžืช ื”ืืฉ. ื—ืกื™ืžื” ื‘ืจืžื” ื›ื” ื ืžื•ื›ื” ืžืืคืฉืจืช ืœื”ืฉื‘ื™ืช ืชื•ืงืคื™ื ืžืžืฉ ื‘ืฉืœื‘ ื—ื™ื‘ื•ืจ ื”-IP ืœืฉืจืช. ืœืคื™ื›ืš, Fail2Ban ื™ื›ื•ืœ ืœื”ืฉืœื™ื ื‘ืฆื•ืจื” ืžื•ืฉืœืžืช ืืช ื”ื”ื’ื ื” ืฉื ื‘ื ืชื” ื‘ืืžืฆืขื•ืช DoSFilter. ื‘ื•ืื• ืœื’ืœื•ืช ื›ื™ืฆื“ ืชื•ื›ืœื• ืœื—ื‘ืจ ืืช Fail2Ban ืขื Zimbra OSE ื•ื‘ื›ืš ืœื”ื’ื‘ื™ืจ ืืช ื”ืื‘ื˜ื—ื” ืฉืœ ืชืฉืชื™ืช ื”-IT ืฉืœ ื”ืืจื’ื•ืŸ ืฉืœื›ื.

ื›ืžื• ื›ืœ ื™ื™ืฉื•ื ืื—ืจ ื‘ืจืžื” ืืจื’ื•ื ื™ืช, Zimbra Collaboration Suite Edition ืงื•ื“ ืคืชื•ื— ืฉื•ืžืจืช ื™ื•ืžื ื™ื ืžืคื•ืจื˜ื™ื ืฉืœ ืขื‘ื•ื“ืชื”. ืจื•ื‘ื ืžืื•ื—ืกื ื™ื ื‘ืชื™ืงื™ื™ื” /opt/zimbra/log/ ื‘ืฆื•ืจื” ืฉืœ ืงื‘ืฆื™ื. ื”ื ื” ืจืง ื›ืžื” ืžื”ื:

  • mailbox.log โ€” ื™ื•ืžื ื™ ืฉื™ืจื•ืช ื”ื“ื•ืืจ ื”ืžื–ื—
  • audit.log - ื™ื•ืžื ื™ ืื™ืžื•ืช
  • clamd.log - ื™ื•ืžื ื™ ืคืขื•ืœื•ืช ืฉืœ ืื ื˜ื™ ื•ื™ืจื•ืก
  • freshclam.log - ื™ื•ืžื ื™ ืขื“ื›ื•ื ื™ ืื ื˜ื™ ื•ื™ืจื•ืก
  • convertd.log - ื™ื•ืžื ื™ ืžืžื™ืจ ืงื‘ืฆื™ื ืžืฆื•ืจืคื™ื
  • zimbrastats.csv - ื™ื•ืžื ื™ ื‘ื™ืฆื•ืขื™ ืฉืจืช

ื ื™ืชืŸ ืœืžืฆื•ื ื’ื ื™ื•ืžื ื™ ื–ื™ืžื‘ืจื” ื‘ืงื•ื‘ืฅ /var/log/zimbra.log, ืฉื‘ื• ื ืฉืžืจื™ื ื™ื•ืžื ื™ื ืฉืœ Postfix ื•ืฉืœ Zimbra ืขืฆืžื”.

ืขืœ ืžื ืช ืœื”ื’ืŸ ืขืœ ื”ืžืขืจื›ืช ืฉืœื ื• ืžื›ื•ื— ื’ืก, ืื ื• ื ื ื˜ืจ mailbox.log, ื™ื•ืžืŸ ื‘ื™ืงื•ืจืช ะธ zimbra.log.

ื›ื“ื™ ืฉื”ื›ืœ ื™ืขื‘ื•ื“, ื™ืฉ ืฆื•ืจืš ืฉ-Fail2Ban ื•-iptables ื™ื•ืชืงื ื• ืขืœ ื”ืฉืจืช ืฉืœืš ืขื Zimbra OSE. ืื ืืชื” ืžืฉืชืžืฉ ื‘ืื•ื‘ื•ื ื˜ื•, ืืชื” ื™ื›ื•ืœ ืœืขืฉื•ืช ื–ืืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช dpkg -s fail2ban, ืื ืืชื” ืžืฉืชืžืฉ ื‘- CentOS, ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ื–ืืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช yum list ืžื•ืชืงื ืช fail2ban. ืื ืื™ืŸ ืœืš ืืช Fail2Ban ืžื•ืชืงืŸ, ืื– ื”ืชืงื ืชื• ืœื ืชื”ื™ื” ื‘ืขื™ื”, ืฉื›ืŸ ื—ื‘ื™ืœื” ื–ื• ื–ืžื™ื ื” ื›ืžืขื˜ ื‘ื›ืœ ื”ืžืื’ืจื™ื ื”ืกื˜ื ื“ืจื˜ื™ื™ื.

ืœืื—ืจ ื”ืชืงื ืช ื›ืœ ื”ืชื•ื›ื ื” ื”ื“ืจื•ืฉื”, ืชื•ื›ืœ ืœื”ืชื—ื™ืœ ื‘ื”ื’ื“ืจืช Fail2Ban. ืœืฉื ื›ืš ืขืœื™ืš ืœื™ืฆื•ืจ ืงื•ื‘ืฅ ืชืฆื•ืจื” /etc/fail2ban/filter.d/zimbra.conf, ืฉื‘ื• ื ื›ืชื•ื‘ ื‘ื™ื˜ื•ื™ื™ื ืจื’ื•ืœืจื™ื™ื ืขื‘ื•ืจ ื™ื•ืžื ื™ Zimbra OSE ืฉื™ืชืื™ืžื• ืœื ื™ืกื™ื•ื ื•ืช ื”ืชื—ื‘ืจื•ืช ืฉื’ื•ื™ื™ื ื•ื™ืคืขื™ืœื• ืžื ื’ื ื•ื ื™ Fail2Ban. ื”ื ื” ื“ื•ื’ืžื” ืœืชื•ื›ืŸ ืฉืœ zimbra.conf ืขื ืงื‘ื•ืฆื” ืฉืœ ื‘ื™ื˜ื•ื™ื™ื ืจื’ื•ืœืจื™ื™ื ื”ืชื•ืืžื™ื ืœืฉื’ื™ืื•ืช ื”ืฉื•ื ื•ืช ืฉ-Zimbra OSE ื–ื•ืจืง ื›ืืฉืจ ื ื™ืกื™ื•ืŸ ืื™ืžื•ืช ื ื›ืฉืœ:

# Fail2Ban configuration file
 
[Definition]
failregex = [ip=<HOST>;] account - authentication failed for .* (no such account)$
                        [ip=<HOST>;] security - cmd=Auth; .* error=authentication failed for .*, invalid password;$
                        ;oip=<HOST>;.* security - cmd=Auth; .* protocol=soap; error=authentication failed for .* invalid password;$
                        ;oip=<HOST>;.* security - cmd=Auth; .* protocol=imap; error=authentication failed for .* invalid password;$
                        [oip=<HOST>;.* SoapEngine - handler exception: authentication failed for .*, account not found$
                        WARN .*;ip=<HOST>;ua=ZimbraWebClient .* security - cmd=AdminAuth; .* error=authentication failed for .*;$

ignoreregex =

ืœืื—ืจ ื”ื™ื“ื•ืจ ืฉืœ ื”ื‘ื™ื˜ื•ื™ื™ื ื”ืจื’ื•ืœืจื™ื™ื ืขื‘ื•ืจ Zimbra OSE, ื”ื’ื™ืข ื”ื–ืžืŸ ืœื”ืชื—ื™ืœ ืœืขืจื•ืš ืืช ื”ืชืฆื•ืจื” ืฉืœ Fail2ban ืขืฆืžื•. ื”ื”ื’ื“ืจื•ืช ืฉืœ ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ื–ื” ื ืžืฆืื•ืช ื‘ืงื•ื‘ืฅ /etc/fail2ban/jail.conf. ืœื›ืœ ืžืงืจื”, ื‘ื•ืื• ื ืขืฉื” ืขื•ืชืง ื’ื™ื‘ื•ื™ ืฉืœื• ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.conf.bak. ืœืื—ืจ ืžื›ืŸ, ื ืฆืžืฆื ืืช ื”ืงื•ื‘ืฅ ื”ื–ื” ืœืฆื•ืจื” ื”ื‘ืื” ื‘ืขืจืš:

# Fail2Ban configuration file
 
[DEFAULT]
ignoreip = 192.168.0.1/24
bantime = 600
findtime = 600
maxretry = 5
backend = auto
 
[ssh-iptables]
enabled = false
filter = sshd
action = iptables[name=SSH, port=ssh, protocol=tcp]
sendmail-whois[name=SSH, [email protected], [email protected]]
logpath = /var/log/messages
maxretry = 5
 
[sasl-iptables]
enabled = false
filter = sasl
backend = polling
action = iptables[name=sasl, port=smtp, protocol=tcp]
sendmail-whois[name=sasl, [email protected]]
logpath = /var/log/zimbra.log
 
[ssh-tcpwrapper]
enabled = false
filter = sshd
action = hostsdeny
sendmail-whois[name=SSH, dest=support@ company.ru]
ignoreregex = for myuser from
logpath = /var/log/messages
 
[zimbra-account]
enabled = true
filter = zimbra
action = iptables-allports[name=zimbra-account]
sendmail[name=zimbra-account, [email protected] ]
logpath = /opt/zimbra/log/mailbox.log
bantime = 600
maxretry = 5
 
[zimbra-audit]
enabled = true
filter = zimbra
action = iptables-allports[name=zimbra-audit]
sendmail[name=Zimbra-audit, [email protected]]
logpath = /opt/zimbra/log/audit.log
bantime = 600
maxretry = 5
 
[zimbra-recipient]
enabled = true
filter = zimbra
action = iptables-allports[name=zimbra-recipient]
sendmail[name=Zimbra-recipient, [email protected]]
logpath = /var/log/zimbra.log
bantime = 172800
maxretry = 5
 
[postfix]
enabled = true
filter = postfix
action = iptables-multiport[name=postfix, port=smtp, protocol=tcp]
sendmail-buffered[name=Postfix, [email protected]]
logpath = /var/log/zimbra.log
bantime = -1
maxretry = 5

ืœืžืจื•ืช ืฉื”ื“ื•ื’ืžื” ื”ื–ื• ื“ื™ ื›ืœืœื™ืช, ืขื“ื™ื™ืŸ ื›ื“ืื™ ืœื”ืกื‘ื™ืจ ื›ืžื” ืžื”ืคืจืžื˜ืจื™ื ืฉืื•ืœื™ ืชืจืฆื” ืœืฉื ื•ืช ื‘ืขืช ื”ื’ื“ืจืช Fail2Ban ื‘ืขืฆืžืš:

  • ื”ืชืขืœื - ื‘ืืžืฆืขื•ืช ืคืจืžื˜ืจ ื–ื” ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ip ืกืคืฆื™ืคื™ ืื• ืจืฉืช ืžืฉื ื” ืฉืžืžื ื” Fail2Ban ืœื ืืžื•ืจ ืœื‘ื“ื•ืง ื›ืชื•ื‘ื•ืช. ื›ื›ืœืœ, ื”ืจืฉืช ื”ืคื ื™ืžื™ืช ืฉืœ ื”ืืจื’ื•ืŸ ื•ื›ืชื•ื‘ื•ืช ืžื”ื™ืžื ื•ืช ืื—ืจื•ืช ืžืชื•ื•ืกืคื•ืช ืœืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช ืฉืžืชืขืœืžื•ืช ืžื”ืŸ.
  • Bantime - ื”ื–ืžืŸ ืฉืขื‘ื•ืจื• ื™ื™ืืกืจ ื”ืขื‘ืจื™ื™ืŸ. ื ืžื“ื“ ื‘ืฉื ื™ื•ืช. ืขืจืš ืฉืœ -1 ืคื™ืจื•ืฉื• ืื™ืกื•ืจ ืงื‘ื•ืข.
  • ืžืงืกื˜ืจื™ - ื”ืžืกืคืจ ื”ืžืจื‘ื™ ืฉืœ ื”ืคืขืžื™ื ืฉื›ืชื•ื‘ืช IP ืื—ืช ื™ื›ื•ืœื” ืœื ืกื•ืช ืœื’ืฉืช ืœืฉืจืช.
  • Sendmail โ€” ื”ื’ื“ืจื” ื”ืžืืคืฉืจืช ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช ื“ื•ื"ืœ ืื•ื˜ื•ืžื˜ื™ืช ื›ืืฉืจ Fail2Ban ืžื•ืคืขืœ.
  • ืœืžืฆื•ื ื–ืžืŸ โ€” ื”ื’ื“ืจื” ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ืืช ืžืจื•ื•ื— ื”ื–ืžืŸ ืฉืื—ืจื™ื• ื›ืชื•ื‘ืช ื”-IP ื™ื›ื•ืœื” ืœื ืกื•ืช ืœื’ืฉืช ืฉื•ื‘ ืœืฉืจืช ืœืื—ืจ ืžื™ืฆื•ื™ ื”ืžืกืคืจ ื”ืžืจื‘ื™ ืฉืœ ื ื™ืกื™ื•ื ื•ืช ืœื ืžื•ืฆืœื—ื™ื (ืคืจืžื˜ืจ maxretry)

ืœืื—ืจ ืฉืžื™ืจืช ื”ืงื•ื‘ืฅ ืขื ื”ื’ื“ืจื•ืช Fail2Ban, ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ื”ื›ืœื™ ื”ื–ื” ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ ื”ืฉื™ืจื•ืช fail2ban. ืœืื—ืจ ื”ื”ืคืขืœื” ืžื—ื“ืฉ, ื™ื•ืžื ื™ ื”ื–ืžื‘ืจื” ื”ืจืืฉื™ื™ื ื™ืชื—ื™ืœื• ืœื”ื™ื•ืช ื‘ืžืขืงื‘ ืžืชืžื™ื“ ืœืฆื•ืจืš ืชืื™ืžื•ืช ืœื‘ื™ื˜ื•ื™ื™ื ืจื’ื•ืœืจื™ื™ื. ื”ื•ื“ื•ืช ืœื›ืš, ืžื ื”ืœ ื”ืžืขืจื›ืช ื™ื•ื›ืœ ืœืžืขืฉื” ืœื—ืกืœ ื›ืœ ืืคืฉืจื•ืช ืฉืœ ืชื•ืงืฃ ืœื—ื“ื•ืจ ืœื ืจืง ืœืชื™ื‘ื•ืช ื”ื“ื•ืืจ ืฉืœ Zimbra Collaboration Suite-Open-Source Edition, ืืœื ื’ื ืœื”ื’ืŸ ืขืœ ื›ืœ ื”ืฉื™ืจื•ืชื™ื ื”ืคื•ืขืœื™ื ื‘ืชื•ืš Zimbra OSE, ื•ื’ื ืœื”ื™ื•ืช ืžื•ื“ืข ืœื›ืœ ื ื™ืกื™ื•ื ื•ืช ืœื”ืฉื™ื’ ื’ื™ืฉื” ืœื ืžื•ืจืฉื™ืช .

ืœื›ืœ ื”ืฉืืœื•ืช ื”ืงืฉื•ืจื•ืช ืœ-Zextras Suite, ื ื™ืชืŸ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ื ืฆื™ื’ืช Zextras Ekaterina Triandafilidi ื‘ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”